{"id":5797,"date":"2026-10-03T13:32:54","date_gmt":"2026-10-03T10:32:54","guid":{"rendered":"https:\/\/www.dchost.com\/blog\/?p=5797"},"modified":"2026-10-03T06:16:49","modified_gmt":"2026-10-03T03:16:49","slug":"rdap-domain-lookup-whois-replacement","status":"publish","type":"post","link":"https:\/\/www.dchost.com\/blog\/en\/rdap-domain-lookup-whois-replacement\/","title":{"rendered":"RDAP Domain Lookup: What Replaces WHOIS and Why It Matters"},"content":{"rendered":"<div class=\"dchost-blog-content-wrapper\"><div class=\"aiw-summary\">\n<p class=\"aiw-box-title\">Quick summary<\/p>\n<p>RDAP domain lookup is the standardized query method used by many registries and registrars to provide domain registration data. It presents registration and expiration dates, registrar details, status codes, and available registration data in a more consistent structure than traditional WHOIS output.<\/p>\n<ul>\n<li>The <code>events<\/code> section usually contains creation, update, transfer, and expiration dates, while <code>status<\/code> shows restrictions on domain operations.<\/li>\n<li>Privacy services and data protection rules can hide the registrant&#8217;s name, email address, or phone number.<\/li>\n<li>Appearing in a domain&#8217;s RDAP record is not, by itself, legal proof of ownership. Registrar accounts, invoices, and contracts may also matter.<\/li>\n<li>If information is missing or contradictory, verify the domain extension&#8217;s RDAP source and then check the registrar account.<\/li>\n<\/ul>\n<\/div>\n<p>When you need to check who controls a domain, when it expires, or whether it can be transferred, an old WHOIS result may not give you a clear answer. Some records hide the registrant, some show dates under unfamiliar labels, and long status codes can be difficult to interpret without context.<\/p>\n<p>RDAP addresses inconsistent output with a shared data model and machine-readable responses. You still need to understand what the protocol shows and what it cannot reveal. This guide explains how to read an RDAP domain lookup, distinguish RDAP from WHOIS, and verify uncertain results before you make an ownership, transfer, or purchase decision.<\/p>\n<div id=\"toc_container\" role=\"navigation\" aria-label=\"Table of Contents\" data-nosnippet class=\"toc_transparent no_bullets toc_numbered toc_title_center\"><p class=\"toc_title\">\u0130\u00e7indekiler<\/p><ul class=\"toc_list\"><li><a href=\"#What_is_RDAP_and_how_did_it_replace_WHOIS\"><span class=\"toc_number toc_depth_1\">1.<\/span> What is RDAP, and how did it replace WHOIS?<\/a><\/li><li><a href=\"#What_information_appears_in_an_RDAP_domain_lookup\"><span class=\"toc_number toc_depth_1\">2.<\/span> What information appears in an RDAP domain lookup?<\/a><ul><li><a href=\"#Registration_dates_and_event_data\"><span class=\"toc_number toc_depth_2\">2.1.<\/span> Registration dates and event data<\/a><\/li><li><a href=\"#Registrar_and_registry_information\"><span class=\"toc_number toc_depth_2\">2.2.<\/span> Registrar and registry information<\/a><\/li><li><a href=\"#What_do_status_codes_mean\"><span class=\"toc_number toc_depth_2\">2.3.<\/span> What do status codes mean?<\/a><\/li><\/ul><\/li><li><a href=\"#Why_is_registrant_information_hidden\"><span class=\"toc_number toc_depth_1\">3.<\/span> Why is registrant information hidden?<\/a><\/li><li><a href=\"#How_should_you_verify_an_RDAP_result\"><span class=\"toc_number toc_depth_1\">4.<\/span> How should you verify an RDAP result?<\/a><ul><li><a href=\"#When_checking_that_you_control_a_domain\"><span class=\"toc_number toc_depth_2\">4.1.<\/span> When checking that you control a domain<\/a><\/li><li><a href=\"#Before_buying_or_accepting_a_domain\"><span class=\"toc_number toc_depth_2\">4.2.<\/span> Before buying or accepting a domain<\/a><\/li><\/ul><\/li><li><a href=\"#How_is_RDAP_different_from_WHOIS\"><span class=\"toc_number toc_depth_1\">5.<\/span> How is RDAP different from WHOIS?<\/a><\/li><li><a href=\"#Which_decisions_can_RDAP_data_support\"><span class=\"toc_number toc_depth_1\">6.<\/span> Which decisions can RDAP data support?<\/a><\/li><li><a href=\"#Frequently_Asked_Questions\"><span class=\"toc_number toc_depth_1\">7.