Skip to content
OneKitly

WHOIS Domain Lookup: Expiry Date, Registrar and Status

Check a domain's registration and expiry dates, registrar, abuse contact, name servers and DNSSEC over RDAP, for .com, .net, .org, .fr and 500+ extensions.

A suspicious site in an email, a name you'd like to buy, your own domain whose renewal date has slipped your mind: you want to know who owns it and until when. The first question rarely has a public answer: since the GDPR, registries almost always mask the holder's contact details. For the second, the tool asks the extension's registry directly and shows what it publishes: the number of days until expiry, the registrar to contact about abuse, and every EPP status turned into a plain sentence. More than 500 extensions are covered, including .net, .io and .app, but not .uk, .de or .eu: their registries do not allow their data to be reused on a third-party site, and the tool then tells you where to look them up.

How to use it

  1. In the “Domain” field, type a name such as wikipedia.org or paste a whole address, link or email: the tool keeps the name, drops the path, the port and any trailing dot, and converts an accented name to punycode.
  2. Click “Look up” or press Enter. To see a full record straight away, click one of the two examples offered, wikipedia.org or example.com.
  3. Read the badge on the “Result” card: “Registered”, “Not found”, “Not covered” or “Error”. The message below explains the answer, and the “Name” and “ASCII form” rows show the name the tool worked with.
  4. Under “Dates”, check “Expires” and “Time left”, which counts the days remaining; under “Registrar”, note the name, the “IANA ID” and the “Abuse email”, which you can click to write a message.
  5. Scroll to “Name servers”, DNSSEC and “EPP statuses”: each code, such as clientTransferProhibited, comes with a sentence explaining it.
  6. If the badge says “Not covered”, follow the link under the message, “Registry's official service”, “IANA record for the extension” or “ICANN Lookup search”: it opens in a new tab.

Where the data comes from, and what the tool does with it

The tool does not use old port-43 WHOIS: it speaks RDAP, the standardised successor (RFCs 9082 and 9083), which returns a domain's record as JSON over HTTPS. To find the right server, the site reads the RDAP directory published by IANA and the list of existing extensions, both cached for a day. It then queries only registries whose terms of use have been read and allow individual lookups relayed through a third-party site: Verisign for .com and .net, Public Interest Registry for .org, Identity Digital for .info, .io, .ai and several hundred more, Afnic for .fr, Google Registry for .app and .dev, Tucows Registry for .online, .store and .cloud, and ZDNS for .top.

The site's server sends the request and checks the answer before showing it to you. The answer must carry the name that was asked for, and the terms it cites must still be the ones that were read; if an unknown terms link shows up, nothing is displayed and the badge switches to “Not covered”. Only what the screen presents is kept: statuses, creation, last-change and expiry dates, the registrar and its abuse contact, name servers and DNSSEC. Nothing about the holder is carried over, and the link to the registrar's own server is not followed: for the record itself, only the registry is contacted, with a 5-second timeout and no redirects followed.

Before any of that, your input is cleaned up: capitals, path, port, login details and a trailing dot go, an IP address or a name without an extension is turned away with a message, and an accented name is converted to punycode, shown on the “ASCII form” row. For a covered extension, a subdomain is cut back to the name the registry knows: fr.wikipedia.org becomes wikipedia.org, and the tool says so. For .fr, Afnic's zones gouv.fr, asso.fr, com.fr, tm.fr and nom.fr are kept, so service-public.gouv.fr stays whole.

When a WHOIS lookup really helps

  • Checking when your own domain expires before it slips away: “Time left” gives the number of days, and a clientTransferProhibited status reminds you that the lock has to be lifted at your registrar before a transfer.
  • Scouting a name to buy: “Not found” means the registry doesn't know it, so it is probably free, to be confirmed with a registrar; “Registered” shows how long it has been taken and the date it is registered until.
  • Reporting a phishing site or a spam run: since the holder isn't published, the “Abuse email” and “Abuse phone” rows give the contact the registrar provides for this, and the address opens in your mail app with one click.
  • Working out why a site has gone dark: clientHold or serverHold mark a domain suspended by the registrar or by the registry, and inactive a domain with no name servers; to see the DNS records themselves, carry on with the DNS lookup tool.
  • Checking a technical change: after switching name servers or turning on DNSSEC at your registrar, make sure the registry record lists the new servers and shows “Signed (DS at the registry)”, allowing for the one-minute cache.
  • Checking a dubious link from an email or text message: paste it as it is, the tool pulls out the domain and shows its creation date; a name registered last week that imitates a bank or a parcel carrier deserves all your suspicion.

