Section 02 · WHOIS
Reading a WHOIS record without jumping to conclusions
WHOIS is the word everyone uses, and the one search engines still expect, even though the protocol behind it has been replaced for generic domains. Since January 2025, RDAP has been the definitive source of gTLD registration data, but the record you read looks familiar: domain name, registrar, creation and expiry dates, status codes, name servers and a registrar abuse contact.
This section is about reading that record well. We explain what codes like clientTransferProhibited and serverHold mean, why a creation date can be the most useful field on the page, and why a redacted registrant isn't a warning sign by itself.
We also cover the limits. A public lookup won't reveal the person behind a privately registered domain, and it isn't meant to. If you need to report abuse or request nonpublic data, there are proper channels, and we'll point to them rather than to shortcuts. Coming up: how to get started with WHOIS lookups, and the beginner misreadings we see most often.
Articles in WHOIS
Nothing filed under WHOIS yet. Until the first piece lands, the headlines below track related reporting, and our guide to verifying a privately registered website shows how to read a record in practice.
Abuse and takedown reporting from Krebs on Security
- Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters InvestigationKrebs on Security
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon ExtortionsKrebs on Security
- Data Broker Radaris Loses Domains in Privacy FightKrebs on Security
- Microsoft Plugs Nearly 1,000 Security HolesKrebs on Security
- FBI Probes Service Selling 153M+ Drivers LicensesKrebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in AustraliaKrebs on Security
Related sections: RDDS · Domain Privacy · All articles in Behind The Domain