Domain history databases: How to search a name’s drop record
A domain history is the full provenance record of a name: the number of times it has dropped and re-registered, who held it across the years, and how its WHOIS, hosting, and content fingerprint shifted between each cycle.
That record lives in drop history databases, and no single one holds the whole picture.
Historical WHOIS sits in WhoisXML API, WhoisFreaks, and DomainTools; drop-count recurrence and spam flags sit in SpamZilla and DomCop; DNS and infrastructure pivots sit in SecurityTrails; the visual content record sits in the Internet Archive Wayback Machine.
Searching one name fully means cross-referencing four or five tools by hand, reconciling pre-2018 identity against post-2018 redaction, and reading a repeated-drop pattern as the churn-and-PBN red flag it is.
SEO Domains runs that cross-database screen once, across a 220,000+ curated catalogue from $100 entry-level domains through $1.5 million premium acquisitions, so a buyer reviews the resolved history signal instead of assembling it five databases at a time.
What a domain history database is
A domain history database is a queryable archive of a name’s past expiration and registration events. For any given name it records the number of times the name has dropped, who held it across each cycle, and how its WHOIS, DNS, and content fingerprint changed over the years.
The archive aggregates registry zone files, registrar feeds, RDAP queries, and content snapshots into one searchable record of provenance.
A drop history database differs from a live drop list and from a single WHOIS lookup.
A live drop list publishes the names releasing on one calendar day, the pool sized in The daily drop pool: size and cadence. A single WHOIS lookup returns the current registration of one name.
A drop history database stores the full timeline behind that name across every recorded cycle. The three sources answer different questions.
- A live drop list answers what is available now.
- A live WHOIS lookup answers who holds the name now.
- A drop history database answers what happened before, the question that decides acquisition risk.
The history record is provenance evidence, not a quality score.
A drop history database reports facts about a name’s past: registration dates, registrant strings, name server changes, and drop counts. It does not rank the name.
Interpretation belongs to the analyst, who reads a clean single-owner timeline as low risk and a four-owner casino-to-pharma timeline as high risk.
The database supplies the evidence; the due-diligence judgement converts that evidence into a buy or skip decision.
What a drop history record actually stores
A drop history record stores eight categories of metadata: domain name, drop date and count, prior registrar, prior registrant identity, name server history, IP address history, lifecycle-phase timestamps, and content snapshots. Each category answers a separate question about prior ownership and prior use.
The depth and detail of each category vary by database. Four archives illustrate the spread.
- DomainTools holds historical WHOIS to 2002 and layers the Iris pivot graph across registrant, IP, name server, and SSL fingerprints.
- WhoisXML API records the latest 3 ownership changes per lookup against a 28.7 billion record archive.
- SpamZilla is the expiring-domain database built around backlink data, tracking the drop count alongside DNS history and an Archive.org content trail.
- BigDomainData publishes a free historical WHOIS archive of 2.89 billion records across 688 million domains.
The categories overlap. The coverage does not.
| Metadata category | Question it answers | Primary database |
|---|---|---|
| Drop date and count | How many times has the name expired, and when | SpamZilla, ExpiredDomains.net |
| Prior registrant identity | Who owned it across each cycle | WhoisXML API, WhoisFreaks, DomainTools |
| Prior registrar | Which registrar managed each registration | Historical WHOIS archives |
| Name server history | Where the name pointed across time | SecurityTrails, DomainTools Iris |
| IP address history | Which infrastructure hosted it | SecurityTrails, DomainTools Iris |
| Lifecycle-phase timestamps | Grace, redemption, and delete dates per cycle | RDAP feeds, registry data |
| Content snapshots | What the site actually displayed each year | Internet Archive Wayback Machine |
| Backlink and spam history | Whether the link profile shows prior abuse | SpamZilla, DomCop |
Which databases hold which slice of the history
Drop history splits across four database families: historical WHOIS archives for ownership, expiring-domain databases for drop count and spam flags, infrastructure databases for DNS and IP pivots, and the content archive for the visual record. Each family answers part of the provenance question, and a complete search reads all four.
Historical WHOIS archives hold ownership across the years.
WhoisXML API indexes 28.7 billion historical WHOIS records across 7,596 TLDs and surfaces the latest 3 ownership changes per lookup.
