WHOIS Lookup Services Compared: The Best Free, Paid, and API Tools for Domain Research in 2026
A WHOIS lookup service reads the public registration record behind a domain name and returns the registrar, the registration and expiry dates, the nameservers, and the domain status. The tools that do this range from a free registry lookup to a paid research suite with historical and reverse search, and they do not return the same depth of data.
Two facts decide which service fits a job. Registrant contact data is redacted by default since the EU GDPR took effect in 2018, so the owner name you expect to see is frequently hidden. And the legacy WHOIS protocol itself reached its ICANN sunset on 28 January 2025, with the Registration Data Access Protocol (RDAP) now the standard lookup behind the better tools.
This guide compares the WHOIS lookup services that matter for domain research across free, paid, and API tiers, with a side-by-side table the listicles leave out. It also draws the line that matters for a domain buyer: a clean registration history is one input into vetting an aged or expired domain before you acquire it, and SEO Domains screens that history across a 220,000+ catalogue, from $100 entry-level aged domains through premium acquisitions, before a name reaches the marketplace.
What a WHOIS lookup actually shows on a domain
A WHOIS lookup returns the public registration record for a domain name: the sponsoring registrar, the creation and expiry dates, the last-updated date, the nameservers, the domain status codes, and, where it is not redacted, the registrant organisation and country. It does not show traffic, backlinks, or page content, and by default the registrant person is now hidden.
The record is the administrative paperwork behind a domain, not its marketing profile. When you query a name, the lookup returns the fields the registry and registrar publish, and nothing about how the site performs. That distinction matters when a tool promises more than the protocol can deliver.
The fields a WHOIS record contains
Every WHOIS or RDAP response is built from the same core fields. Knowing them tells you what a lookup can answer and what it cannot:
- Registrar. The ICANN-accredited company that sponsors the registration, such as GoDaddy, Namecheap, or Gandi.
- Creation, updated, and expiry dates. When the domain was first registered, last changed, and when it lapses. The creation date is the domain age signal investors read first.
- Nameservers. The DNS servers the domain points to, which reveal the hosting or DNS provider.
- Domain status codes. EPP status values such as clientTransferProhibited or pendingDelete that describe the registration lifecycle.
- Registrant data. Organisation, country, and historically the contact name and email. On most domains this is now marked REDACTED FOR PRIVACY.
What a WHOIS lookup cannot tell you
A WHOIS lookup is silent on the things a domain buyer cares about first: the backlink profile, the organic traffic history, the spam record, and what the site published in the past. Those live in other tools, and reading them is the work covered across the Domain Authority & Metrics hub and the Wayback archive in the same discovery toolkit. A WHOIS service answers who and when, not how good.
How WHOIS lookups changed: the WHOIS protocol, RDAP, and redaction
Two shifts reshaped every WHOIS lookup service. GDPR in 2018 forced registrars to redact registrant contact data on the public record, and ICANN set 28 January 2025 as the sunset of the legacy WHOIS protocol, with the Registration Data Access Protocol (RDAP) as its structured successor. A tool described as WHOIS today is frequently querying RDAP underneath.
The legacy WHOIS protocol and its 2025 sunset
The original WHOIS protocol dates to the early internet and runs over port 43, returning free-form text that differs registry to registry. Its weakness was always that the format was inconsistent and not machine-friendly. ICANN approved RDAP as the replacement and, per its published transition, the contractual requirement to run the legacy WHOIS service ended on 28 January 2025. Registries and registrars now serve registration data through RDAP, which returns the same fields in structured JSON.
Why GDPR redaction is the bigger practical change
The protocol change is plumbing. The redaction change is what you feel on every lookup. After EU GDPR took effect on 25 May 2018, ICANN’s Temporary Specification required registrars to strip personal registrant data from public responses for domains tied to natural persons. The result is the REDACTED FOR PRIVACY line that now fills the registrant fields on the public record. Registration data still exists, but access to the personal layer narrowed.
This is the reason a free WHOIS lookup so frequently disappoints a researcher. The owner name is gone by design. The fields that survive, the registrar, the dates, the nameservers, and the status, carry the signal a domain investor relies on, and the historical and reverse tools fill the gap where current ownership is hidden.