Real records, as the tool displays them

The records below are real registry answers, saved on 14 September 2026 between 22:14 and 22:21 UTC and read back with the tool's own code. Dates are written as the screen shows them, and the time left is as of that moment.

  • google.com, at Verisign: Created Sep 15, 1997, Expires Sep 14, 2028, which reads “in 730 days”; registrar MarkMonitor Inc., IANA ID 292, with an abuse email and phone number. Six EPP statuses: clientDeleteProhibited, clientTransferProhibited and clientUpdateProhibited, set by the registrar, and their three server counterparts, set by the registry. DNSSEC: “Unsigned”.
  • fr.wikipedia.org typed into the field: the message starts with “fr.wikipedia.org is a subdomain: this is the record for wikipedia.org.”, published by Public Interest Registry. Created Jan 13, 2001, Expires Jan 13, 2027, “in 120 days”, the same registrar as google.com, and only the registrar's three locks, with no registry lock.
  • académie-française.fr: the “ASCII form” row shows xn--acadmie-franaise-npb1a.fr, the name actually sent to Afnic. The record gives the ok status, a registrar, AURIC, with no IANA ID published (the row shows —) and DNSSEC “Not published”, whereas afnic.fr shows “Signed (DS at the registry)” and an expiry on Jul 18, 2029.
  • onekitly-rdap-probe-7f3k2q9x.org, a made-up name: “Not found” badge and “The .org registry does not know onekitly-rdap-probe-7f3k2q9x.org: it is probably available, with no guarantee (reserved name, deletion under way).” With nominet.uk, on the other hand, no request goes out at all: “Not covered” badge, the message “The .uk registry does not allow its data to be reused on a third-party site: check its official service.” and a link labelled “IANA record for the extension”.

What this lookup cannot tell you

  • Of the 1,438 extensions in the root zone, the tool queries 527 (count taken in September 2026; it follows IANA's directory). Twenty are left out because their registry does not allow its data to be reused: .uk, .de, .eu, .be, .nl, .ch, .at, .it, .us, .co, .br, .mx, .biz, .club, .vip, .xyz, .icu, .paris, .bzh and .citic. For .ie, .es, .pt and .lu, no RDAP service is known. All the others go unqueried because their terms have not been checked: the tool then points to the extension's IANA record or to ICANN Lookup.
  • .uk is out of reach too: Nominet's terms forbid extracting or reusing all or part of its data without permission; for .uk, the tool links to the IANA record, which names the registry. .us and .co are in the same position, with copying ruled out by GoDaddy Registry and storage or reproduction by CentralNic.
  • The holder stays hidden: registries almost always mask their contact details (GDPR), and the tool shows no data about the holder in any case. It cannot tell you who owns a domain; it tells you which registrar to turn to.
  • “Not found” does not guarantee the name is free: the registry may have reserved it, or a deletion may still be under way. Confirm availability with a registrar before counting on it.
  • Dates are the registry's, shown to the day in UTC: afnic.fr's creation, recorded on 10 December 2001 at 23:00 UTC, appears as Dec 10, 2001, although it was already midnight on the 11th in Paris. The registrar is never queried, and its own dashboard may show a day's difference depending on its time zone.
  • Answers stay cached for a minute (30 seconds for a name that isn't found): a name registered moments ago, or name servers changed just now, can take up to a minute to show.
  • No more than 10 lookups a minute from the same connection: beyond that, the message “Too many lookups in a short time. Try again in a minute.” appears. A registry can also throttle lookups on its side, or fail to answer within 5 seconds; the tool says which, and trying again a little later is enough.

Privacy

Processed on a server

The domain you type goes to the site's server, which queries the extension's registry itself: the registry sees our server's address and the name requested, never your IP address. To know which registry to ask, the server reads two public IANA files, the RDAP directory and the list of extensions, cached for a day: IANA sees neither the domain nor your address. No registrar is contacted, and for an extension that isn't covered, no request goes to any registry. The site keeps neither the domain nor the answer, apart from a minute in the CDN cache. To prevent abuse, a counter holds a fingerprint of your connection derived from your IP address, not the address itself. Usage statistics record that a lookup was started, succeeded or failed, never the domain.

Frequently asked questions

Can I find out who owns a domain name?

Rarely. Since the GDPR, registries almost always mask the holder's name and contact details, and this tool shows no data about the holder at all. What it does show is the registrar, with its IANA ID and, when the registry publishes them, an abuse email and phone number: that is the route for reporting a fraudulent site or asking to reach the holder. If the proxy status appears, the published contact belongs to an intermediary.