WhoisFreaks indexes 3.9 billion WHOIS snapshots dating back to 1986. Its free history tier returns a limited record count, and a separate Dropped Domain Search indexes 100 million dropped names.
DomainTools retains historical WHOIS to 2002 and adds the Iris pivot graph. BigDomainData and Whoxy both offer free historical WHOIS, and Whoxy adds reverse WHOIS at an entry-tier price point.
These archives answer one question: who held this name, and when.
Expiring-domain databases hold drop count and the spam verdict.
SpamZilla processes the daily expiring pool and records the drop count directly, the number of times a name has cycled through expiration. It pairs that count with a 1-to-100 spam score built from six inputs.
- Domain age across the record.
- Archive.org content history.
- Redirect status.
- Parked intervals.
- Anchor text distribution.
- Backlink history.
DomCop runs each name through 90-plus metrics and checks whether Google has ever banned the domain for prior spam.
ExpiredDomains.net covers 676 TLDs across deleted, pending-delete, and auction categories. It surfaces Majestic Trust Flow and Citation Flow, domain age, and Wayback data on each listing.
These databases answer a second question: has this name been abused, and how repeatedly has it churned. SpamZilla frames the answer as spam detection across the prior website history, not a single score.
Infrastructure and content databases close the picture.
SecurityTrails specializes in DNS and IP history. Paid plans start around $50 per month, the free tier grants 50 DNS-history queries per month, and enterprise tiers serve threat-intelligence teams.
The reverse IP and reverse name server pivots reveal hosting consolidation and shared infrastructure between aged domains. They expose the registration spikes that betray a network built in one burst.
The Internet Archive Wayback Machine preserves content snapshots across a name’s registration years and confirms whether topical use stayed continuous or pivoted.
Together the infrastructure database and the content archive convert a list of dates into a story about how the name was run in practice.
How to search drop history by domain, registrant, IP, and name server
Drop history databases support five search patterns: forward lookup by domain name, reverse WHOIS by registrant identity, reverse IP by hosting address, reverse name server by DNS pair, and recurrence filtering by drop count.
Each pattern starts from a different known input and returns a different slice of the provenance graph.
Reverse WHOIS finds every domain tied to one registrant.
Reverse WHOIS queries the archive for all names registered under a given email, organization, name, or phone number.
WhoisXML API runs reverse WHOIS against 25.5 billion records, and WhoisFreaks and Whoxy both expose it through web UI and API.
The pattern exposes portfolios. An aged domain whose prior registrant also held a cluster of spam names inherits guilt by association that a forward lookup alone would miss.
Reverse WHOIS produces false positives when registrant names collide. A match against a common name is cross-validated against IP and name server data before it counts as evidence.
Reverse IP and reverse name server expose shared infrastructure.
A reverse IP query returns every domain hosted on one address at a point in time. A reverse name server query returns every domain pointing to one DNS pair. SecurityTrails indexes both pivots at scale.
The two patterns surface PBN footprints invisible to surface WHOIS, because a private blog network shares hosting and name servers even when it scatters registrant identities.
A name that historically shared a name server with a confirmed link farm carries that proximity in its record.
Drop-count filtering surfaces the names that keep cycling.
SpamZilla treats drop count as a first-class filter. An analyst sorts the expiring pool by the number of prior expirations and isolates names that have dropped repeatedly.
ExpiredDomains.net and DomCop expose age and recurrence signals alongside Majestic metrics.
Drop-count filtering pairs with the signal-versus-noise screen detailed in Spotting value in drop lists: signal vs noise. Together they separate a name dropped once by an owner who forgot to renew from a name abandoned and re-abandoned across owners.
How repeated-drop history flags churn and PBN risk
A domain that has dropped 3 or more times, or shows rapid ownership changes paired with a backlink spike and collapse, signals registration churn, prior PBN reuse, or penalty residue.
Repeated-drop history is the single clearest valuation red flag a drop history database surfaces, because abandonment recurs for a reason.
Recurrence reads as risk because each abandonment carries information. A name registered, built, and held for a decade dropped once when its owner retired tells a clean story.
A name that cycled through four owners in six years, each holding it briefly before letting it lapse, tells a story of failed monetization, PBN burn, or penalty flight.
The DomainDetails due-diligence record names multiple rapid ownership changes as a core red flag, alongside content pivots, language changes, and prior PBN use.
