RDAP is the structured successor to port-43 WHOIS and is now the official source for gTLD registration data. This tool queries the right registry automatically for domains, IPv4/IPv6 addresses and AS numbers.
Table of Contents
Using it for abuse and migrations
For an attacking IP, the abuse contact shown is where to send logs. For a domain you are migrating, check the expiry date, the clientTransferProhibited status (the registrar lock) and the name servers before you start.
Many ccTLDs still lack RDAP; if a lookup fails, use the registry’s own WHOIS page.
WHOIS lookup at a glance



How to use this tool
- Type a registered domain such as
example.com, an IPv4 or IPv6 address such as203.0.113.10, or an AS number written asAS13335or just13335. - You can paste a full URL. The tool removes
https://, the path and any port, and converts internationalised names to punycode before the lookup. - Enter the registered name, not a host inside it. Registries only know
example.com, sowww.example.comormail.example.comreturns “Not found in RDAP”. - Press Look up. The query goes to rdap.org, which redirects it to the registry that is authoritative for that TLD, IP block or AS number. A repeat of the same query within five minutes is answered from cache.
How to read the results
The fields depend on what you looked up. Every value comes from the registry record, not from your registrar’s account page, so dates and contacts can differ slightly from what your registrar shows.
| Field | Shown for | What it means |
|---|---|---|
| Registrar | Domain | The ICANN-accredited company that manages the registration, with its contact email when the registry publishes one. A reseller or hosting company you pay may not appear here. |
| Registered | Domain | Date the domain was first created at the registry. It does not reset when the domain moves to another registrar. |
| Expires | Domain | Expiry date at the registry and the days left. Shown as a warning when fewer than 30 days remain. |
| Last changed | Domain | Last time the registry record was updated, for example a name server or status change. |
| Status | Domain | The EPP status codes, written the RDAP way: client transfer prohibited is the RDAP form of clientTransferProhibited. See the table below. |
| DNSSEC | Domain | signed means a DS record is published at the registry, so validating resolvers expect signed answers. unsigned means no DS record. |
| Name servers | Domain | The delegation stored at the registry. This list, not the NS records inside your zone, decides which servers the internet asks. |
| Network, Range, Country | IP | The block the address belongs to, its registry handle and the country registered for it. |
| Organisation, Abuse contact | IP, AS | Who the regional internet registry lists as holder of the block or AS, and where to send abuse reports. |
| Reverse DNS | IP | The PTR hostname of the address, or none. |
| AS name, Handle | AS | The registered name and handle of the autonomous system. |
Domain status values
| RDAP status | EPP code | What it means for you |
|---|---|---|
| active | ok | No locks and no pending operations. |
| client transfer / update / delete prohibited | clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited | Locks set by the registrar. Normal and recommended. Remove the transfer lock in the registrar panel before a transfer. |
| server transfer / update / delete prohibited | serverTransferProhibited and similar | Locks set by the registry, for example a registry lock or a dispute. Only the registrar can ask the registry to lift them. |
| client hold, server hold | clientHold, serverHold | The domain is not published in DNS and does not resolve. Common causes: unpaid renewal, unverified registrant email, abuse report. Contact the registrar. |
| inactive | inactive | No name servers are set, so the domain does not resolve. |
| add period | addPeriod | Grace period right after registration. Informational. |
| auto renew period | autoRenewPeriod | The registration term ended and the registry renewed it automatically. The registrar can still renew or delete it during this grace period. |
| redemption period | redemptionPeriod | The domain was deleted. It stays here for 30 days and can be restored through the registrar, usually for a restore fee. |
| pending delete | pendingDelete | Redemption ended without a restore. The domain is purged and becomes available again a few days later. |
| pending transfer | pendingTransfer | A transfer to another registrar is in progress. If you did not request it, contact your registrar immediately. |
Common problems and how to fix them
“Not found in RDAP. The domain may be unregistered, or its registry does not offer RDAP yet.”
rdap.org answers 404 when it knows no authoritative RDAP service for the name, and registries answer 404 for names they do not hold. Check three things: you entered the registered domain and not a subdomain, the spelling is right, and the TLD has an RDAP server. Several country-code registries still offer only port-43 WHOIS or a web form. For those, query WHOIS from a shell:
# AlmaLinux / Rocky
dnf install whois
# Ubuntu / Debian
apt install whois
whois example.com
On Windows there is no built-in whois command; Microsoft’s Sysinternals suite includes one.
“Enter a domain, IP address or AS number.”
