WHOIS and RDAP lookup

Look up who holds a domain name, IP address block or AS number using RDAP, the structured successor to WHOIS. The query runs from iseeu.cc's server, so the registry sees a Cloudflare address instead of yours.

iseeu.cc's server asks the registry IANA lists for this query. Up to 10 lookups a minute; nothing is stored.

What it does

This tool asks the authoritative registration database who holds a domain name, IP address block or autonomous system number, and summarises the answer. It speaks RDAP, the Registration Data Access Protocol (RFC 9082 and RFC 9083), which returns structured JSON over HTTPS instead of the free-form text a port-43 WHOIS server sends. Port-43 WHOIS is not used.

There is no single RDAP server for the internet. Each top-level domain registry and each regional internet registry (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC) runs its own. To pick the right one, the tool consults IANA's RDAP bootstrap registry (RFC 9224), which maps TLDs, IP ranges and AS number ranges to servers. iseeu.cc bundles a copy and refreshes it whenever the site is rebuilt.

The request is made by iseeu.cc's server, a Cloudflare Worker, not by your browser, so the registry sees a Cloudflare network address rather than yours. The Worker only contacts RDAP servers listed in IANA's bootstrap data, allows 10 lookups a minute per IP, times out after a few seconds, and keeps no record of what was looked up.

How to use it

  1. Type a domain name, an IPv4 or IPv6 address, a CIDR block, or an AS number with or without the AS prefix.
  2. Submit the query. Internationalized domain names are converted to their xn-- form first.
  3. Read the summary. A domain shows the registrar and its IANA ID if published, status codes, created, updated and expiry dates, name servers, whether the delegation is DNSSEC-signed, and the registrar abuse contact if published. An IP address shows the range and CIDR, network name, allocation type, country, organisation if public, and abuse contact. An AS number shows its name, number range, country and organisation.
  4. Expand the raw RDAP JSON below the summary for fields the summary leaves out, such as remarks.
example.com
bücher.com            sent as xn--bcher-kva.com
8.8.8.8
2001:4860:4860::8888
8.8.8.0/24
AS15169               15169 works too

A domain has two record keepers: the registry, which runs the TLD, and the registrar, the company the name was bought through. Thin registries such as .com and .net publish only registrar-level data. Their response usually links to the registrar's own RDAP record; the tool prints that address as text so you can query it yourself, but does not follow it. Some country-code registries do not run RDAP; the tool then says so and suggests the registry's own lookup service.

For IP results, ALLOCATED PA (RIPE NCC) or DIRECT ALLOCATION (ARIN) usually marks an ISP or host that sub-assigns space; ASSIGNED PA or REASSIGNED marks one customer's block.

Use cases

  • Checking a renewal date. A few weeks before a domain lapses, compare the registry's expiry date with your registrar's control panel. A mismatch is cheaper to fix before an outage.
  • Finding where to report abuse. Paste the source IP from a log line to get the abuse mailbox of the network that holds it, usually a hosting company or ISP.
  • Diagnosing a domain that stopped resolving. A clientHold or serverHold status means the name is withheld from the TLD zone; no change to your own DNS records will fix that.
  • Vetting an unfamiliar sender. A supposedly long-established supplier whose domain was registered last week deserves a second look before anyone pays its invoice.
  • Labelling an ASN. Enter a number from a traceroute or BGP path to see the organisation and country it is registered to.

Reading domain status codes

Status values come from EPP, the protocol registrars use to talk to registries (RFC 5731, plus RFC 3915 for grace periods). RDAP spells them as lowercase phrases, so clientTransferProhibited arrives as client transfer prohibited, and EPP's ok arrives as active (RFC 8056 defines the mapping). Client codes are set by the registrar, server codes by the registry.

