UFOZoo

WHOIS Lookup — Domain, IP & ASN RDAP Lookup Tool Online Free

Look up domain, IP, and ASN data via RDAP — the modern replacement for WHOIS. Get registrar, dates, nameservers, DNSSEC, and abuse contact. 100% browser-based.

Features

  • Domain WHOIS — look up registrar, creation/expiry/update dates, nameservers, DNSSEC, and domain status (EPP codes)
  • ASN WHOIS — find the organization, CIDR range, country, and allocation date for any AS number
  • IP WHOIS — get the owning organization, network range, country, and abuse contact for any IP address
  • Uses the modern RDAP protocol (JSON-based successor to WHOIS) for structured, machine-readable results
  • Automatically detects your input type — just type a domain, IP address, or AS number and search
  • Displays raw RDAP JSON response for advanced users who need the full data
  • Caches RDAP server discovery data locally for faster subsequent lookups
  • All queries originate directly from your browser to the authoritative RDAP server — no intermediary server involved
  • Detailed DNSSEC information — shows whether DNSSEC is signed, the DS record digest type, and key tag for domains that have DNSSEC enabled
  • EPP status code explanations — each domain status code includes a human-readable description explaining what it means and how it affects domain operations
  • Automatic RDAP server discovery — the tool finds the correct authoritative RDAP server for any TLD or IP range without manual configuration
  • Copy individual data fields or the entire result — click any field to copy its value, or use the Copy All button to export the complete lookup report

How to Use

  1. 1Enter a domain name (e.g., example.com), IP address, or AS number (e.g., AS15169) in the search box.
  2. 2Click the Search button or press Enter to start the RDAP query.
  3. 3Browse the results organized into sections: Registrar, Dates, Nameservers, Status, and more.
  4. 4Click the Raw JSON tab to inspect the complete RDAP response data.
  5. 5Use the History tab to revisit previous lookups stored in your browser.
  6. 6When looking up a domain, check the DNSSEC section to confirm that DNSSEC is enabled — important for preventing DNS spoofing on sensitive domains like banking and e-commerce sites
  7. 7Review the EPP status codes — a status like 'clientTransferProhibited' means the domain is locked from unauthorized transfers, while 'pendingDelete' indicates imminent deletion
  8. 8Use the raw JSON view to access advanced data like RDAP notices, remarks, and linked resources that aren't displayed in the summary view

Frequently Asked Questions

What is RDAP and how is it different from WHOIS?

RDAP (Registration Data Access Protocol) is the modern replacement for WHOIS. It uses JSON for structured data, supports internationalization, provides authenticated access, and has standardized error codes. ICANN mandated RDAP for all gTLDs as of January 2025, making it the new standard for domain registration data lookup.

What input types does the tool support?

The tool supports three input types: domain names (e.g., example.com), IP addresses (both IPv4 and IPv6), and Autonomous System Numbers (e.g., AS15169 or 15169). Input is auto-detected so you don't need to select a lookup type manually.

Why do some lookups fail with CORS errors?

RDAP servers are operated by different registries and RIRs, and not all of them enable Cross-Origin Resource Sharing (CORS) for browser-based queries. If a lookup fails due to CORS, the tool provides a direct link to the RDAP service so you can view the data in a new tab. We are not able to proxy requests because this tool runs entirely in your browser with no server backend.

Does this tool send my data to any server?

Your browser queries RDAP servers directly. There is no intermediate proxy or server. However, the RDAP server you query (e.g., Verisign for .com, ARIN for IPs) will see your request, just as any web API call does. No data is stored or logged by this tool. Your search history is stored locally in your browser (IndexedDB/localStorage) and never leaves your device.

Why do some domain lookups show redacted data?

Many registries redact personal contact information (registrant, admin, tech) from RDAP responses due to GDPR and other privacy regulations. This is normal and intentional. The tool displays whatever data the RDAP server returns. If you need full contact data, you may need to use a service that authenticates with the registry, or use a dedicated WHOIS privacy proxy.

What are EPP status codes?

EPP (Extensible Provisioning Protocol) status codes indicate the current state of a domain. Common codes include: ok (normal), clientTransferProhibited (transfer locked), clientRenewProhibited (renewal locked), pendingDelete (scheduled for deletion), and serverHold (DNS deactivated). These codes affect what operations can be performed on the domain.

Is this tool free to use?

Yes, completely free. The tool uses public RDAP endpoints provided by ICANN-accredited registries and Regional Internet Registries (RIRs). There are no usage limits from the tool itself, though individual RDAP servers may have their own rate limiting policies.

What is an IP WHOIS query and what information does it show?

An IP WHOIS query looks up the organization, network range, country, and abuse contact for a specific IP address or IP range. This is useful for identifying who owns an IP block, reporting abuse (spam, hacking attempts), verifying whether an IP belongs to a cloud provider or residential ISP, and understanding network routing. The tool displays network CIDR range, organization name, country, and contact details for abuse reporting.

How do I read and interpret DNSSEC information in the results?

If DNSSEC is enabled for a domain, the tool shows the DS (Delegation Signer) record digest type (usually SHA-256), key tag (a numeric identifier), and the DNSKEY algorithm. A green indicator means DNSSEC is properly configured and the chain of trust is intact. If DNSSEC is missing or misconfigured, the domain is vulnerable to DNS spoofing attacks where an attacker could redirect traffic to a malicious server. For business-critical domains, DNSSEC should always be enabled.

What should I do with abuse contact information from an IP lookup?

The abuse contact email shown in IP WHOIS results should be used to report malicious activity originating from that IP address, such as hacking attempts, spam, DDoS attacks, phishing, or port scanning. When reporting, include relevant timestamps (with timezone), log excerpts, and a clear description of the incident. Most abuse teams respond within 24-48 hours. For emergency situations involving active attacks, contact your local CERT (Computer Emergency Response Team) instead.

Related Tools