Skip to content
Traffgate Review

Reading the web without overreading the name

NL-005 Name Limits

What WHOIS and RDAP Still Show About a Domain

WHOIS is being phased out in favor of RDAP. Learn what registration data can still tell you about a domain, and what redaction and the protocol change have taken away.

Reading a domain's registration data alongside a printed record.
Reading a domain's registration data alongside a printed record.

WHOIS and RDAP are lookup services that return a domain's registration data: its registry, its registrar, and key dates. They do not return a domain's history, ownership story, or past content. As of January 28, 2025, the protocol itself has mostly changed too: RDAP, not WHOIS, is now the required service for generic top level domains (ICANN, https://www.icann.org/rdap).

What Is the Difference Between WHOIS and RDAP?

WHOIS is an older, plain text lookup protocol with no standard output format, which made automated reading unreliable across registries. RDAP, the Registration Data Access Protocol, was built by the Internet Engineering Task Force as its replacement. It returns registration data in standardized query and response formats, and supports internationalization, secure access to data, and the discovery of authoritative servers (ICANN, https://www.icann.org/rdap). The underlying registration facts are similar. The format and the access rules around them are what changed.

When Did RDAP Actually Replace WHOIS?

The transition was not instant. ICANN's own RDAP page states that all generic top level domain registries and registrars are required to provide RDAP services under the gTLD RDAP Profile, and that as of January 28, 2025 they are no longer required to provide WHOIS services, with three exceptions: .com, .name, and .post (ICANN, https://www.icann.org/rdap). In practice this means a lookup tool that only speaks WHOIS can fail or return less for a gTLD whose operators have stopped running it, while an RDAP query against the same domain is the service they are required to keep.

What Can a Registration Record Still Tell You?

A current record can reliably show:

Field What it tells you What it does not tell you
Registry/registrar Who sells and administers the name Who actually controls the content
Creation date When the current registration was created (it resets if the name lapsed and was registered again) When any website on it was first published
Expiration date When the registration must be renewed Whether the site is still active
Status codes Whether a transfer or deletion lock is set Why the owner set that lock
Name servers Which DNS provider currently answers for the name What that provider's customer intends

This is the same caution the site applies elsewhere: a record is evidence of registration, not evidence of a website's content or intent. See What a Domain String Can and Cannot Prove for the parallel limit on the name itself.

What Does Privacy Redaction Hide?

In many public gTLD records today, the registrant's personal contact details are redacted, or replaced by the contact details of a privacy or proxy service. This is a common practice, not a sign of concealment specific to one domain. A redacted record simply means the personal data is not published in the public output. It does not tell you whether the underlying registrant is an individual, a company, or a reseller.

Can You Still Find Historical Registration Data?

A live RDAP or WHOIS query only returns the current record. If a domain changed hands, its registration dates and name servers may have changed too, and a live query will not show the earlier version. Historical registration snapshots exist only where someone archived them before the change, which is a different kind of evidence than a current lookup, and carries the same reading caution as any other archived page. See Using the Wayback Machine as a Primary Source for how to treat an archived snapshot once you have one.

How Should You Cite a Registration Lookup?

Record the exact date you ran the query, the service you used (an RDAP client or a registrar's lookup page), and the raw output if possible. Because registration data can change at renewal, a transfer, or a privacy setting update, a lookup from last year is not proof of this year's state. State the date of your own lookup explicitly, the same way the archived timestamps on this site are treated as capture dates, not publication dates.

A Short Checklist Before You Rely on a Registration Record

  1. Confirm you are reading a current RDAP result, not a cached WHOIS output from an older tool.
  2. Note the creation and expiration dates, and whether the record has been renewed recently.
  3. Check whether contact fields are redacted by a privacy service, and treat that as normal.
  4. Do not infer ownership, intent, or website content from registry or name server fields alone.
  5. If you need a past registration state, look for an archived record from before the date in question, and cite its capture date.

Registration data answers one narrow question well: who is administratively responsible for a name right now, and since when. For anything beyond that, the record itself says nothing, and the honest move is to say so rather than to fill the gap with a plausible guess.

Neighbouring entries