The WHOIS protocol is standardised in RFC 812, returning free-form text over port 43. It becomes the default registration-data lookup for decades. Source: IETF RFC archive.
EU GDPR takes effect. ICANN’s Temporary Specification requires registrars to redact registrant personal data from public WHOIS, producing the REDACTED FOR PRIVACY record. Source: ICANN GDPR and WHOIS materials.
RDAP is ratified and rolled out as the structured, JSON-based successor to WHOIS, returning the same fields in machine-readable form. Source: ICANN RDAP program.
The contractual requirement for registries and registrars to operate the legacy WHOIS protocol ends. RDAP becomes the standard ICANN registration-data lookup. Source: ICANN WHOIS-to-RDAP transition notice.
The four categories of WHOIS lookup service
WHOIS lookup services fall into four categories, and they answer different questions. Registry and registry-grade tools give the authoritative current record. Registrar lookups give a fast free check tied to a buy flow. Research suites add historical and reverse search behind a subscription. API and bulk tools serve programmatic domain research at scale with published rate limits.
Choosing well starts with the category, not the brand. A single availability check and a portfolio investigation pull from different tiers, and a tool built for one is weak at the other. The four cells below frame the field before the named comparisons.
Registry and registry-grade
ICANN Lookup and registry operators like Verisign. The authoritative current record, RDAP-backed, free, no historical or reverse search. The source of truth for what a domain looks like right now.
Registrar lookups
GoDaddy, Whois.com, Gandi, NameSilo, DNSimple. Fast, free, clean, and wired to a registration flow. Good for availability and a quick read, thinner on data, biased toward a buy prompt.
Research suites
DomainTools and peers. Historical WHOIS, reverse WHOIS, hosting history, and screenshots behind a subscription. Built for investigation: who owned a domain before, and what else they own.
API and bulk tools
HackerTarget, MXToolbox, and provider APIs. Programmatic lookups in JSON for scripted research, with published per-day rate limits and paid tiers for higher throughput.
Free WHOIS lookup tools compared
The free tier covers the registry source of truth and the registrar quick-checks. ICANN Lookup is the authoritative RDAP-backed record. Whois.com, GoDaddy, Gandi, NameSilo, and DNSimple give fast free reads tied to a registration flow. MXToolbox bundles WHOIS into a diagnostics suite. All return the unredacted fields, none give historical or reverse search for free.
ICANN Lookup: the authoritative current record
ICANN Lookup at lookup.icann.org is the registry-grade tool, querying RDAP to return the current authoritative record for generic top-level domains. It is the reference point: when a registrar lookup and a research suite disagree on a current field, the ICANN record is the tiebreaker. It carries no historical view, no reverse search, and no API for general users, because its job is to be correct about now, not to investigate the past.
Registrar quick-checks: Whois.com, GoDaddy, Gandi, NameSilo, DNSimple
The registrar lookups are the fast free workhorses. Whois.com, GoDaddy WHOIS, Gandi, NameSilo, and DNSimple each return the registrar, dates, nameservers, and status in seconds, with a clean interface aimed at beginners. The trade is depth and neutrality. The data is thinner than a research suite, and the page is wired to nudge an available name toward a registration cart. For a single availability-and-status read, that trade is fine.
MXToolbox: WHOIS inside a diagnostics suite
MXToolbox folds a free WHOIS lookup into a broader suite of DNS, blacklist, and mail-server checks. For a technical user already running an MX or blacklist test, having WHOIS in the same place is convenient. As a standalone WHOIS service it is shallow, because the lookup is one feature in a wider toolset and not the product.
Paid and research-grade WHOIS services compared
The paid tier exists for one thing the free tools cannot do: investigate the past and the connections. DomainTools is the reference research suite, with historical WHOIS, reverse WHOIS, hosting history, and screenshots behind a subscription. The value is not the current record, which is free elsewhere, but the ownership timeline and the portfolio links that matter for diligence.
