WHOIS Lookup
See who registered a domain, when it expires and which name servers it uses.
Related tools
- DNS LookupLook up DNS records by type, including reverse (PTR) lookups for IP addresses.
- Domain HealthOne check for DNS, email authentication, TLS, security headers and redirects, with a grade per area and a full report.
- Blacklist CheckerCheck whether an IP address or a domain's mail server is listed on DNS blocklists.
About this tool
WHOIS Lookup asks the registry for a domain’s registration record: the registrar, the creation, update and expiry dates, the status codes, the name servers and the abuse contact when one is published. It queries RDAP first - structured JSON over HTTPS, defined in RFC 9082 and RFC 9083 - using the IANA bootstrap list, and falls back to the port 43 WHOIS protocol (RFC 3912) for registries that publish no RDAP service. Enter an IP address instead of a name and the same question goes to the regional internet registry that holds the address block, returning the network range, the organisation and the abuse contact. The expiry date is turned into a warning when it is close, and each status code is explained in plain language. It reports only what the registry publishes: it does not recover redacted registrant details, tell you whether a name is free to register, or contact the owner on your behalf.
XGM asks the registry over RDAP (RFC 9082/9083, structured JSON over HTTPS) using the IANA bootstrap list, and falls back to port 43 WHOIS for registries without RDAP. Status codes are explained in plain language.
How to use it
- Open the WHOIS Lookup tool.
- Enter the public domain, hostname or IP address you want to check.
- Run the check; XGM queries it from its server and lists the findings.
- Copy the output only after checking it looks correct.
- Use related XGM tools if you need a broader diagnostic view.
FAQ
Why does the result say it was answered by WHOIS and not RDAP?
RDAP was tried first and either the TLD publishes no RDAP service in the IANA bootstrap registry (RFC 9224) or the RDAP server failed; the finding quotes the reason. The answer then comes from the port 43 WHOIS server, which returns free text that has to be parsed heuristically, so individual fields such as the updated date can be missing even when the raw response shows them. The Source line names the server that answered.
Why is there no registrant name, address or email?
Registries and registrars redact registrant contact data in the public record, so what remains is the registrar, the dates, the status codes, the name servers and, in most records, an abuse contact. XGM shows what the server returned and nothing more. The raw response below the summary is the unedited answer, so you can confirm that nothing was dropped in parsing.
What do status codes such as clientTransferProhibited mean?
They are EPP status codes set by the registrar (client...) or by the registry (server...), and each one in the result is explained next to the code. clientTransferProhibited is a transfer lock: the registrar will refuse a transfer request until you unlock the domain, which is what you want between planned transfers. When no transfer lock is present the result says so, because an unlocked domain is easier to move without your consent.
Why is the expiry date empty for this domain?
Several registries, in particular many ccTLDs, do not publish registration or expiry dates at all, and the result then shows the field as not published rather than guessing. Check the raw response for a differently named field, or the renewal date in your registrar account. An expired-looking date is never inferred from anything else.
Can I look up a subdomain such as shop.example.com?
No. Registration data exists only for the registered domain, so enter example.com; a subdomain is created in DNS and has no registry record. To see where a subdomain points, use DNS Lookup instead.
Read the full WHOIS Lookup guide