How do I find a domain's expiry date?

Type the name and look at the “Dates” card: “Expires” gives the day published by the registry, in UTC, and “Time left” the number of days remaining, for instance “in 1,037 days” for afnic.fr on 14 September 2026. Once the date has passed, the count switches to the past (“3 days ago”), and the statuses show where the domain stands: redemptionPeriod, deleted but still restorable by the holder, then pendingDelete, waiting to be released at the end of the registry's delay.

Is a “Not found” domain available?

Probably, but with no guarantee. “Not found” means the registry answered that it does not know the name. A name the registry has reserved, or a deletion still under way, can nonetheless stop you from registering it. Before building a project on it, start the purchase at a registrar: that is what confirms it. And since this answer stays cached for 30 seconds, a name someone registered moments ago can still show up as not found.

Why do .uk or .de domains show nothing?

Because their registries do not allow their data to be reused on a third-party site. Nominet's terms forbid extracting or reusing .uk data without permission, and DENIC restricts .de data to the technical or administrative running of the internet and to disputes. The tool sends no request at all: it shows “Not covered”, with a link to the IANA record for .uk and to DENIC's own lookup for .de. The same applies to .eu, .us or .co; .ie and .es have no known RDAP service.

What do clientTransferProhibited and the other EPP statuses mean?

They are a domain's EPP status codes, which RDAP publishes in its own spelling (the mapping is set by RFC 8056). Codes starting with client are set by the registrar, those starting with server by the registry. clientTransferProhibited stops the domain moving to another registrar, clientHold and serverHold suspend it from the DNS, and ok marks a domain with no restriction. The tool shows every code with a sentence; google.com carries six, locks on both sides.

Why isn't the name shown exactly the one I typed?

For two reasons. A registry only knows the registered name, so for a covered extension fr.wikipedia.org is cut back to wikipedia.org, and the message says so; the .fr zones gouv.fr, asso.fr, com.fr, tm.fr and nom.fr are the exception and stay whole. And an accented name travels in its ASCII form: café.com becomes xn--caf-dma.com, shown on the “ASCII form” row, while “Name” keeps the accents.

What's the difference between WHOIS and RDAP?

WHOIS is the original protocol: a text query on port 43, with each registry laying out its answer its own way. RDAP, its standardised successor (RFCs 9082 and 9083), returns JSON over HTTPS with defined fields, and IANA publishes a directory giving each extension's RDAP server. That is what lets the tool read a record from Verisign, Afnic or Identity Digital in the same way. It uses RDAP only, never port 43.

What does “Not published” mean on the DNSSEC card?

That the registry's record doesn't say whether the delegation is signed. The tool tells three cases apart: “Signed (DS at the registry)” when the registry reports a signed delegation or publishes DS or key data, “Unsigned” when it reports the opposite, and “Not published” when the information is missing, as for académie-française.fr. An unsigned zone is not a fault but the holder's choice; to check the signature chain itself, you need a DNS tool.

Further reading

All guides →
GuideHTTP Status Codes Explained: The Ones That Actually Get Confused301 against 308, 302 against 307, 401 against 403, 404 against 410 — plus what Retry-After on a 429 or a 503 actually promises. The pairs where picking the wrong code changes behaviour, not just wording.How-toHow to Write a Cron Expression: Five Fields and the OR Rule Nobody MentionsMinute, hour, day of month, month, day of week. The traps are that a step is a stride through a range and not an interval, and that the two day fields are combined with OR — so 0 0 1 * 1 fires on the 1st and on every Monday.ExplainerHow Unix File Permissions Work: Reading 755 Without GuessingRead is 4, write is 2, execute is 1, and each of the three digits describes a different party. The part most explanations get wrong is what the execute bit does on a directory — it grants traversal, not the right to run anything.How-toHow Long Does It Take to Upload a File? The Size Times 8 Divided by Speed FormulaEstimate upload time with one formula: file size in bits divided by your upload speed. Learn why upload is usually slower than download and how overhead affects the result.How-toHow to Write a robots.txt: Directives, Matching, and What It Cannot HideFour directives, two wildcards, one file at the host root. It is a crawl instruction and nothing more — it does not remove a page from search results, it does not restrict access, and it publishes every path you list in it.ExplainerSemicolon, Tab, Pipe: Choosing a Delimiter That Survives the TripWhy the reader's language decides the delimiter, what the converter does to the quoting when you switch, what the sep= first line really is, and the count of quoted cells on the same export written five ways.