DomainTools: historical and reverse WHOIS
DomainTools is the named leader of the research tier. Its historical WHOIS shows what a domain’s record looked like before the GDPR redaction era, which is how an investigator recovers a prior owner that the current record hides. Its reverse WHOIS finds other domains tied to the same registrant fingerprint, the basis for mapping a portfolio or a network. Hosting history and screenshots round out the picture of how a domain was used over time. These capabilities sit behind a paid subscription, which is the honest cost of the only data the free tier structurally cannot provide.
When the paid tier earns its cost
The subscription pays for itself on diligence, not on a casual check. Two jobs justify it: recovering a redacted prior owner through historical records, and mapping connected domains through reverse search. Both feed directly into evaluating an aged or expired domain before acquisition, where a hidden past owner or a tie to a spam network changes the decision. The deeper techniques for the historical layer are set out in Historical WHOIS research: databases and techniques, and the portfolio-mapping side in Reverse WHOIS.
API and bulk WHOIS lookup for programmatic domain research
Scripted domain research needs a WHOIS lookup that returns structured data and accepts automated queries. HackerTarget exposes a WHOIS API in JSON and plain text with published rate limits of 5 queries per day on the free tier and 500 to 2,000 per day for members. Provider APIs and RDAP endpoints serve higher volume. Bulk and API access is where rate limits, not features, decide the tool.
HackerTarget and the API model
HackerTarget is the worked example of the API tier. Its WHOIS endpoint answers a simple HTTP call and returns JSON or text, which makes it scriptable for a research pipeline. Its own published limits are explicit: 5 queries per day for free accounts, rising to a 500 to 2,000 daily range on membership, with captcha gates on the free tier removed for members. The honest read of the API tier is that the per-day cap, not the data depth, is the constraint you plan around.
RDAP as the native structured endpoint
Because RDAP returns JSON by design, the RDAP endpoints run by registries are themselves a programmatic lookup. For a developer building domain research tooling, querying RDAP directly removes a layer of dependence on a third-party WHOIS service and reads the registration data in its native structured form. The bulk monitoring use case, watching status codes change across a watchlist, is covered in the wider discovery toolkit alongside drop monitoring.
The full side-by-side WHOIS lookup comparison
The consolidated table below is the comparison the roundup articles omit. It maps each named WHOIS lookup service to its category, its free tier and rate limit, its API support, whether it offers reverse and historical search, how it handles redaction, and the job it fits best. Read it as the decision grid, then match the row to the task in the next section.
No single service wins every column, which is the point. The registry tool is authoritative and free but shallow. The research suite is deep but paid. The API tool is scriptable but rate-capped. The grid makes the trade explicit so the choice follows the job and not the marketing.
| Service | Category | Free tier | API | Reverse / historical | Best for |
|---|---|---|---|---|---|
| ICANN Lookup | Registry-grade (RDAP) | Free, no cap | No public user API | No / No | The authoritative current record |
| Verisign WHOIS | Registry operator | Free, no cap | RDAP endpoint | No / No | Authoritative .com and .net data |
| Whois.com | Registrar lookup | Free | Limited | No / No | Fast availability and status check |
| GoDaddy WHOIS | Registrar lookup | Free | No public API | No / No | Quick read tied to registration |
| Gandi / NameSilo / DNSimple | Registrar lookup | Free | Registrar API (account) | No / No | Registrar-managed portfolios |
| MXToolbox | Diagnostics suite | Free | Paid API | No / No | WHOIS alongside DNS and blacklist tests |
| DomainTools | Research suite | Limited preview | Paid API | Yes / Yes | Ownership history and portfolio mapping |
| HackerTarget | API / bulk | 5 queries/day | JSON / text API | No / No | Scripted lookups at small volume |
How to choose a WHOIS lookup service for domain research
Choosing a WHOIS lookup service is a five-step match between the question you are answering and the tier that answers it. Define the job, start from the free authoritative record, escalate to a research suite only when you need the past, reach for an API only at volume, and always confirm a critical field against the ICANN record. The wrong tier wastes money or returns thin data.
The sequence below pairs the right move with the mistake that sends researchers to the wrong tool. Each step names the tier it points to, so the choice is mechanical and not a guess.