Google’s expired domain abuse policy, launched 5 March 2024, targets names repurposed off a mismatched prior reputation, the exact profile a high-recurrence record exposes.
A high-recurrence name is not automatically worthless, but it shifts the burden of proof.
The analyst who buys it accepts inherited risk that the history record made visible. The deeper audit of those exposures is covered in Risks of buying an expired domain: 7 costly mistakes and how to avoid them.
When the history shows recurrence plus a topical pivot plus a link collapse, the record has converted a strong-looking name into a documented liability. That condition is mapped in When an aged domain is worse than a new one.
How the WHOIS sunset and GDPR redaction shape the record
ICANN retired plaintext WHOIS on 28 January 2025 under Specification 4, completing the transition to RDAP. GDPR redaction since 2018 already obscured registrant identity for natural persons.
Pre-sunset records stay searchable in archive databases. The high-value identity window runs from 2002 to 2018.
The two events reshape what a reverse-WHOIS search can recover. RDAP returns structured JSON with standardized field names where plaintext WHOIS returned inconsistent key-value text, so post-sunset records index more cleanly.
GDPR redaction since 2018 shows REDACTED FOR PRIVACY for natural-person registrants, with registrars applying it globally for operational consistency.
The practical effect is a divide: a reverse-WHOIS query against pre-2018 history returns identifiable registrants, while the same query against post-2018 history returns mostly redacted strings.
Pre-2018 history is the high-value attribution window.
A name registered and held before 2018 leaves 16 years of identifiable WHOIS evidence, from the 2002 DomainTools baseline to the redaction wall.
That window is where reverse-WHOIS attribution does its real work, linking prior registrants to portfolios and surfacing the churn patterns that matter.
A name first registered after 2018 carries a thinner, mostly redacted record, which raises the weight of infrastructure pivots and Wayback content as the remaining attribution signals.
The lifecycle status tooling that reads current records is catalogued in Domain lifecycle tracking: WHOIS, RDAP, and the workflow tools that monitor every status code.
How the four-database search workflow runs in order
The drop history search runs four databases in sequence: an expiring-domain database for drop count and spam verdict, a historical WHOIS archive for ownership, an infrastructure database for DNS and IP pivots, and the Wayback Machine for content continuity.
Each step narrows the candidate set while raising confidence in the verdict.
The order is deliberate. The cheapest, fastest signal runs first. SpamZilla or DomCop returns the drop count and spam score in one pass, eliminating serial-abandonment and Google-banned names before any deeper work.
The historical WHOIS archive then attributes the survivors to prior registrants and runs reverse WHOIS on the strongest candidates. SecurityTrails pivots those on shared IP and name server to catch PBN proximity.
The Wayback Machine closes the read by confirming the content matched a continuous topical use instead of pivoting across cycles.
Reversing the order, opening Wayback on an unfiltered list, burns the expensive manual hours on names a drop-count filter would have killed in seconds.
| Step | Database family | Search pattern | What it resolves |
|---|---|---|---|
| 1. Drop count and spam | SpamZilla, DomCop | Recurrence filter, spam score | Kills serial-abandonment and Google-banned names |
| 2. Ownership history | WhoisXML API, WhoisFreaks | Historical and reverse WHOIS | Attributes prior registrants and portfolios |
| 3. Infrastructure pivot | SecurityTrails, DomainTools Iris | Reverse IP, reverse name server | Surfaces shared hosting and PBN proximity |
| 4. Content continuity | Internet Archive Wayback Machine | Year-by-year snapshot read | Confirms topical use stayed continuous |
Free tiers triangulate; paid tiers compound the signal.
Five free tiers together supply a usable triangulation for a budget-constrained researcher.
- BigDomainData free historical WHOIS.
- WhoisFreaks free history tier.
- Whoxy free reverse WHOIS.
- The SecurityTrails 50-query free allowance.
- The public Internet Archive Wayback Machine.
Paid tiers compound the signal. DomainTools Iris navigates registrant, IP, and name server in one pivot graph, and WhoisXML API cross-references registrant patterns across a portfolio.
The free path works for one name at a time. The paid path scales the read across a list. The broader sourcing-to-acquisition routine these searches feed is mapped in Scanning a daily drop list: workflow.
