WHOISRDAPDomainsNetworkingWeb Development

WHOIS is Dead, Long Live RDAP: Looking Up Any Domain in 2026

•By Hamid Abderrahim

For thirty years, "who owns this domain?" had one answer: WHOIS — a plain-text protocol from the early 1980s served on port 43. It is now being retired across the industry in favor of RDAP (Registration Data Access Protocol), and if you have typed a domain into a lookup tool lately and gotten an error or a wall of legalese instead of data, you have already met the transition. Here is what changed, and how to do modern domain lookups with the WHOIS Lookup tool.

Why WHOIS is being replaced

The classic WHOIS protocol has three structural problems:

  1. No standard output. Every registry prints its own free-text format. Parsers are a minefield of regexes that break whenever a registry redesigns its page.
  2. No structured error handling. "Domain not found" is just human prose on the wire.
  3. No built-in privacy or access control. WHOIS predates GDPR by decades, which is why the public data shrank so dramatically after 2018 — registrars responded by blanking almost everything.

RDAP fixes all three: it is REST over HTTPS, returning JSON with defined fields (events, entities, status, nameservers), standard HTTP status codes, and a registration-data model designed for both redaction and tiered access. ICANN has required all gTLD registries and registrars to run RDAP since 2019, and WHOIS port-43 services are progressively being deprecated.

How an RDAP lookup actually works

You cannot ask a single global server about every domain — RDAP uses a bootstrap process, standardized by IETF RFC 9224:

  1. Your client downloads IANA's small, official bootstrap file mapping each TLD to its authoritative RDAP server (https://data.iana.org/rdap/dns.json).
  2. For google.com, the table points to Verisign's RDAP endpoint; for .dev, to Google's registry; for .io, to Identity Digital — and so on.
  3. The client sends GET https://<rdap-server>/domain/google.com and receives structured JSON.

The response contains everything a WHOIS lookup used to bury in free text:

  • events — registration date, last changed, expiry, with exact timestamps.
  • entities — the registrar (look for the vCard fn field, e.g. "MarkMonitor Inc.") and, where disclosure is allowed, the registrant.
  • status — client transfer prohibited, server delete prohibited, and the critical pending delete / redemption period states.
  • nameservers — the delegation, in structured form.

What you can legitimately do with domain data

Domain lookups have everyday, legitimate uses:

  • Spotting scams — check the domain in a suspicious email. Registered three days ago, registrar known for anonymous signups, short expiry? Strong phishing signal.
  • Acquisition research — expiry dates and statuses tell you whether a domain is actively managed or lapsing.
  • Technical triage — nameserver records reveal where DNS actually lives before you debug it.
  • Due diligence — confirm a vendor's claimed domain age and stability.

What you should not expect: personal addresses and phone numbers. Since GDPR, most registrant contact data is redacted from public responses, and that is a feature — RDAP is designed to support privacy without breaking structured access.

Why browser-side lookups are different

Traditional WHOIS lookups ran on port 43 — a raw TCP protocol a browser cannot speak, so almost every web-based "WHOIS" tool queries its own backend. RDAP changes that: it is plain HTTPS returning JSON, which means a properly built tool can query registries directly from your browser. No relay server logging the domains you investigate — a meaningful difference when you are researching a phishing domain and would rather not announce it.

That is exactly how the WHOIS Lookup tool works: it reads the IANA bootstrap file, talks to the authoritative registry's RDAP endpoint, and renders the registrar, key dates, statuses and nameservers — all from your tab. For related checks, DNS Lookup resolves the domain's records and the Spamhaus Blacklist Checker tells you whether the domain or its infrastructure is on a reputation blocklist.

Frequently asked questions

Is WHOIS completely gone?

Not yet — many country-code registries still run it, and whois command-line clients remain popular. But for gTLDs (.com, .net, .org, .dev, .app, and hundreds more), RDAP is the official, required interface, and WHOIS is being phased out.

Why does RDAP show less data than old WHOIS pages did?

Privacy regulation, not RDAP itself. Registrars redact personal data; RDAP's structured model actually supports proper tiered access for investigators and IP lawyers that the old free-text protocol could never provide.

What does "redemption period" status mean?

The domain expired and the registrant has a grace window (typically 30 days) to restore it, usually at a premium fee. After that comes "pending delete" — a five-day window — and then the name drops and can be registered by anyone.

Can I look up a domain without anyone knowing?

Browser-based RDAP queries go directly to the registry over your own HTTPS connection — there is no intermediary logging your interest. Your network operator still sees which registry you talked to, of course, but not which domain you asked about.


Check a domain now: enter any domain in WHOIS Lookup for registrar, dates, statuses and nameservers — then pull its full DNS profile with DNS Lookup, both straight from your browser.