The input did not parse as any of the three. Typical causes: an email address (user@example.com), a space inside the AS number (AS 13335) or stray characters copied from a document. Enter example.com or AS13335 with no spaces.
“The registry returned an unreadable response (HTTP 429)” or “RDAP lookup failed”
An unreadable response with a code such as 429 or 503, or a timeout, means the redirect service or the registry is rate limiting or slow. rdap.org documents a limit of 10 requests in 10 seconds, and registries apply their own limits. Wait a minute and try again. You can also query RDAP directly; -L follows the redirect to the registry:
curl -sL https://rdap.org/domain/example.com | python3 -m json.tool
The expiry date is a year later than expected, or already in the past
Many gTLD registries renew a domain automatically on its expiry date and give the registrar a grace period to delete it, so the registry date can move forward a year before you have paid. The status then shows auto renew period. Your registrar account is the only place that shows whether the renewal was paid. A date in the past with redemption period or pending delete means the domain has already been deleted.
The domain stopped resolving after a DNS move and DNSSEC shows “signed”
A DS record still points at the old DNS provider’s keys, so validating resolvers such as 1.1.1.1 and 8.8.8.8 reject every answer from the new name servers with SERVFAIL. Remove the DS record at the registrar, or replace it with the DS record from the new provider. Confirm with:
dig +short DS example.com
dig example.com A +dnssec @1.1.1.1
The DNSSEC checker shows where the chain of trust breaks.
Name servers here differ from the NS records in your DNS zone
The registry list is the one resolvers use. Changing NS records inside your zone (in cPanel Zone Editor, Plesk or Cloudflare) does not move the domain. Change the name servers at the registrar, then follow the change with the DNS propagation checker.
An IP lookup shows Cloudflare or another CDN, not the hosting company
A proxied site resolves to the CDN’s addresses, so the RDAP record belongs to the CDN. The origin server is hidden on purpose. Send abuse reports for such a site to the CDN’s abuse form; it forwards them to the host.
WHOIS and RDAP: what changed
Classic WHOIS runs on TCP port 43 and returns free-form text that differs between registries. RDAP returns structured JSON over HTTPS, uses standard status names and supports redaction of personal data. ICANN made RDAP the definitive source of gTLD registration data on 28 January 2025, in place of the sunsetted WHOIS services. Some port-43 servers still answer, but tools and scripts should move to RDAP.
IP addresses and AS numbers are not handled by ICANN registrars but by the five regional internet registries: ARIN, RIPE NCC, APNIC, LACNIC and AFRINIC. All of them run RDAP, which is why this tool can show the holder and abuse contact for any public address. For mail problems with a specific IP, also check the reverse DNS and the blacklist status.
Official documentation: AlmaLinux wiki, Linux man pages.
Related guides: Adding MailBaby SPF, DKIM and DMARC records in Cloudflare DNS · Cloudflare Tunnel (cloudflared): expose an internal service without opening ports · Cloudflare in front of cPanel: DNS, proxy mode and real visitor IPs done right.
Frequently asked questions
Why is the registrant’s name hidden?
Registrars redact personal data under GDPR and similar laws. Use the registrar’s contact form or abuse address to reach the owner.
What does clientTransferProhibited mean?
The registrar lock is on. Remove it in the registrar’s control panel before transferring the domain.
Can I look up who owns an IP address?
Yes — enter the IP to see the network name, allocated range, country and abuse contact from the regional internet registry.
Is WHOIS still used for domains?
For generic TLDs such as .com, .net and .org, RDAP replaced WHOIS as the definitive source on 28 January 2025. Some registries still answer port-43 WHOIS, and some country-code TLDs offer only WHOIS.
Why does a lookup for www.example.com fail?
Registries store registered domains only. Look up example.com instead; subdomains such as www or mail exist only in your DNS zone.
How do I find which registrar a domain is with?
Look it up and read the Registrar field. If you bought the domain through a hosting company, that company may be a reseller of the registrar shown.
What happens after a domain expires?
Depending on the registrar there is an auto-renew grace period of up to 45 days, then a 30-day redemption period in which it can be restored for a fee, then a short pending-delete stage before it becomes available to anyone.
What does DNSSEC unsigned mean in the result?
No DS record is published at the registry, so resolvers do not validate the domain. That is the default for most domains and does not stop it from working.
What is an AS number?
An autonomous system number identifies a network that announces its own IP ranges on the internet, such as a hosting provider or ISP. Looking it up shows the organisation and its abuse contact.