5 frequently asked questions about drop history databases
The 5 questions buyers raise about drop history databases concern free options, legality, the best tool for ownership history, what the WHOIS sunset changed, and how to read a repeated-drop count.
The answers reflect the SEO Domains analytical position alongside documented database capabilities and dates.
Q1Is there a free domain drop history database?
Free history exists across five databases, none complete alone.
- BigDomainData: free historical WHOIS, 2.89 billion records.
- WhoisFreaks: free history tier plus a free Dropped Domain Search across 100 million names.
- Whoxy: free reverse WHOIS.
- SecurityTrails: 50 free DNS-history queries per month.
- Internet Archive Wayback Machine: fully free.
Triangulating the five covers a single name for a budget-constrained researcher, though paid tiers add depth and scale.
Q2Are drop history searches legal?
Drop history searches qualify as open-source intelligence under public-record rules, since registration data has been public DNS infrastructure since the early internet.
Authenticated queries against WhoisXML API, DomainTools, SecurityTrails, WhoisFreaks, and similar databases remain compliant because the providers hold the licensing and access agreements with registries.
Scraping ICANN registries directly violates registry policy and contractual terms, which is the line a researcher does not cross.
Q3Which database is best for domain ownership history?
For raw ownership depth, WhoisXML API leads with 28.7 billion historical WHOIS records across 7,596 TLDs and the latest 3 ownership changes per lookup. WhoisFreaks reaches back to 1986 across 3.9 billion snapshots.
DomainTools adds the Iris pivot graph for high-stakes attribution. The best choice tracks the use case: WhoisXML API for breadth, WhoisFreaks for historical reach, and DomainTools for investigative pivots.
Q4What did the WHOIS sunset on 28 January 2025 change?
It retired plaintext WHOIS in favor of structured RDAP under ICANN Specification 4. New records arrive cleaner and more uniform, which improves indexing for fresh data.
It introduced no break in historical searchability, since pre-2025 records remain in archive form. The larger constraint on history searches is the GDPR redaction wall of 2018, which obscured registrant identity well before the protocol changed.
Q5How is a repeated-drop count read?
A drop count of 3 or more shifts the burden of proof onto the name. One drop reads as an owner who forgot to renew.
Repeated drops across different owners read as serial abandonment, PBN burn, or penalty flight, especially when paired with a backlink spike-and-collapse or a topical pivot in the Wayback trail.
SpamZilla exposes the count directly; the deeper interpretation pairs it with the spam score and content history before any acquisition.
How the curated catalogue resolves the history once
Drop history is one more manual due-diligence layer: real, decisive, and laborious to verify across five databases that disagree on identity, depth, and date.
SEO Domains has already run that cross-database history screen across a 220,000+ curated catalogue, scoring Domain Authority, Domain Rating, Trust Flow, and Citation Flow and applying a 7-vector inheritance screen.
A buyer reviews the resolved provenance signal instead of cross-referencing WhoisXML API, SpamZilla, SecurityTrails, and the Wayback Machine by hand for every candidate.
| History layer | Manual cross-database research | Curated SEO Domains catalogue |
|---|---|---|
| Ownership history | Reconcile WhoisXML API, WhoisFreaks, DomainTools by hand | Prior-registrant continuity screened before listing |
| Drop count and recurrence | Sort SpamZilla, read DomCop ban check per name | Serial-abandonment names filtered at ingestion |
| Infrastructure pivot | Run SecurityTrails reverse IP and name server lookups | Shared-infrastructure and PBN proximity screened |
| Content continuity | Open one Wayback snapshot per year per candidate | Topical continuity checked across the catalogue |
| Identity window | Reconcile pre-2018 identity against post-2018 redaction | Resolved provenance reported on the listing |
The catalogue runs the cross-database screen once so the buyer does not assemble it per name.
A raw drop record hands a buyer five databases that each answer one question and disagree at the edges. The curated catalogue resolves the disagreement upstream.
SEO Domains reads ownership history, drop-count recurrence, infrastructure pivots, and content continuity at ingestion. It surfaces Domain Authority, Domain Rating, Trust Flow, and Citation Flow on each listing, and lists only names that clear the 7-vector inheritance screen.
The buyer reviews the resolved history, the same verdict a disciplined five-database search would reach, without running the search. ICANN-accredited transfer applies to every acquisition.