-
Define the question first
Name the job before the tool. Availability and status, current registrar, prior owner, or connected portfolio are four different questions that point at four different tiers. The job decides the service.
The mistake: opening a paid research suite to answer a question a free registry lookup settles in seconds, or expecting a free registrar tool to reveal a redacted prior owner it never holds.
-
Start from the authoritative free record
For the current state of a domain, start at ICANN Lookup or the registry. It is free, RDAP-backed, and authoritative, so it answers availability, registrar, dates, nameservers, and status with no cost and no upsell.
The mistake: trusting a single registrar lookup as gospel when its cached record lags the registry. Confirm a field that matters against the ICANN record.
-
Escalate to a research suite only for the past
When the question is who owned this before redaction or what else they own, move to a paid suite like DomainTools for historical and reverse WHOIS. That is the data the free tier structurally cannot provide.
The mistake: paying for a subscription to read a current record that ICANN Lookup returns free, or skipping the historical check on a domain you are about to buy.
-
Reach for an API only at volume
For hundreds or thousands of lookups, use an API like HackerTarget or query RDAP endpoints directly. Plan around the published per-day rate limit, because at scale the cap is the constraint, not the data.
The mistake: scripting a bulk run against a free tier capped at 5 queries a day, then wondering why the job stalls after the first five domains.
-
Read redaction as data, not a dead end
When the registrant shows REDACTED FOR PRIVACY, read the fields that survive. Registrar, dates, nameservers, and status still carry the domain age and lifecycle signal an investor needs, and a historical tool recovers the hidden owner.
The mistake: treating a redacted record as a failed lookup and abandoning the research, when the surviving fields and the historical record still answer the real question.
Common WHOIS lookup mistakes and how to read redacted data
The errors that derail a WHOIS lookup are a short, repeatable list. Each one is a wrong assumption about what the record contains or which tool holds it, and each has a fix. The fixes converge on one habit: confirm the authoritative record, read redaction as partial data, and escalate tiers only when the question demands it. Use this as the scannable reference.
The table consolidates the traps scattered through the sections above. The left column is the mistake, the centre is why it misleads, and the right is the corrective move. Read top to bottom, the fixes describe a disciplined lookup workflow that starts authoritative and escalates on purpose.
| The mistake | Why it misleads | The fix |
|---|---|---|
| Treating REDACTED FOR PRIVACY as no data | The registrant is hidden but registrar, dates, nameservers, and status remain | Read the surviving fields, then use a historical tool to recover the prior owner |
| Trusting a stale registrar cache | Some registrar lookups serve a cached record that lags the registry | Confirm a critical field against the authoritative ICANN Lookup record |
| Expecting reverse search from a free tool | Reverse WHOIS sits in the paid research tier, not the free registrar lookups | Use a research suite for reverse and portfolio mapping |
| Reading the creation date as ownership age | A domain can change hands without resetting its creation date | Cross-check the historical record for ownership transfers, not just the creation field |
| Querying WHOIS where only RDAP runs | The legacy WHOIS protocol sunset on 28 January 2025 for ICANN data | Use an RDAP-backed tool, which most modern services already are |
| Scripting bulk runs against a free API cap | Free API tiers cap at a few queries per day and then block | Plan volume around the published rate limit or query RDAP directly |
| Reading WHOIS as a quality signal | WHOIS shows who and when, never backlinks, traffic, or spam history | Pair the lookup with authority-metric and archive tools for a full picture |
Reading a redacted record without exposing your own query trail is its own workflow, set out in Privacy-safe WHOIS lookup workflow. The short version: the surviving fields plus a historical lookup answer the ownership question that redaction looks set to close.
WHOIS lookups when you acquire an aged or expired domain
For a domain buyer, a WHOIS lookup is one input into diligence, not the verdict. The registration record confirms age, registrar, status, and lifecycle stage, and the historical and reverse layers surface a hidden prior owner or a tie to a spam network. A clean registration history is necessary but not sufficient, because WHOIS cannot read the backlink profile that decides real value.
