Domain intelligence

The Ultimate WHOIS and Domain Intelligence Guide

WHOIS, RDAP, ownership history, registrar metadata, expiration monitoring, and how investigators use domain intelligence to surface fraud, brand abuse, and infrastructure relationships — explained for practitioners and curious owners alike.

Quick summary

  • WHOIS/RDAP is the canonical ownership and registration record for every domain.
  • GDPR redaction is normal — absence of registrant data is not by itself suspicious.
  • Domain age, nameserver patterns, and TLS fingerprints link related infrastructure.
  • Monitor expiry on critical domains 90/30/7 days out.

What WHOIS records actually contain

  • Registrar of record and IANA ID.
  • Creation, updated, and expiration dates.
  • Registrant, admin, and tech contacts (often redacted).
  • Authoritative nameservers.
  • Domain status codes (clientTransferProhibited, etc.).
  • DNSSEC enrollment status.

Investigation patterns operators use

When a suspicious domain shows up, pivot: pull WHOIS, then nameservers, then resolve the hostname and check the IP's other PTR records and TLS SANs. A single fraudulent domain usually reveals a cluster of sibling infrastructure built from the same template.

Defensive use: protecting your own portfolio

Lock domains with registrar-level transfer protection, enable DNSSEC, set MFA on the registrar account, and monitor expiry plus WHOIS changes. The most common preventable brand outage is silent contact-record drift after team turnover.

Troubleshooting workflow

Run through these steps in order. Each step links to the right diagnostic tool.

  1. 1

    Pull WHOIS

    Registrar, age, expiry, status codes.

    Open WHOIS
  2. 2

    Check domain age

    Age is one of the strongest abuse signals.

    Open Domain Age
  3. 3

    Inspect DNS

    Nameservers reveal hosting and operator footprint.

    Open DNS
  4. 4

    Check reputation

    Combine WHOIS findings with reputation feeds.

    Open Domain Reputation
  5. 5

    Cross-check blacklists

    Final pass for known abuse footprints.

    Open Blacklist

Frequently asked questions

What is WHOIS?

WHOIS is the public record describing a domain's registrant, registrar, registration date, expiry, and nameservers. Modern data is increasingly served via RDAP, a structured JSON successor protocol.

Why is the registrant often redacted?

GDPR and ICANN policy let registrants hide personal contact data behind privacy services. Legitimate investigations request unredacted records via the registrar's abuse channel or law-enforcement process.

What does domain age tell me?

Old domains carry weight in reputation systems. Brand-new registrations are statistically more likely to host phishing, scams, or short-lived abuse infrastructure.

How do investigators link related domains?

Shared nameservers, identical TLS certificates, repeating WHOIS fingerprints, hosting on the same /24, and matching DNS records all suggest common operators.

How do I monitor expiry?

Set up automated alerts on critical domains 90, 30, and 7 days before expiration. Losing a domain to drop-catchers is one of the most painful preventable outages.

Monitor it continuously

Save this check, get alerts on changes, and track multiple domains in one dashboard.

Learn about monitoring