Skip to main content
UFOZoo

WHOIS Lookup: Domain, IP, ASN & RDAP Lookup Online

WHOIS lookup online: query domain registration, IP ownership, ASN, nameservers, and DNSSEC via RDAP, with raw and parsed views for research.

Updated 2026-08-16

Related Tools

Features

  • Domain WHOIS: look up registrar, creation/expiry/update dates, nameservers, DNSSEC, and domain status (EPP codes)
  • ASN WHOIS: find the organization, CIDR range, country, and allocation date for any AS number
  • IP WHOIS: get the owning organization, network range, country, and abuse contact for any IP address
  • Uses the modern RDAP protocol (JSON-based successor to WHOIS) for structured, machine-readable results
  • Automatically detects your input type: just type a domain, IP address, or AS number and search
  • Displays raw RDAP JSON response for advanced users who need the full data
  • Caches RDAP server discovery data locally for faster subsequent lookups
  • All queries originate directly from your browser to the authoritative RDAP server; no intermediary server involved
  • Detailed DNSSEC information: shows whether DNSSEC is signed, the DS record digest type, and key tag for domains that have DNSSEC enabled
  • EPP status code explanations: each domain status code includes a human-readable description explaining what it means and how it affects domain operations
  • Automatic RDAP server discovery: the tool finds the correct authoritative RDAP server for any TLD or IP range without manual configuration
  • Copy individual data fields or the entire result: click any field to copy its value, or use the Copy All button to export the complete lookup report

How to Use

  1. 1Enter a domain name (e.g., example.com), IP address, or AS number (e.g., AS15169) in the search box.
  2. 2Click the Search button or press Enter to start the RDAP query.
  3. 3Browse the results organized into sections: Registrar, Dates, Nameservers, Status, and more.
  4. 4Click the Raw JSON tab to inspect the complete RDAP response data.
  5. 5Use the History tab to revisit previous lookups stored in your browser.
  6. 6When looking up a domain, check the DNSSEC section to confirm that DNSSEC is enabled, important for preventing DNS spoofing on sensitive domains like banking and e-commerce sites
  7. 7Review the EPP status codes: a status like 'clientTransferProhibited' means the domain is locked from unauthorized transfers, while 'pendingDelete' indicates imminent deletion
  8. 8Use the raw JSON view to access advanced data like RDAP notices, remarks, and linked resources that aren't displayed in the summary view

Frequently Asked Questions

What is RDAP and how is it different from WHOIS?

RDAP (Registration Data Access Protocol) is the modern replacement for WHOIS. It uses JSON for structured data, supports internationalization, provides authenticated access, and has standardized error codes. ICANN mandated RDAP for all gTLDs as of January 2025, making it the new standard for domain registration data lookup.

What input types does the tool support?

The tool supports three input types: domain names (e.g., example.com), IP addresses (both IPv4 and IPv6), and Autonomous System Numbers (e.g., AS15169 or 15169). Input is auto-detected so you don't need to select a lookup type manually.

Why do some lookups fail with CORS errors?

RDAP servers are operated by different registries and RIRs, and not all of them enable Cross-Origin Resource Sharing (CORS) for browser-based queries. If a lookup fails due to CORS, the tool provides a direct link to the RDAP service so you can view the data in a new tab. We are not able to proxy requests because this tool runs entirely in your browser with no server backend.

How do I find out who owns an IP address?

Type the IP address (IPv4 or IPv6) into the search box and the RDAP result shows the owning organization, the network CIDR range, the country, and an abuse contact. One honest caveat: this returns the network owner (an ISP, hosting provider or company), not the individual user behind the address; that level of detail is not public data.

Why does my WHOIS result differ from GoDaddy's WHOIS?

Both sides query the same registry data, so the core fields (registrar, dates, nameservers, status) should match. Differences come from the display layer: GoDaddy merges privacy-proxy data, applies its own formatting, and may show cached results, while this tool returns the raw RDAP response including fields GoDaddy hides. When they conflict, the registry's own RDAP/WHOIS is authoritative.

Why do some domain lookups show redacted data?

Many registries redact personal contact information (registrant, admin, tech) from RDAP responses due to GDPR and other privacy regulations. This is normal and intentional. The tool displays whatever data the RDAP server returns. If you need full contact data, you may need to use a service that authenticates with the registry, or use a dedicated WHOIS privacy proxy.

What are EPP status codes?

EPP (Extensible Provisioning Protocol) status codes indicate the current state of a domain. Common codes include: ok (normal), clientTransferProhibited (transfer locked), clientRenewProhibited (renewal locked), pendingDelete (scheduled for deletion), and serverHold (DNS deactivated). These codes affect what operations can be performed on the domain.

What is an IP WHOIS query and what information does it show?

An IP WHOIS query looks up the organization, network range, country, and abuse contact for a specific IP address or IP range. This is useful for identifying who owns an IP block, reporting abuse (spam, hacking attempts), verifying whether an IP belongs to a cloud provider or residential ISP, and understanding network routing. The tool displays network CIDR range, organization name, country, and contact details for abuse reporting.

How do I read and interpret DNSSEC information in the results?

If DNSSEC is enabled for a domain, the tool shows the DS (Delegation Signer) record digest type (usually SHA-256), key tag (a numeric identifier), and the DNSKEY algorithm. A green indicator means DNSSEC is properly configured and the chain of trust is intact. If DNSSEC is missing or misconfigured, the domain is vulnerable to DNS spoofing attacks where an attacker could redirect traffic to a malicious server. For business-critical domains, DNSSEC should always be enabled.

What should I do with abuse contact information from an IP lookup?

The abuse contact email shown in IP WHOIS results should be used to report malicious activity originating from that IP address, such as hacking attempts, spam, DDoS attacks, phishing, or port scanning. When reporting, include relevant timestamps (with timezone), log excerpts, and a clear description of the incident. Most abuse teams respond within 24-48 hours. For emergency situations involving active attacks, contact your local CERT (Computer Emergency Response Team) instead.

Why can't I look up some ccTLD domains like .cn?

Country-code top-level domains are operated by their national registries, and not all of them support RDAP or allow open queries; .cn and several other ccTLDs restrict or omit data for third-party lookups. When a query fails or returns minimal data, try the registry's own lookup page or your registrar's WHOIS tool. This is a registry-side limitation, not a problem with this tool.

Why does my whois lookup ip show a location hundreds of miles away?

An IP WHOIS record describes the network's registrant (usually the ISP, hosting company, or data center), not the person using the address, and the registered city can be the company's HQ or registry location. Geolocation databases then approximate, which is why a home IP may appear in another city, and VPN or cloud IPs look like their exit nodes. Use IP WHOIS to identify the owner and abuse contact, not to locate a user; for approximate location, a geolocation API is the honest tool.

Why does my whois lookup tool return nothing for a domain I just registered?

Brand-new registrations can take a few minutes to a few hours (occasionally 24-48 hours) to propagate from the registry to RDAP servers and WHOIS mirrors, so a lookup right after purchase may return 'no data' or the old status. Wait, clear the query history, and retry; if it still shows nothing after 48 hours, ask your registrar to verify the registration (or check whether privacy redaction hides the fields, which looks like missing data).