Back to Utiliverse
Utiliverse Guides

All guides / Networking

What WHOIS and RDAP data can—and cannot—tell you

Use registration records to investigate registrar, status, and delegation while keeping ownership, availability, and website trust separate.

By UtiliverseLast reviewed: September 29, 2026

Start with the question a registration record can answer

Registration data can help identify a domain’s registrar, reported events, status codes, and nameserver delegation. Utiliverse’s WHOIS Lookup retrieves RDAP data: a structured response from a registration-data service. ICANN identifies RDAP as the definitive registration-data source for generic top-level domains following the January 2025 transition; country-code domains and individual service arrangements can differ. See ICANN’s transition notice.

Begin with the domain itself, not a screenshot of a website. A plausible-looking page and a registration record answer different questions. Neither record age nor a familiar registrar is a guarantee that a current website is legitimate.

Worked example: an upcoming renewal

Suppose a lookup reports an expiration event in 20 days. Record the exact event type, timestamp, service, and lookup time. Then confirm the renewal state in the registrar account that manages the domain. An RDAP event is useful evidence, but it is not a bill, proof of payment, or assurance that auto-renewal will succeed.

If the record contains multiple events, do not substitute “last changed” for “registration” or infer that the current owner has held the name continuously since creation. The tool presents fields supplied by the service; absent data stays unknown.

Read these fields with their limits

Useful checks and common overclaims
FieldUseful checkLimit
RegistrarWhere to investigate registration managementNot necessarily the website host
NameserversWhere DNS is delegatedNot the same as a current A or MX answer
Status codesTransfer, hold, or lifecycle cluesInterpret each code with registry guidance
DNSSEC dataRegistration-side signing/delegation informationNot a complete live validation test
Registrant fieldsPublicly returned contact informationMay be redacted, absent, or represented by a service

Missing data is not an availability check

A not-found result can mean the domain is unregistered, but a lookup can also fail because of unsupported coverage, a provider error, rate limiting, or browser restrictions. Confirm registration availability through a registrar. Likewise, privacy-redacted contact information is not by itself evidence of wrongdoing.

ICANN’s RDAP user guidance explains the purpose and access model. Public access does not mean every personal field is publicly returned.

A practical investigation record

  1. Normalize the domain and confirm spelling, including internationalized names.
  2. Save the reported registrar, relevant events, and status values with the lookup time.
  3. Use the raw JSON when a formatted field is ambiguous; keep the source’s labels.
  4. For web failures, investigate DNS answers and TLS separately. For mail failures, check email records and a real message’s authentication results.
  5. Confirm account actions such as renewal or transfer with the managing registrar.

The lookup sends the domain to an external RDAP service. It does not access your registrar account or change the registration. Avoid sending private internal hostnames that are not meaningful public registration queries. A subdomain is not necessarily a separately registered domain; start with the registered name when investigating ownership and renewal.

Try the related tools

Continue reading

Sources and review

Examples are illustrative. Reviewed September 29, 2026 against the listed references and the related tool behavior. Methodology · Report a correction.