Skip to content

WHOIS

Definition

A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since ICANN's GDPR alignment policy took effect in 2018, much registrant contact data for .com and other gTLDs is redacted by default in public queries.

Field
OSINT, domain and network investigation
Data returned
Registrant, organisation, email, nameservers, registration and expiry dates
Major policy change
ICANN GDPR alignment policy, effective 2018
Effect of that policy
Most registrant contact data redacted by default for gTLDs
Query method
WHOIS protocol lookup or web-based WHOIS tools

Common questions

If WHOIS data is redacted, how do investigators still get registrant information?+

They can request disclosure through the registrar's or registry's formal legal process, use historical WHOIS databases that captured records before 2018, or pursue the information through subpoena or mutual legal assistance in a criminal matter.

Does WHOIS redaction apply equally to all domain extensions?+

No. Redaction driven by GDPR alignment mainly affects gTLDs administered under ICANN policy; some country-code TLDs (ccTLDs) set their own privacy rules independently, so redaction levels vary considerably by extension.

What can historical WHOIS records reveal that a current lookup cannot?+

Historical records, held by third-party archiving services, can show a domain's registrant details, nameserver changes, and ownership transfers from before current privacy redaction took effect, which is often useful for linking a domain to an earlier known identity.

Related terms

A Record
A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
Digital Footprint
The cumulative set of data traces a person or entity leaves across internet-accessible sources, including domain registrations, social media posts, forum accounts,...
DNS Tunnelling
Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
Domain Generation Algorithm (DGA)
Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
Fast-Flux
An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
Metadata
Data about data. In document forensics, metadata includes file-creation timestamps, last-modified dates, author fields, revision history, and embedded GPS coordinates in images....
OSINT
Open-Source Intelligence. Investigation using publicly available sources: social media, satellite imagery, news archives, public databases. In deepfake casework, OSINT corroborates or contradicts...
Passive Collection
OSINT collection that queries third-party databases and archived sources without sending any traffic directly to the target's systems, avoiding any trace on...
Passive DNS
A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a...
Sock Puppet
A fictitious online identity created and controlled by an investigator to observe or interact with a target without revealing the investigation. The...

Explained in these topics

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.