WHOIS Domain Lookup: How to Read Current RDAP Registration Data

A current guide to WHOIS-style domain lookup after the transition to RDAP, including field meanings, privacy redaction, scam checks, and verification limits.

Short answer

A current guide to WHOIS-style domain lookup after the transition to RDAP, including field meanings, privacy redaction, scam checks, and verification limits.

What not to assume

  • Do not assume an email match confirms who owns or uses an address.
  • Do not assume reverse email results are current or complete.
  • Do not use email lookup data for regulated decisions about people.

Safer next steps

  • Read related email privacy and opt-out guides on Lookup Plainly.
  • Treat matches as leads that need independent verification.
  • Use account-security steps from official providers when appropriate.

Key takeaways

Quick answer: use ICANN Lookup and read the result as registration data

A WHOIS domain lookup now commonly means an RDAP registration-data search. Enter the domain, not a full page URL, into ICANN's free Registration Data Lookup Tool. Review the registrar, registration and expiration dates, domain status codes, nameservers, and any available contact or abuse information.

Do not treat a match as proof of website ownership or safety. Registration data describes a domain registration and may be redacted. It does not authenticate every person, email, product, or payment page using the domain.


WHOIS vs RDAP in plain English

WHOIS is the familiar name for looking up registration details. RDAP is the newer, structured protocol designed to replace legacy WHOIS. ICANN phased out certain WHOIS obligations for generic top-level-domain registries and registrars in January 2025, making RDAP the definitive source for that data.

RDAP supports standardized responses, HTTPS transport, internationalization, and differentiated access. Human-facing tools such as ICANN Lookup turn its structured response into readable fields.

How to perform a domain lookup

  1. Copy the domain only, such as example.org.
  2. Remove https://, paths, query strings, and email usernames.
  3. Open ICANN Lookup at lookup.icann.org.
  4. Submit the domain and open the result.
  5. Note the registrar, creation date, expiration date, update date, and status codes.
  6. Review nameservers and DNSSEC information if relevant.
  7. Expand remarks, notices, and the raw RDAP response when a field is unclear.
  8. Combine the result with independent business, security, and contact checks.

Country-code domains can follow policies set by their own registry. Coverage and displayed fields therefore vary.

Important fields and what they mean

FieldUseful interpretationCommon overreach
RegistrarCompany sponsoring the registrationAssuming the registrar operates the website
Creation dateDate the current registration object was createdTreating it as the age of the business or content
Expiration dateCurrent registry expiration valueAssuming the site will disappear on that date
Updated dateA registry or registrar update occurredAssuming the website content changed then
NameserversDNS infrastructure designated for the domainTreating the provider as the site owner
Status codesRegistry protections or lifecycle stateCalling every locked status suspicious
Registrant/contactPublicly available registration contact dataAssuming it identifies the actual site operator

Why contact information is redacted

Domain registration data is limited by applicable law and policy. Public results may display “redacted for privacy,” a privacy/proxy service, or no personal contact fields. Some data may be available only through a legitimate-interest disclosure process.

Redaction is routine. It neither proves fraud nor guarantees privacy. Abuse contacts and registrar channels may still be available for reporting.

Domain status codes

Status labels such as clientTransferProhibited commonly indicate that a registrar lock prevents an unauthorized transfer. Other codes can relate to renewal, deletion, disputes, or registry actions.

Read the linked ICANN explanation before interpreting a status. A lock can be protective, while a pending-delete state can be operationally important. The label alone does not reveal why a website behaves a certain way.

Using registration data for scam checks

A newly registered domain deserves more scrutiny when a message also includes urgency, impersonation, unusual payment methods, or a login link you did not request. It is not enough on its own.

Check several independent signals:

An old domain can be compromised, sold, or repurposed. A new domain can belong to a legitimate launch.

Domain lookup vs IP lookup vs email lookup

A domain RDAP result is not the same as an IP-allocation lookup. IP addresses and autonomous system numbers are managed through regional internet registry data. It is also not a reverse email directory.

For an email address, email lookup explains what directories can and cannot infer. For breach exposure, see data breach lookup. Never paste a password or private token into a lookup site.

No result, conflicting dates, or unfamiliar registrar

No result: verify the spelling and top-level domain. The registry may have different service coverage or the domain may be unregistered.

Different dates across tools: cached third-party pages can lag. Prefer the current authoritative RDAP response and read which object supplied each field.

Unfamiliar registrar: registrars often serve customers through resellers. The registrar name is not a trust score.

Privacy-service name: this may be a proxy contact, not the beneficial website operator.

Responsible use

Use public registration data to understand infrastructure, contact the proper abuse channel, or verify a technical claim. Do not use exposed contact data for harassment, spam, or unsupported accusations.

Lookup Plainly is not ICANN, a registrar, a cybersecurity incident-response provider, or an identity-verification service.

Domain lookup checklist

Bottom line

WHOIS remains the familiar search phrase, but RDAP is the current protocol behind modern domain-registration lookup. Use the result to understand registration facts, not to declare an owner, identity, or website trustworthy without corroboration.

Important use limitation

Lookup Plainly is not a Consumer Reporting Agency and does not provide consumer reports, background checks, live lookup results, or identity verification. Information on this site must not be used for employment, tenant screening, credit, insurance, or any other regulated eligibility decision.

This article is general information only. It is not legal advice and does not replace official records, carriers, or regulators.

These related guides continue the same topic without treating lookup results as proof.

Sources and references

Lookup Plainly articles are written for careful, general education. Editorial and legal review may update wording as sources and policies change.