Quick answer: use ICANN Lookup and read the result as registration data
A WHOIS domain lookup now commonly means an RDAP registration-data search. Enter the domain, not a full page URL, into ICANN's free Registration Data Lookup Tool. Review the registrar, registration and expiration dates, domain status codes, nameservers, and any available contact or abuse information.
Do not treat a match as proof of website ownership or safety. Registration data describes a domain registration and may be redacted. It does not authenticate every person, email, product, or payment page using the domain.
WHOIS vs RDAP in plain English
WHOIS is the familiar name for looking up registration details. RDAP is the newer, structured protocol designed to replace legacy WHOIS. ICANN phased out certain WHOIS obligations for generic top-level-domain registries and registrars in January 2025, making RDAP the definitive source for that data.
RDAP supports standardized responses, HTTPS transport, internationalization, and differentiated access. Human-facing tools such as ICANN Lookup turn its structured response into readable fields.
How to perform a domain lookup
- Copy the domain only, such as
example.org. - Remove
https://, paths, query strings, and email usernames. - Open ICANN Lookup at
lookup.icann.org. - Submit the domain and open the result.
- Note the registrar, creation date, expiration date, update date, and status codes.
- Review nameservers and DNSSEC information if relevant.
- Expand remarks, notices, and the raw RDAP response when a field is unclear.
- Combine the result with independent business, security, and contact checks.
Country-code domains can follow policies set by their own registry. Coverage and displayed fields therefore vary.
Important fields and what they mean
| Field | Useful interpretation | Common overreach |
|---|---|---|
| Registrar | Company sponsoring the registration | Assuming the registrar operates the website |
| Creation date | Date the current registration object was created | Treating it as the age of the business or content |
| Expiration date | Current registry expiration value | Assuming the site will disappear on that date |
| Updated date | A registry or registrar update occurred | Assuming the website content changed then |
| Nameservers | DNS infrastructure designated for the domain | Treating the provider as the site owner |
| Status codes | Registry protections or lifecycle state | Calling every locked status suspicious |
| Registrant/contact | Publicly available registration contact data | Assuming it identifies the actual site operator |
Why contact information is redacted
Domain registration data is limited by applicable law and policy. Public results may display “redacted for privacy,” a privacy/proxy service, or no personal contact fields. Some data may be available only through a legitimate-interest disclosure process.
Redaction is routine. It neither proves fraud nor guarantees privacy. Abuse contacts and registrar channels may still be available for reporting.
Domain status codes
Status labels such as clientTransferProhibited commonly indicate that a registrar lock prevents an unauthorized transfer. Other codes can relate to renewal, deletion, disputes, or registry actions.
Read the linked ICANN explanation before interpreting a status. A lock can be protective, while a pending-delete state can be operationally important. The label alone does not reveal why a website behaves a certain way.
Using registration data for scam checks
A newly registered domain deserves more scrutiny when a message also includes urgency, impersonation, unusual payment methods, or a login link you did not request. It is not enough on its own.
Check several independent signals:
- Type the known organization's official domain manually.
- Compare the exact spelling, including substituted letters and extra words.
- Verify contact details from an existing statement or official directory.
- Do not sign in through an unexpected email or text link.
- Search official regulator or business records where relevant.
- Treat browser padlocks as encryption indicators, not legitimacy badges.
An old domain can be compromised, sold, or repurposed. A new domain can belong to a legitimate launch.
Domain lookup vs IP lookup vs email lookup
A domain RDAP result is not the same as an IP-allocation lookup. IP addresses and autonomous system numbers are managed through regional internet registry data. It is also not a reverse email directory.
For an email address, email lookup explains what directories can and cannot infer. For breach exposure, see data breach lookup. Never paste a password or private token into a lookup site.
No result, conflicting dates, or unfamiliar registrar
No result: verify the spelling and top-level domain. The registry may have different service coverage or the domain may be unregistered.
Different dates across tools: cached third-party pages can lag. Prefer the current authoritative RDAP response and read which object supplied each field.
Unfamiliar registrar: registrars often serve customers through resellers. The registrar name is not a trust score.
Privacy-service name: this may be a proxy contact, not the beneficial website operator.
Responsible use
Use public registration data to understand infrastructure, contact the proper abuse channel, or verify a technical claim. Do not use exposed contact data for harassment, spam, or unsupported accusations.
Lookup Plainly is not ICANN, a registrar, a cybersecurity incident-response provider, or an identity-verification service.
Domain lookup checklist
- Search the registrable domain, not the full URL.
- Prefer ICANN Lookup or the authoritative registry RDAP service.
- Note registrar, dates, status, and nameservers.
- Expect lawful redaction.
- Check spelling and independent contact channels.
- Do not rely on domain age alone.
- Do not equate HTTPS with legitimacy.
- Report abuse through the registrar or relevant official channel.
Bottom line
WHOIS remains the familiar search phrase, but RDAP is the current protocol behind modern domain-registration lookup. Use the result to understand registration facts, not to declare an owner, identity, or website trustworthy without corroboration.
