Whois Lookup: How It Works
A WHOIS lookup returns the registration record for a domain: when it was registered, when it expires, who the registrar is, and which nameservers it uses. Since privacy rules tightened, the contact details are usually redacted — but the dates and status codes still tell you a great deal.
What you still get
| Field | Why it matters |
|---|---|
| Creation date | Domain age — a strong signal in fraud assessment |
| Expiry date | Whether the domain is about to lapse |
| Registrar | Who to contact about abuse or transfers |
| Nameservers | Where DNS is actually hosted |
| Status codes | Whether the domain is locked, pending deletion, or in dispute |
| Last updated | Recent changes, which can indicate a transfer or hijack |
Why contact details are hidden
Before 2018, WHOIS exposed registrants' names, addresses, emails and phone numbers publicly. GDPR made that unlawful for personal data relating to people in the EU, and registrars applied redaction broadly rather than trying to determine jurisdiction per record. Most domains now show a privacy service or a registrar-provided forwarding address instead.
Legitimate access for law enforcement and intellectual property claims now runs through registrar request processes rather than a public query. Some registries — particularly country-code ones — remain more open, and business registrations are sometimes still published.
Status codes worth recognising
| Code | Means |
|---|---|
| clientTransferProhibited | Transfer lock on — normal and good; prevents hijacking |
| clientHold | Domain removed from DNS — usually unpaid or under complaint |
| pendingDelete | Deletion in progress; will be released shortly |
| redemptionPeriod | Expired but recoverable, usually at a high fee |
| serverTransferProhibited | Registry-level lock, often due to a dispute |
A domain you own should normally show a transfer lock. If it does not, enable it — the lock is the main defence against unauthorised transfer.
Domain age as a signal
Fraudulent sites are usually new, because they are taken down and replaced constantly. A domain registered three days ago that claims twenty years of trading is a strong warning sign, and domain age is one of the more reliable inputs to any manual fraud assessment.
The inverse does not hold. An old domain can be bought, and expired domains with history are traded precisely because age carries credibility. Age is evidence, not proof.
The expiry cycle
- Expiry date passes. Many registrars keep the domain resolving briefly.
- Grace period — typically up to 30 days for straightforward renewal.
- Redemption period — around 30 days, recoverable only at a substantial fee.
- Pending delete — around 5 days, no recovery possible.
- Released — anyone can register it.
Losing a domain by accident is common and entirely avoidable: enable auto-renew, keep the registrar contact email current and separate from the domain itself, and set an independent calendar reminder rather than trusting renewal notices to reach you.
RDAP
The Registration Data Access Protocol is WHOIS's structured successor, returning JSON with proper internationalisation and standardised access controls. It is now the required protocol for generic top-level domains, and most lookup tools query it behind a familiar WHOIS-style interface.