Look up the full registration record for any domain, IP address, or AS number. See the registrar, key dates, name servers, DNSSEC and status codes in plain English, with the raw WHOIS or RDAP record one click away. Uses the modern RDAP standard with a WHOIS fallback for country domains. No sign-up.
A WHOIS lookup shows the public registration record behind a domain name, IP address, or AS number: who the registrar is, when the domain was registered and when it expires, which name servers it points to, and what its status codes mean. ToolsPivot runs this lookup on its own server using the modern RDAP standard, falls back to classic WHOIS for the country domains that still need it, and returns a clean, sectioned report with the full raw record one click away. There is no account to create, no CAPTCHA to clear, and no daily query cap.
A WHOIS lookup answers a simple question: who is behind this domain, and what is its registration status? The record is held by the registry that runs the domain ending (for example, Verisign for .com) and the registrar where the domain was bought (GoDaddy, Namecheap, Cloudflare, and so on). Between them they publish the registrar name and its abuse contact, the created, updated, and expiry dates, the name servers, the DNSSEC status, and a set of status codes that describe what the domain can and cannot do right now.
What you often will not see is the owner's name and personal contact details. Since privacy rules tightened, most generic domains hide that information by default, which surprises people running their first lookup. The registration facts are still public and useful on their own, and they are usually enough to research a domain before buying it, verify a name server change after a migration, or flag a suspicious site. For a fuller picture of where a domain resolves, a WHOIS record pairs naturally with a DNS lookup, which reads the live A, MX, TXT, and NS records that WHOIS does not carry.
Enter a domain, an IP address, or an AS number, and the tool decides how to fetch the record. For domains it queries RDAP first, the Registration Data Access Protocol that ICANN required registries and registrars to run from 2019 and that replaced the old mandatory port-43 WHOIS for generic domains in early 2025. RDAP returns clean, structured data instead of the free-form text that classic WHOIS produces, which is why the results come back in labeled sections rather than a wall of unformatted output.
To reach the right server, the tool reads the official IANA bootstrap file, the master list that maps each domain ending to its registry's RDAP endpoint, and caches that list for a week. It then queries the registry directly. Generic domains use a "thin" model, where the registry holds the dates, name servers, status, and registrar but not the owner's contact fields. Those live with the registrar, so the tool follows the link in the registry's response to the registrar's own RDAP record and reads the registrant, administrative, and technical contacts from there. That extra hop is how it recovers contact fields that a registry-only lookup leaves blank.
Roughly three-quarters of country-code endings, including .de, .io, .co, and .jp, have no RDAP server yet. For those the tool falls back to classic port-43 WHOIS: it asks IANA which server is authoritative for that ending, queries it, and for thin endings follows one more hop to the registrar's WHOIS server. A few registries need special handling, which happens automatically, such as the specific query flag DENIC expects for .de and the English-record request JPRS needs for .jp. For generic domains, the tool also pulls the port-43 record in the background so the familiar raw WHOIS text sits alongside the structured RDAP data.
The report is grouped so you can scan it instead of parsing it. Each block answers one part of the record.
The dates section is where domain investors and buyers spend the most time, because age and expiry carry real signals. A domain first registered fifteen years ago tends to carry more trust than one registered last week, and the expiry date tells you whether a name might soon be available if the current owner lets it lapse. To turn the raw creation date into a clean age figure, run the same domain through the domain age checker, and if you are weighing a purchase, check whether close variants are still open with the domain availability checker.
Status codes describe what the domain is allowed to do. A status of "ok" means the domain is active with no restrictions. Codes beginning with "client" were set by the registrar, usually at the owner's request, so clientTransferProhibited simply means the owner has locked the domain against transfers, which is good hygiene rather than a warning sign. Codes beginning with "server" were set by the registry itself. If you see redemptionPeriod, the domain has expired and sits in a recovery window; pendingDelete means it is about to be released back to the public. Because the tool labels each code and explains it on hover, you do not need to keep ICANN's status-code glossary open in another tab.
If a lookup returns "REDACTED FOR PRIVACY" instead of a name, that is by design, not a fault in the record. Since the GDPR took effect in 2018, most generic-domain records hide the registrant's name, address, phone number, and personal email. Two forces drive this: registrar privacy or proxy services, which many registrars include free and which swap in the proxy's details, and the data-protection rules that require registrars to redact personal data for registrants in the relevant jurisdictions.
Plenty stays visible even so. The registrar and its IANA ID, the dates, the name servers, the status codes, the DNSSEC state, and the registrar's abuse contact all remain public. When the identity is redacted, the tool explains why and points you to the public abuse contact and, where the registrar offers one, a registrant contact form, so you can still reach the owner without their address. For a legitimate legal or law-enforcement need, ICANN's Registration Data Request Service provides a formal channel to ask a registrar for the redacted fields. If you are trying to identify the organization behind a redacted site, an SSL certificate check often names it in the certificate, and a hosting checker shows which provider serves the site.
The same box accepts more than domains. Enter an IP address or an AS number and the tool queries RDAP for internet number resources, which routes to the correct regional registry: ARIN for North America, RIPE NCC for Europe and the Middle East, APNIC for Asia-Pacific, LACNIC for Latin America, and AFRINIC for Africa. The result gives the network name, the address range and CIDR block, the owning organization, the country, the allocation date, and the abuse contact for that block.