"status": ["client delete prohibited", "client transfer prohibited",
           "client update prohibited"],
"events": [
  {"eventAction": "registration", "eventDate": "2019-03-04T17:22:05Z"},
  {"eventAction": "expiration",   "eventDate": "2027-03-04T17:22:05Z"}
],
"secureDNS": {"delegationSigned": false}
  • clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited: routine registrar locks against hijacking, often on by default.
  • serverTransferProhibited and other server locks: set by the registry, for example for a registry lock service or during a dispute.
  • clientHold or serverHold: the name is not published in DNS and does not resolve. Causes include an unverified registrant email, non-payment, abuse or a court order.
  • redemptionPeriod: the registration was deleted but can still be restored through the registrar, usually for a fee and typically within 30 days.
  • pendingDelete: the name will be purged, typically within five days, and then becomes available to anyone. It can no longer be restored.

Expiry dates need care too: many gTLD registries renew a name automatically at expiry, so a date that just jumped forward a year does not prove the owner paid. The registrar can still delete the name during the auto-renew grace period of up to 45 days, shown as autoRenewPeriod.

From WHOIS to RDAP, and what redaction means

Port-43 WHOIS dates from the early 1980s (today it is described in RFC 3912). It has no standard output format, no reliable character encoding and no way to mark withheld fields. RDAP closes those gaps with defined JSON members, UTF-8, HTTPS and the bootstrap registry. ICANN has required gTLD registries and registrars to offer RDAP since 2019, and in January 2025 it ended their obligation to run port-43 WHOIS.

Since GDPR took effect in May 2018, most registries and registrars withhold personal data about registrants. A typical response omits the registrant's name, street address, phone and email, often leaving a state or province, a country, and a web form or forwarding address for reaching the owner. RFC 9537 adds a redacted member so clients can tell which fields were removed. Privacy and proxy services differ: the record is complete but names the service, not the customer.

Frequently asked questions

Is RDAP just a new name for WHOIS?

No. Both answer the same question, who holds a name or address block, but RDAP returns structured JSON over HTTPS, handles non-Latin text and marks which fields were withheld. Port-43 WHOIS sends unformatted text that differs from server to server. For generic TLDs, ICANN ended the requirement to run port-43 WHOIS in January 2025, so RDAP is now the dependable source for those domains.

Why are the registrant's name and email hidden?

Most registries and registrars redact personal data about registrants, a practice that became standard after GDPR took effect in 2018. The tool shows exactly what the registry publishes and cannot uncover anything that has been withheld. To reach a domain owner, look for a contact form or forwarding address in the registrar's record, or ask the registrar directly if you have a legitimate legal need for the data.

Why does a .com or .net lookup show so little?

The .com and .net registries are thin: they hold the registrar, dates, status codes, name servers and DNSSEC flag, while contact data stays with the registrar. The tool shows the registry's answer and prints the registrar's RDAP address as plain text, but it does not query that address. You can open it yourself, although the contact fields there are usually redacted as well.

Does the registry learn my IP address or what I searched for?

The registry sees the name or address that was looked up, because that is the query itself. It does not see your IP address: the request comes from iseeu.cc's Cloudflare Worker, so the registry sees a Cloudflare network address. The Worker keeps no record of lookups, and iseeu.cc keeps no request logs, sets no cookies and shows no ads.

My domain shows clientTransferProhibited. Is something wrong?

Usually not. It is a lock your registrar sets so the name cannot be moved to another registrar without your approval, and many registrars apply it by default. To transfer the domain, remove the lock in the registrar's control panel and request the authorization code. If the status is serverTransferProhibited instead, the registry set it, and you will need to ask your registrar how it can be lifted.

Why do some country-code domains return no RDAP data?

Country-code registries set their own rules and are not bound by ICANN's gTLD contracts, so some have not deployed RDAP. When that is the case, the tool tells you and suggests the registry's own lookup service instead. It does not fall back to port-43 WHOIS, so you will not get a partial or differently formatted answer from an older server.

How do I find where to report abuse coming from an IP address?

Look up the address and use the abuse contact in the result. The regional internet registry returns the most specific network registered for that address, which is often the hosting provider or ISP rather than its end customer. Include the source IP, timestamps with a time zone and the relevant log lines. For a phishing site, the registrar abuse contact from a domain lookup is a second place to report.

Registration records are maintained by registries and registrars and may be incomplete, redacted or out of date. Verify anything important with the registrar of record.