<\/span> Frequently Asked Questions<\/a><ul><li><a href=\"#Is_an_RDAP_lookup_free\"><span class=\"toc_number toc_depth_2\">7.1.<\/span> Is an RDAP lookup free?<\/a><\/li><li><a href=\"#Does_RDAP_show_the_real_domain_owner\"><span class=\"toc_number toc_depth_2\">7.2.<\/span> Does RDAP show the real domain owner?<\/a><\/li><li><a href=\"#Does_a_domain_become_available_immediately_on_its_expiration_date\"><span class=\"toc_number toc_depth_2\">7.3.<\/span> Does a domain become available immediately on its expiration date?<\/a><\/li><li><a href=\"#Can_RDAP_identify_the_hosting_company\"><span class=\"toc_number toc_depth_2\">7.4.<\/span> Can RDAP identify the hosting company?<\/a><\/li><\/ul><\/li><li><a href=\"#Action_checklist\"><span class=\"toc_number toc_depth_1\">8.<\/span> Action checklist<\/a><\/li><\/ul><\/div>\n<h2><span id=\"What_is_RDAP_and_how_did_it_replace_WHOIS\">What is RDAP, and how did it replace WHOIS?<\/span><\/h2>\n<p>RDAP stands for Registration Data Access Protocol. It is an Internet protocol designed to provide access to domain and IP registration data through structured responses.<\/p>\n<p>For many years, WHOIS presented domain registration information mainly as plain text. Each registry or registrar could use different field names, date formats, and response layouts, which made automated processing difficult. RDAP returns data in JSON, a structured format that applications can read more consistently. Monitoring tools and domain portfolio software can therefore process similar types of information through a more predictable model.<\/p>\n<p>RDAP has become the required registration-data access method for many generic top-level domains, but availability and implementation still depend on the domain extension and its registry or registrar. It is not a universal service that reveals every domain owner.<\/p>\n<p>Privacy rules, registrar policies, and registry practices can limit the personal data that is published. The main change is the standardization of the access method and data structure, not the removal of privacy restrictions. If a domain extension does not provide the result you expect, confirm its designated RDAP service rather than assuming that every extension uses the same endpoint.<\/p>\n<div class=\"aiw-note aiw-note-example\">\n<p class=\"aiw-box-title\">Example scenario<\/p>\n<p>Assume that you check a domain&#8217;s creation date and current registrar before buying it. If the RDAP response shows a privacy service provider instead of an individual&#8217;s name, that does not mean the lookup failed. It means that publishable personal information may be restricted. In this scenario, you should also review the contract, transfer process, and registrar verification.<\/p>\n<\/div>\n<h2><span id=\"What_information_appears_in_an_RDAP_domain_lookup\">What information appears in an RDAP domain lookup?<\/span><\/h2>\n<p>When reading an RDAP record, first confirm the domain itself, then review the registration object and event dates. The extension determines which registry infrastructure handles the query. A mistyped extension or incomplete domain name can produce an empty or misleading result instead of the record you need.<\/p>\n<h3><span id=\"Registration_dates_and_event_data\">Registration dates and event data<\/span><\/h3>\n<p>RDAP responses commonly place dates in an <code>events<\/code> section. A single domain can have several event types. The most common include:<\/p>\n<ul>\n<li><strong>registration:<\/strong> The date when the domain was initially registered.<\/li>\n<li><strong>expiration:<\/strong> The planned end date of the current registration period.<\/li>\n<li><strong>last changed:<\/strong> The time when the registration record or object was last modified.<\/li>\n<li><strong>transfer:<\/strong> A time associated with a registrar transfer, when that event is available.<\/li>\n<\/ul>\n<p>An expiration date does not mean that the domain will definitely be deleted on that day. The registrar may apply renewal, auto-renewal, late-renewal, recovery, or pre-deletion policies. If you manage the domain, compare the date with the registrar account&#8217;s renewal and payment information instead of waiting for the final day.