This is the fast way to find out who controls the address a domain sits on, or to trace the operator behind a range that keeps appearing in your logs. If you have a domain and want the address it resolves to first, the domain to IP tool makes that conversion, and you can confirm your own address any time with the IP address checker before running a lookup on it.
People pull WHOIS records for very different reasons, and the same report serves each of them differently.
Before spending real money on a name, investors confirm the expiry date, check that the domain is not locked in a dispute, and read the age as a rough proxy for trust and resale value. A name that expires soon can sometimes be backordered; one locked with serverTransferProhibited will not move easily. Investors often check the same domain's domain authority to weigh its SEO standing alongside its registration history.
Phishing and scam domains share patterns a WHOIS record exposes fast: a registration only days old, privacy switched on the moment it was created, and a registrar known for slow abuse response. A domain registered forty-eight hours ago with hidden ownership is worth a second look. Analysts pair the record with a blacklist lookup and a website safety checker to turn a hunch into a triage decision, and use the abuse contact in the record to file a report.
Before moving a site, developers confirm the name servers, make sure the domain will not expire mid-migration, and note the registrar in case DNS needs changing. WHOIS gives all of that in one lookup. Checking the server status at the same time confirms the origin is responding before any traffic gets redirected.
A WHOIS lookup on a prospective vendor or a suspicious lookalike domain shows whether the name was registered yesterday or a decade ago. For a trademark complaint under the UDRP process, the record documents who registered an infringing domain, when, and through which registrar, which is the starting evidence a filing needs. Marketers assessing a link source or partner site sometimes run the domain through a backlink checker as well to judge its reach.
Honesty first: RDAP-first lookups, WHOIS fallback for country domains, DNSSEC display, and IP and ASN support are no longer unusual. Several good free tools now do all of that, and any page claiming these as exclusive features is overselling. What is worth pointing out is narrower and true.
A WHOIS lookup has real limits, and it is better to know them upfront than to misread a result. The record is a snapshot from RDAP or the registry, not a live authoritative feed, so it can lag reality by a few minutes after a change. Some country-code registries publish only limited data, and a few restrict public access to contact details entirely, which is a policy of that registry rather than a gap in the tool. Owner details are usually redacted by design, so an empty registrant field is the norm for generic domains, not a sign the lookup failed. And WHOIS accuracy depends on registrants keeping their records current; dates and registrar fields are the most reliable, while contact details on older domains are the least. Lookups run on the ToolsPivot server and are not logged, stored, or shared.
A WHOIS lookup retrieves the public registration record for a domain, IP address, or AS number, showing the registrar, key dates, name servers, status codes, and, when they are public, the contact details. ICANN requires registrars to maintain these records, and anyone can query them. Results usually appear within seconds.
WHOIS is the original protocol that returns free-form plain text, while RDAP returns the same registration data as structured JSON over HTTPS. RDAP replaced the mandatory port-43 WHOIS for generic domains in early 2025 and gives uniform formatting, better internationalization, and selective privacy redaction. This tool queries RDAP first and falls back to WHOIS where RDAP is not yet available.
That means the owner's personal details are hidden, either by a registrar privacy service or by data-protection rules such as the GDPR. You can still see the registrar, the dates, the name servers, the status codes, and the abuse contact. The tool points you to the abuse contact and, where available, a registrant contact form so you can still reach the owner.
Yes, it is free with no sign-up, no CAPTCHA, and no daily limit. You can run as many lookups as you need. There are no premium tiers or feature locks.
You can find the registered owner only when they have not enabled privacy protection and no redaction rule applies, which for most generic domains means the name is hidden. Even then, the registrar, registration dates, name servers, and status codes stay visible and often point toward the owner indirectly.
Yes. Because roughly three-quarters of country-code endings have no RDAP server yet, the tool falls back to classic WHOIS for them and handles registry quirks automatically, such as the flag DENIC needs for .de and the English-record request for .jp. Some country registries publish less data than generic domains do.
Yes. Enter an IP address or an AS number and the tool queries the correct regional registry, whether that is ARIN, RIPE NCC, APNIC, LACNIC, or AFRINIC. It returns the network name, the address range and CIDR, the owning organization, the country, the allocation date, and the abuse contact.
EPP status codes describe what actions a domain currently allows. Common ones include ok (no restrictions), clientTransferProhibited (the owner has locked transfers), and pendingDelete (the domain is about to be released). The tool shows each code with a plain-English explanation on hover, drawn from ICANN's canonical list.
Registration dates and registrar information are the most reliable fields, since the registry maintains them. Contact details are the least reliable, especially on older domains whose owners may have moved or changed email. The record is a snapshot and can lag a live change by a few minutes.
Yes. Bulk mode accepts several entries at a time, one per line, and returns a separate card for each domain, IP, or AS number. This saves running the same lookup over and over when you are vetting a list.
No. Lookups run on the ToolsPivot server and are not logged, stored, or shared. Results are cached briefly to keep repeat queries fast and to stay within the rate limits that registry and registrar servers enforce, but your search history is not kept.