What the record confirms before a purchase
When you evaluate an aged or expired domain to buy, the WHOIS or RDAP record settles the lifecycle facts. The creation date evidences the age you are paying for. The status codes show whether the name is live, pending delete, or redemption. The registrar and nameservers tell you where the domain lives and how a transfer runs. These are the verifiable facts a listing claim is checked against.
Where the screened marketplace fits
The scale of the drop pool is why the WHOIS filter matters. DomCop, an expired-domain data platform that indexes the daily drop feeds, lists hundreds of thousands of expiring and deleted domains at any time, and the registration record is the first cut that thins that pool to names worth a deeper look. Treat that volume as the reason a manual lookup workflow needs a starting filter, not a number to act on blind.
This is the point where the research resolves to a decision. Running historical and reverse WHOIS on every drop, then cross-reading the backlink profile, is the work that separates a clean aged domain from a junk one. SEO Domains does that screening before a name is listed, reading the registration history and the authority metrics together across a 220,000+ catalogue that runs from $100 entry-level aged domains through premium acquisitions, so a buyer starts diligence from vetted inventory instead of an unverified drop. Browse the screened catalogue on the SEO Domains marketplace when the WHOIS research points to a name worth acquiring.
WHOIS lookup services frequently asked questions
The questions domain researchers raise when they compare WHOIS lookup services, answered against the RDAP transition and the redaction reality this guide sets out.
Q1What is the best free WHOIS lookup tool?
For the authoritative current record on a domain, ICANN Lookup at lookup.icann.org is the reference: free, RDAP-backed, and the tiebreaker when other tools disagree. For a fast availability-and-status read tied to a buy flow, a registrar lookup like Whois.com or GoDaddy is fine. Neither offers historical or reverse search, which is the paid tier.
Q2Why does a WHOIS lookup show REDACTED FOR PRIVACY instead of the owner?
Since EU GDPR took effect in 2018, ICANN’s Temporary Specification requires registrars to strip personal registrant data from the public record for domains tied to natural persons. The registrar, dates, nameservers, and status still show. To recover a prior owner the current record hides, a historical WHOIS tool reads the pre-redaction record.
Q3Is WHOIS being replaced by RDAP?
Yes. ICANN set 28 January 2025 as the end of the contractual requirement to run the legacy WHOIS protocol, with the Registration Data Access Protocol (RDAP) as the standard successor. RDAP returns the same registration fields in structured JSON. A tool labelled WHOIS in 2026 is frequently an RDAP client behind a familiar name.
Q4Which WHOIS service offers reverse and historical search?
Reverse WHOIS and historical WHOIS sit in the paid research tier, with DomainTools the named leader. Historical search recovers a prior owner from before the redaction era, and reverse search finds other domains tied to the same registrant fingerprint. The free registry and registrar tools do not provide either.
Q5Can a WHOIS lookup tell me if an aged domain is worth buying?
It answers part of the question. A WHOIS or RDAP lookup confirms the age, registrar, status, and lifecycle stage, and a historical lookup surfaces a hidden prior owner or a network tie. It cannot read the backlink profile or spam history that decide real value, so it is the first filter in diligence, not the verdict. Pair it with authority metrics.
Source domains with screened registration history from SEO Domains
A WHOIS lookup is the first filter on a domain, and the screened marketplace is where that filter is already applied. Reading registration history, ownership transfers, and authority metrics on every drop is the diligence that separates a clean aged or expired domain from a junk one. SEO Domains operates the curated marketplace where that screening happens before a name is priced.
Why screened registration history matters
The work this guide describes, running historical and reverse WHOIS and reading the surviving fields, is exactly the diligence a buyer runs before acquiring an aged or expired domain. A name with a redacted spam owner in its past or a tie to a flagged network is a liability the public record alone will not flag. The screen reads that history so the buyer does not start from an unverified drop list.
The asset is the clean domain, not a lookup service
The demand behind comparing WHOIS lookup services is access to domains whose history checks out. That is the product: a vetted aged or expired domain, not a WHOIS API, not a subscription tool, and not a research service. SEO Domains screens registration history and authority metrics together, so a name that reaches the catalogue has already passed the first filter this guide teaches you to run by hand.