<\/p>\n<p>The domain&#8217;s registration date is not the same as the date when its website went online. An older domain may be reused for a new site, and a newly launched website may use a domain that was registered by someone else in the past. Do not judge brand trust or SEO performance from domain age alone.<\/p>\n<h3><span id=\"Registrar_and_registry_information\">Registrar and registry information<\/span><\/h3>\n<p>A registrar registers and manages the domain on your behalf and usually provides the management panel. A registry operates the registration database for a particular top-level domain. An RDAP response can represent these as different entities.<\/p>\n<p>Checking the registrar is useful when you need to:<\/p>\n<ul>\n<li>Find where to request an authorization or transfer code.<\/li>\n<li>Understand why a domain has been suspended.<\/li>\n<li>Identify which account controls a domain managed by a former agency or employee.<\/li>\n<li>Confirm which panel can update renewal and contact details.<\/li>\n<\/ul>\n<p>The registrar name in RDAP does not reveal your panel username or necessarily identify the account holder. A domain managed through an agency account can show the same registrar as a domain managed directly by its business owner. Separate the registration provider from the management account when evaluating ownership. For related risks, compare the RDAP record with your invoice and review guidance on <a href=\"https:\/\/www.dchost.com\/blog\/en\/domain-and-hosting-ownership-avoid-whois-vs-invoice-name-problems\/\">domain and hosting ownership<\/a>.<\/p>\n<h3><span id=\"What_do_status_codes_mean\">What do status codes mean?<\/span><\/h3>\n<p>The <code>status<\/code> field describes which domain operations are open or restricted. A status code is not automatically an error. For example, a transfer restriction may be enabled as a security measure.<\/p>\n<ul>\n<li><code>clientTransferProhibited<\/code>: The registrar has applied a rule that blocks transfer.<\/li>\n<li><code>serverTransferProhibited<\/code>: A transfer restriction exists at the registry level.<\/li>\n<li><code>clientUpdateProhibited<\/code>: Updates through the registrar are restricted.<\/li>\n<li><code>clientDeleteProhibited<\/code>: The registrar prevents the domain from being deleted.<\/li>\n<li><code>clientHold<\/code>: The registrar has placed the domain on hold; this can affect DNS resolution or use of the domain.<\/li>\n<li><code>serverHold<\/code>: The registry has applied a hold, which can affect the domain&#8217;s operation.<\/li>\n<li><code>redemptionPeriod<\/code>: After expiration, the domain may have entered a recovery period before deletion.<\/li>\n<li><code>pendingDelete<\/code>: The domain may be in the final stage before deletion.<\/li>\n<li><code>pendingTransfer<\/code>: A registrar transfer process may be underway.<\/li>\n<\/ul>\n<p>The exact effect of a status code depends on the extension, registrar, and relevant registry policy. If you see a hold, do not assume that ownership changed or that the website is definitely offline. Check DNS responses, the registrar panel, and any support explanation together. You can also compare the result with the reference on <a href=\"https:\/\/www.dchost.com\/blog\/en\/domain-status-codes-clienthold-serverhold-pendingtransfer-redemptionperiod\/\">domain status codes<\/a> to distinguish a transfer lock from a hold that affects DNS resolution.<\/p>\n<h2><span id=\"Why_is_registrant_information_hidden\">Why is registrant information hidden?<\/span><\/h2>\n<p>It is normal for an RDAP domain lookup to hide a name, organization, email address, or phone number. The cause may be a privacy service offered by the registrar, personal data protection obligations, or the registry&#8217;s publication policy.<\/p>\n<p>Hidden fields usually do not mean that ownership disappeared. The registrar may retain the actual contact details in its own system while publishing a proxy address or redacted value. Some responses show a phrase such as &#8220;REDACTED FOR PRIVACY,&#8221; an anonymous email address, or only organization information instead of personal data.