Home › Guides › Domain WHOIS / RDAP lookup
Domain WHOIS and RDAP lookup: registrar, domain age and registrant data as clean rows
A counterparty whose domain was registered three weeks ago is a different risk from one registered in 2004. The Domain WHOIS/RDAP Lookup reads RDAP — the structured JSON replacement for WHOIS — so you get real dates and status codes instead of scraped free text: registrar and IANA ID, creation, expiry and last-changed dates, domain age, EPP status codes, nameservers and DNSSEC, plus the registrant organization and country wherever the registry or registrar still discloses them.
Who it's for
- Fraud and risk screening — vendor and merchant onboarding by domain age;
domainAgeDaysis the field most risk rules key on. - Lead qualification — a registrar like MarkMonitor or CSC points to a corporate legal team; a low-cost reseller points to a small business.
- Portfolio monitoring — expiry dates across a domain portfolio, in one table.
Why RDAP instead of WHOIS
RDAP is the IETF-standard registration data protocol that every gTLD registry is required to serve. The lookup finds the authoritative server for each domain ending in IANA's RDAP directory — plus the few registries missing from it — and queries it directly, with no key. When the registry names no registrant (.com and .net never do), it follows the registry's link to the registrar's own RDAP server, where the registrant lives: one more request per domain.
What you get
| Data | Field and meaning |
|---|---|
| Domain | domain — the registrable domain that was looked up |
| Registrar | registrar — the sponsoring registrar; registrarIanaId — its IANA ID |
| Dates | incorporatedOn (creation), expiresOn (registration expiry) and lastChangedOn (last update to the registration) |
| Domain age | domainAgeDays — days since registration |
| Status | status — active, or inactive when the domain is on hold or pending delete; eppStatusCodes — the raw EPP status codes |
| DNS | nameservers; nameserverProvider — their second-level domain, usually the DNS or hosting vendor; dnssec — whether DNSSEC is signed |
| Registrant | registrantOrganization where disclosed — never a privacy service or a redaction placeholder; otherwise companyName is the domain |
| Location | registrantCountry and countryName, plus the address where disclosed |
| Contact | email and phone — the registrant's when its identity is disclosed, otherwise what the domain's own website publishes; emailSource and phoneSource say where each came from |
| Website | website — the site the domain actually serves, checked live with redirects followed |
| Privacy | privacyService — the privacy or proxy service registered in the owner's place; isRedacted — whether the registrant's identity is withheld |
| Provenance | sourceUrl (the RDAP record that was read), query, scrapedAt and, when a lookup fails, error with the reason |
A real row for shopify.ca, one of the registries that still publishes the registrant in full, trimmed:
{
"domain": "shopify.ca",
"registrantOrganization": "Shopify Inc.",
"registrar": "MarkMonitor International Canada Ltd.",
"incorporatedOn": "2006-02-20",
"expiresOn": "2028-02-20",
"lastChangedOn": "2026-01-19",
"domainAgeDays": 7521,
"status": "active",
"eppStatusCodes": [
"client delete prohibited",
"client transfer prohibited",
"client update prohibited"
],
"nameserverProvider": "foundationdns.com",
"dnssec": false,
"registrantCountry": "CA",
"website": "https://www.shopify.com",
"privacyService": null,
"isRedacted": false,
"sourceUrl": "https://rdap.ca.fury.ca/rdap/domain/shopify.ca"
}
Fields such as tax number, legal form, industry, employees, capital and officers belong to the company schema shared across this series of scrapers; they are not part of RDAP and stay null here.
Redaction: what is never passed off as data
Since GDPR, most registries and registrars redact the registrant's name and address. isRedacted tells you when that has happened — redacted, hidden behind a privacy service, or not published by the registry — so a companyName that is just the domain is explained rather than mysterious. Only disclosed values are returned: redaction placeholders, privacy-service details and email relays are never passed off as the owner's. For a .com behind a privacy service the row reads, for example, companyName “notion.com”, privacyService “c/o whoisproxy.com” and isRedacted true. The registrant country usually survives: most registrars keep it even when the rest is redacted.
Contacts from the domain's own website
When the registrant's contact is withheld — which, since GDPR, is most domains — email and phone come from the domain's own website, and only from what the site states explicitly:
mailto:andtel:links (Cloudflare-protected addresses included) and schema.org JSON-LD, on the homepage or the contact page it links. Nothing is guessed out of running text.- An email must be on the domain itself — a web agency's or a provider's address never qualifies — and role mailboxes such as info@, contact@ and sales@ are preferred over a person's.
- Template placeholders are dropped, and
emailSource/phoneSourcesay where each value came from.
Measured on 30 randomly drawn small-company domains: 22 homepages answered, 13 gave an email and 12 a phone, and a manual check found all 25 values to be the company's own published contact. The website field also catches rebrands: angel.co resolves to https://wellfound.com and vercel.app to https://vercel.com.
Input example
{
"queries": [
"stripe.com",
"shopify.com",
"https://www.notion.com/pricing"
],
"maxResultsPerQuery": 1,
"maxConcurrency": 5,
"includeRaw": false
}
Queries can be domain names or URLs; subdomains are reduced to the registrable domain. Five queries run at a time by default. Each domain takes one RDAP request, one more to the registrar for .com and .net, one to its website, and one to its contact page when the homepage lacks an email or phone. includeRaw attaches the untouched RDAP record under raw.
Coverage and honest limits
- Registries missing from IANA's directory —
.io,.me,.co,.us,.de,.chand.sorun RDAP anyway and are queried directly;.deand.chpublish little beyond status and nameservers. - No usable RDAP server — among others
.se,.jp,.es,.it,.euand.cn. Such a query returns a free row that says so. - Registrar servers can fail on some endings (Tucows on
.app); such rows keep the registry fields andisRedactedisnull. - Redaction is the norm since GDPR, so registrant organization and address are often empty. The lookup never attempts to unmask redacted data.
- Rate limits — RDAP servers answer datacenter IPs, though some registries rate-limit by IP; lower
maxConcurrencyif a source starts throttling.
Pricing
You pay only for the rows a run delivers. Failed or empty lookups are never charged. Current prices are on the actor's Pricing tab.
Related
More company-data scrapers on foXLabs. Domain age is one input to business verification — see KYB company verification for the register side — and why a verified domain anchors company data is covered in firmographics and competitive intelligence.
Frequently asked questions
What is the difference between RDAP and WHOIS?
RDAP is the structured JSON replacement for WHOIS and the IETF-standard registration data protocol that every gTLD registry is required to serve. You get real dates and status codes instead of scraped free text.
Do I need an API key or a login?
No. Registries and registrars answer RDAP without a key.
What can I search by?
By domain name or any URL containing one. stripe.com, https://www.stripe.com/pricing and WWW.STRIPE.COM all resolve to the same lookup, and subdomains are reduced to the registrable domain.
Why is the registrant empty for most domains?
Since GDPR, most registries and registrars redact the registrant's name and address. isRedacted tells you when that has happened, and the registrant country is often still published. The lookup returns only what the registry or registrar discloses and never attempts to unmask redacted data.
Which domain endings are not covered?
Endings with no RDAP server the lookup can use, among them .se, .jp, .es, .it, .eu and .cn. Such a query returns a free row that says so. .io, .me, .co, .us, .de, .ch and .so are missing from IANA's RDAP directory but are queried directly.
Try it: paste a list of domains or URLs into the input above and get registrar, age, status and registrant data in one table.
Open the Domain WHOIS/RDAP Lookup →Or browse all foXLabs datasets on Apify.