Skip to content

WHOIS Lookup guide

Tool guide. Updated .

How to read a WHOIS record with the XGM WHOIS Lookup: registrar, creation and expiry dates, EPP status codes, name servers and why some data is hidden.

What WHOIS is

WHOIS is one of the oldest internet directory services. Registries and registrars answer queries on TCP port 43 with the registration record of a domain: the sponsoring registrar, important dates, status codes and name servers. The protocol itself (RFC 3912) is simple text with no fixed format, so each registry formats its answers a little differently.

RDAP (Registration Data Access Protocol) is the structured, JSON-based successor to WHOIS and is now the standard way generic top-level domain registries publish registration data. WHOIS on port 43 still answers for many TLDs, and it remains a quick way to read the essentials. The XGM WHOIS Lookup asks the registry over RDAP first, using the IANA bootstrap list of RDAP servers, and falls back to the WHOIS server for the TLD when a registry has no RDAP service.

How a WHOIS lookup finds the recordXGM looks up the RDAP server for the TLD in the IANA bootstrap list and reads the JSON record; without RDAP it picks the WHOIS server for the TLD, follows a referral from IANA when needed and parses the text response.Domain example.comThe top-level domain is comRDAP server from the IANA bootstrap listhttps://rdap.verisign.com/com/v1/ for comRDAP query over HTTPSJSON with events, entities, name servers andstatus; WHOIS on port 43 if RDAP isunavailableRaw responseRegistrar, dates, status codes, name servers,abuse contact, often redacted registrant dataSummary and findingsExpiry countdown, transfer lock, raw text fordetails
XGM looks up the RDAP server for the TLD in the IANA bootstrap list and reads the JSON record; without RDAP it picks the WHOIS server for the TLD, follows a referral from IANA when needed and parses the text response.

How to use the WHOIS Lookup

  1. Open the WHOIS Lookup and enter a registered domain, such as example.com. Subdomains have no WHOIS record of their own; use the registered domain.
  2. XGM asks the registry's RDAP server from its server; if the TLD has no RDAP service or it fails, it queries the WHOIS server for the TLD and follows referrals. The result says which source answered.
  3. Read the summary: registrar, creation, updated and expiry dates, name servers, the registrar's abuse contact and each status code explained in plain language.
  4. Check the findings for expiry and transfer lock, and open the raw response for anything not in the summary.

Some country-code TLD registries limit what they publish over WHOIS, or publish dates in a format the summary cannot read. In that case the finding says the expiry date is not published, and the raw response or the registrar's control panel has the details.

Reading the record

Fields in the summary
FieldMeaning
RegistrarThe company the domain is registered through; changes to the registration go through it
Creation dateWhen the domain was first registered (not necessarily by the current owner)
Updated dateThe last change to the registration record, such as contacts or name servers
Expiry dateWhen the current registration period ends unless renewed
Name serversThe authoritative DNS servers the registry delegates the domain to
StatusEPP status codes describing locks and lifecycle state
Shortened WHOIS response for a .com domain
Domain Name: EXAMPLE.COM
Registrar: Example Registrar, Inc.
Creation Date: 1995-08-14T04:00:00Z
Updated Date: 2026-08-14T07:01:34Z
Registry Expiry Date: 2027-08-13T04:00:00Z
Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Name Server: NS1.EXAMPLE.NET
Name Server: NS2.EXAMPLE.NET
DNSSEC: signedDelegation

The name servers in WHOIS come from the registry and show where the domain is delegated. If they differ from where you edit your DNS records, your changes are going to a zone nobody queries, which is a common cause of "DNS changes have no effect". Compare them with the NS records in DNS Lookup.

EPP status codes

Status codes come from the Extensible Provisioning Protocol used between registrars and registries. Codes starting with client are set by the registrar, codes starting with server by the registry. ICANN publishes an explanation of every code, and the WHOIS output often links to it.

Common EPP status codes
StatusMeaning
ok / activeNo restrictions; normal state
clientTransferProhibitedTransfers to another registrar are blocked until the registrar removes the lock
clientUpdateProhibitedChanges to the registration are blocked
clientDeleteProhibitedThe domain cannot be deleted
serverTransferProhibited and other server… codesLocks set by the registry, often as part of a registry lock service or a legal hold
clientHold / serverHoldThe domain is not published in DNS; it does not resolve
redemptionPeriodThe registration was deleted after expiry; restoring it usually costs extra
pendingDeleteThe domain will be released for registration soon
pendingTransferA transfer to another registrar is in progress

Registry lock for important domains

client…Prohibited locks can be removed by anyone who gets into your registrar account. Registry lock adds server…Prohibited codes that need a manual, verified process at the registry to remove, which protects high-value domains against account takeover.

What the findings mean

WHOIS Lookup findings
FindingSeverityAction
Registration expired n days agoCriticalRenew immediately at the registrar; the domain may already have stopped resolving.
Registration expires in n days (under 30)WarningConfirm auto-renew and a valid payment method.
Registered until … (n days)PassedNo action; the registrar is shown for reference.
Expiry date not publishedInfoCheck the raw response or the registrar; some registries hide dates.
No transfer lockInfoAsk the registrar to enable clientTransferProhibited unless a transfer is planned.

Privacy and redacted data

Since 2018, most registrars and registries redact personal contact data such as the registrant's name, address and email for generic TLDs, largely because of data protection laws. The record often shows "REDACTED FOR PRIVACY" or a proxy service instead. That is normal and not a sign that something is wrong with the domain.

To contact a domain owner, use the contact form or anonymised email address the registrar publishes in the record. For abuse such as phishing or malware on a domain, the registrar's abuse contact in the WHOIS output is the right address, together with the hosting provider of the IP address the domain points to.

Avoiding accidental expiry

Expired domains stop resolving, which takes down websites and mail. After a grace period they can be deleted and registered by someone else, who then receives any mail and traffic that still arrives. The costs of that are far higher than a renewal fee.

  • Enable auto-renew and keep the payment method up to date.
  • Use a role address, not a personal inbox, as the registrar account's contact.
  • Renew important domains for several years at a time.
  • Monitor expiry dates of every domain you own, including old brand and campaign domains.
  • Keep old domains after a rename; see the domain migration checklist.

FAQ

Why is the owner's name hidden?

Most registrars redact personal data for privacy and legal reasons. Use the registrar's contact form or the published abuse address instead.

What is the difference between WHOIS and RDAP?

RDAP is the structured, JSON-based successor to WHOIS with standard fields and access control. WHOIS is plain text with registry-specific formats.

Can I look up a subdomain?

No. Registration data exists for registered domains such as example.com, not for names under them such as www.example.com.

What happens when a domain expires?

It usually stops resolving within days, enters a grace or redemption period during which the owner can still renew, and may later be deleted and become available to others.

What does clientTransferProhibited mean?

The registrar has locked the domain against transfers to another registrar. It protects against unauthorised transfers and is removed at the registrar when you want to move.

Why do the name servers in WHOIS differ from my DNS provider?

The domain is delegated somewhere other than where you are editing records. Update the name servers at the registrar, or edit DNS where the domain is actually delegated.

Does the lookup work for every TLD?

It uses RDAP wherever the IANA bootstrap list has a server, and WHOIS otherwise. Some ccTLD registries publish neither dates nor RDAP, so some fields may be missing from the summary.

Sources