<\/p>\n<p>Use these signs to distinguish privacy restrictions from an incorrect record:<\/p>\n<ul>\n<li>If the registrar, creation date, and expiration date are visible, the lookup may be working correctly and only personal fields may be hidden.<\/li>\n<li>If the registrar differs from the organization on your invoice, investigate whether the domain is held in another account or through a reseller.<\/li>\n<li>If a forwarding address appears instead of a direct contact address, do not assume that it is the registrant&#8217;s personal email.<\/li>\n<li>If no record is returned, verify the extension and spelling first, then contact the relevant registrar or registry support channel.<\/li>\n<\/ul>\n<p>If you must verify ownership for a legal or commercial transaction, do not use the RDAP output as your only document. A registrar account, registration agreement, invoice, corporate email correspondence, and any required official process may provide stronger evidence. A separate explanation of <a href=\"https:\/\/www.dchost.com\/blog\/en\/domain-whois-privacy-and-gdpr-what-it-really-protects-and-when-to-use-it\/\">WHOIS privacy and GDPR<\/a> can help clarify why personal fields are not necessarily public.<\/p>\n<div class=\"aiw-note aiw-note-warning\">\n<p class=\"aiw-box-title\">Caution<\/p>\n<p>An organization name shown in RDAP is not always the ultimate owner of the brand or website. It may belong to an intermediary, agency, holding company, or privacy service. Compare registration and management documents before making an ownership decision.<\/p>\n<\/div>\n<h2><span id=\"How_should_you_verify_an_RDAP_result\">How should you verify an RDAP result?<\/span><\/h2>\n<p>If a result differs from what you expected, use a narrow diagnostic process instead of changing random fields. First check the spelling and extension of the domain. <code>example.com<\/code> and <code>www.example.com<\/code> are not the same registration object; an RDAP domain lookup normally uses the root domain.<\/p>\n<p>Then locate these four sections in the response:<\/p>\n<ol>\n<li><strong>Domain identity:<\/strong> The queried domain and, where available, a unique registration identifier.<\/li>\n<li><strong>Registrar:<\/strong> The organization responsible for registration and management.<\/li>\n<li><strong>Events:<\/strong> Registration, update, transfer, and expiration dates.<\/li>\n<li><strong>Status:<\/strong> Restrictions related to transfer, updates, deletion, or DNS use.<\/li>\n<\/ol>\n<p>If these sections are present but personal details are absent, the cause is usually a privacy policy rather than a failed query. If the domain cannot be found, the registrar is missing, or dates are empty, confirm that you are being directed to the correct RDAP service for that extension. Not every extension uses the same registration infrastructure, so a method that works for one extension may not produce the same result for another.<\/p>\n<p>For an automated integration, parse the JSON object and handle missing fields rather than assuming that every response contains the same entities or event types. Verify the integration with a domain whose registrar and dates you can independently confirm. Do not treat a successful HTTP response as proof that the domain exists; inspect the returned domain object and status as well.<\/p>\n<h3><span id=\"When_checking_that_you_control_a_domain\">When checking that you control a domain<\/span><\/h3>\n<p>For your own domain, the goal is not only to read publicly visible data but also to verify your management authority. Being able to sign in to the registrar panel, start a renewal, and manage the transfer lock within your permissions is a more useful practical check.<\/p>\n<p>If the registrar in RDAP differs from what you expected, identify which account or agency manages the domain. The registrar may have changed, or the domain may have been purchased through a reseller account. Before changing anything, document the current contact details, renewal date, and transfer conditions. Export or save the current registration information if your registrar provides that option so you have a reference for rollback or support discussions.