Free WHOIS Domain Lookup
Enter a domain to see its registrar, registration and expiry dates, nameservers, and DNSSEC status (via RDAP, the modern structured successor to legacy WHOIS).
Need to track registration and expiry across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the WHOIS Lookup
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Look up
ActiScan queries RDAP, the modern registry lookup protocol, live.
Read the record
Registrar, key dates, nameservers, DNSSEC status, and domain status codes.
What Is WHOIS/RDAP?
WHOIS is the original protocol for looking up who registered a domain – decades old, plain text, with a slightly different response format for every registry. RDAP (Registration Data Access Protocol, defined in RFC 9083) is its modern replacement: structured JSON, served over HTTPS, standardized across registries. This tool uses RDAP, not legacy port-43 WHOIS.
Lookups are routed through rdap.org, a community-run bootstrap redirector that forwards each request to whichever registry's own RDAP server is authoritative for that domain's TLD – so the data you see comes straight from the registry, not a cached third-party copy.
What Each Field Means
| Field | What it shows |
|---|---|
| Registrar | The company the domain is registered through (e.g. GoDaddy, Namecheap). |
| Registered | The date the domain was first registered. |
| Expires | The date the current registration period ends. Renew before this date or the domain can lapse. |
| Last updated | The last time the registration record itself changed – not necessarily a DNS or website change. |
| DNSSEC | Whether the registry has a signed delegation on file for this domain (a DS record). Pair with the DNSSEC checker to confirm the chain actually validates. |
| Nameservers | The authoritative nameservers the registry has on file for this domain. |
| Status | One or more domain status codes describing the domain's current state – see the table below. |
Common Domain Status Codes
A domain can carry more than one status code at a time. These are the ones you'll run into most often:
| Code | What it means |
|---|---|
| ok / active | Normal state – no restrictions in effect. |
| clientTransferProhibited | The registrar has locked the domain against transfer to another registrar – usually the default anti-hijacking setting, not a problem. |
| clientDeleteProhibited | The registrar has locked the domain against deletion. |
| clientUpdateProhibited | The registrar has locked the domain against contact or nameserver changes. |
| clientHold | The registrar has told the registry not to resolve the domain in DNS – typically for non-payment or an abuse/legal issue. The domain will not work while this is set. |
| pendingDelete | The domain is in the final stage of expiring and will be released for public registration soon. |
Next Steps After Your Lookup
DNSSEC shows signed?
RDAP only confirms the registry delegation is signed – confirm the signature chain actually validates.
DNSSEC Checker →Want alerts before a domain expires?
ActiScan tracks registration and expiry dates across every domain you manage, and alerts you before renewal deadlines.
Start free →Frequently Asked Questions
Is this WHOIS lookup free?
Yes – look up any registered domain for free, no signup required.
What's the difference between WHOIS and RDAP?
WHOIS is the original, decades-old lookup protocol – free-form text, with a different format for every registry. RDAP (RFC 9083) is its modern replacement: structured JSON over HTTPS, standardized across registries. This tool uses RDAP.
Why don't I see the registrant's name or email?
Most registries and registrars redact personal registrant contact data by default for privacy. The registrar organization itself is still shown.
Why does a domain show no data at all?
Either the domain isn't registered, or its registry doesn't yet support RDAP. Both are legitimate outcomes, not errors.
What does "DNSSEC: Not signed" mean here?
The registry has no signed delegation (DS record) on file for this domain, so it isn't using DNSSEC – distinct from the separate DNSSEC checker, which confirms whether an existing signature chain actually validates.