<\/p>\n<h3><span id=\"Before_buying_or_accepting_a_domain\">Before buying or accepting a domain<\/span><\/h3>\n<p>For a purchase or transfer decision, the creation date, expiration date, and status codes are initial checkpoints. If you see <code>redemptionPeriod<\/code>, <code>pendingDelete<\/code>, or a transfer restriction, confirm the current stage with the seller and registrar before sending payment or starting a transfer.<\/p>\n<p>A domain&#8217;s previous use does not automatically transfer earlier content or trademark rights to you. Trademark disputes, obligations of the previous registrant, and search engine history are outside RDAP&#8217;s scope. Do not base a commercial decision on technical registration data alone.<\/p>\n<div class=\"aiw-note aiw-note-tip\">\n<p class=\"aiw-box-title\">Tip<\/p>\n<p>If you manage several domains, review their registration and expiration dates at regular intervals. Make sure your monitoring tool does not treat privacy-hidden personal fields as errors, and alert on changes to registrar, expiration, or status data instead.<\/p>\n<\/div>\n<h2><span id=\"How_is_RDAP_different_from_WHOIS\">How is RDAP different from WHOIS?<\/span><\/h2>\n<p>WHOIS and RDAP serve the same broad purpose: providing access to domain registration data. The difference is how the data is delivered and how well it supports modern access and automation needs.<\/p>\n<table>\n<thead>\n<tr>\n<th>Topic<\/th>\n<th>WHOIS<\/th>\n<th>RDAP<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Response format<\/td>\n<td>Usually plain text with variable field names<\/td>\n<td>Structured JSON objects<\/td>\n<\/tr>\n<tr>\n<td>Automated processing<\/td>\n<td>Can require more work because output formats vary<\/td>\n<td>More suitable because fields and object relationships are standardized<\/td>\n<\/tr>\n<tr>\n<td>Date information<\/td>\n<td>May appear in different formats within text<\/td>\n<td>Can be grouped by event type and timestamp<\/td>\n<\/tr>\n<tr>\n<td>Privacy<\/td>\n<td>May be hidden, redacted, or controlled by registrar policy<\/td>\n<td>May be hidden, redacted, or controlled by registrar policy<\/td>\n<\/tr>\n<tr>\n<td>Reference to authoritative parties<\/td>\n<td>May not be equally clear in every service<\/td>\n<td>Can associate registration objects and related organizations more consistently<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>This does not mean that RDAP always exposes more personal data. Its main advantage is presenting available data in a more predictable structure. Privacy and data-sharing limits continue regardless of the protocol.<\/p>\n<p>WHOIS output can still appear in older tools or registrar interfaces, but its format is less suitable for software that needs consistent field names. When moving to RDAP, you are reading the same broad registration concepts through structured objects and event labels.<\/p>\n<h2><span id=\"Which_decisions_can_RDAP_data_support\">Which decisions can RDAP data support?<\/span><\/h2>\n<p>RDAP is a useful source for technical due diligence. It can help you determine whether a domain is registered, which registrar manages it, which stage of its lifecycle it may be in, and whether transfer restrictions are visible.<\/p>\n<p>It is not enough by itself to:<\/p>\n<ul>\n<li>Prove the legal owner of a domain.<\/li>\n<li>Determine whether a trademark right is valid.<\/li>\n<li>Decide whether a domain was previously used for malicious activity.<\/li>\n<li>Identify the hosting provider or physical owner of the website&#8217;s server.<\/li>\n<li>Measure SEO value from registration age alone.<\/li>\n<\/ul>\n<p>Domain security also requires separate checks such as a registrar lock, DNSSEC, and two-factor authentication on the registrar account. A transfer lock in RDAP is useful evidence, but it does not verify the security of the entire account. Review <a href=\"https:\/\/www.dchost.com\/blog\/en\/domain-security-best-practices-registrar-lock-dnssec-whois-privacy-and-2fa\/\">domain security best practices<\/a> as a separate step when protecting domains that support business websites or email.<\/p>\n<h2><span id=\"Frequently_Asked_Questions\">Frequently Asked Questions<\/span><\/h2>\n<h3><span id=\"Is_an_RDAP_lookup_free\">Is an RDAP lookup free?<\/span><\/h3>\n<p>The cost of an end-user RDAP interface depends on the service you use. The protocol is an access method; the registrar or registry determines any applicable service or access fees. Check the terms of the specific lookup service before automating repeated queries.<\/p>\n<h3><span id=\"Does_RDAP_show_the_real_domain_owner\">Does RDAP show the real domain owner?<\/span><\/h3>\n<p>Not always. Privacy services and data protection rules can redact personal fields, and a visible registrant is not by itself proof of legal ownership. Use the registrar account and contractual records when verification is required.<\/p>\n<h3><span id=\"Does_a_domain_become_available_immediately_on_its_expiration_date\">Does a domain become available immediately on its expiration date?<\/span><\/h3>\n<p>Usually not. Renewal, late renewal, recovery, and deletion stages depend on the registrar and extension policy. Check the registrar account and the relevant registry policy for the actual timeline.<\/p>\n<h3><span id=\"Can_RDAP_identify_the_hosting_company\">Can RDAP identify the hosting company?<\/span><\/h3>\n<p>RDAP shows domain registration data, not the server hosting the website. Hosting research requires separate sources such as DNS records, IP information, and hosting account records. A domain&#8217;s registrar and hosting provider may be different companies.<\/p>\n<h2><span id=\"Action_checklist\">Action checklist<\/span><\/h2>\n<ul>\n<li>Check that you entered the domain correctly, including its extension.<\/li>\n<li>Confirm that the extension&#8217;s registry or registrar provides the RDAP service you are querying.<\/li>\n<li>Find the domain identity, registrar, event dates, and status codes in the RDAP response.<\/li>\n<li>Do not confuse the <code>registration<\/code> date with the <code>expiration<\/code> date.<\/li>\n<li>Recognize that <code>clientTransferProhibited<\/code> is a transfer lock, while <code>clientHold<\/code> and <code>serverHold<\/code> can have different effects.<\/li>\n<li>Do not treat hidden personal fields as proof that the lookup failed.<\/li>\n<li>Compare RDAP with invoices, contracts, and the registrar account for ownership or purchase decisions.<\/li>\n<li>Track expiration dates and registrar access separately for domains you manage.<\/li>\n<\/ul>\n<p>Your next step is to check one domain you manage through RDAP and record four items: registrar, registration date, expiration date, and status codes. If something looks unexpected, verify only that field in the registrar panel or support record. The move from WHOIS to RDAP is easier when you focus on reading the right data in context rather than simply searching for more data.<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>RDAP replaces WHOIS with structured domain registration data. Learn how to read dates, registrar details, status codes, and privacy limits.<\/p>\n","protected":false},"author":4,"featured_media":5794,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[175],"tags":[633,634,396,629,632,97],"class_list":["post-5797","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-domain","tag-domain-lookup","tag-domain-privacy","tag-domain-security","tag-rdap","tag-registrar","tag-whois"],"_links":{"self":[{"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/posts\/5797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/comments?post=5797"}],"version-history":[{"count":1,"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/posts\/5797\/revisions"}],"predecessor-version":[{"id":5799,"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/posts\/5797\/revisions\/5799"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/media\/5794"}],"wp:attachment":[{"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/media?parent=5797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/categories?post=5797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dchost.com\/blog\/en\/wp-json\/wp\/v2\/tags?post=5797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}