WHOIS
Definition
A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since ICANN's GDPR alignment policy took effect in 2018, much registrant contact data for .com and other gTLDs is redacted by default in public queries.
- Field
- OSINT, domain and network investigation
- Data returned
- Registrant, organisation, email, nameservers, registration and expiry dates
- Major policy change
- ICANN GDPR alignment policy, effective 2018
- Effect of that policy
- Most registrant contact data redacted by default for gTLDs
- Query method
- WHOIS protocol lookup or web-based WHOIS tools
Common questions
If WHOIS data is redacted, how do investigators still get registrant information?+
They can request disclosure through the registrar's or registry's formal legal process, use historical WHOIS databases that captured records before 2018, or pursue the information through subpoena or mutual legal assistance in a criminal matter.
Does WHOIS redaction apply equally to all domain extensions?+
No. Redaction driven by GDPR alignment mainly affects gTLDs administered under ICANN policy; some country-code TLDs (ccTLDs) set their own privacy rules independently, so redaction levels vary considerably by extension.
What can historical WHOIS records reveal that a current lookup cannot?+
Historical records, held by third-party archiving services, can show a domain's registrant details, nameserver changes, and ownership transfers from before current privacy redaction took effect, which is often useful for linking a domain to an earlier known identity.
Related terms
- A Record
- A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
- Digital Footprint
- The cumulative set of data traces a person or entity leaves across internet-accessible sources, including domain registrations, social media posts, forum accounts,...
- DNS Tunnelling
- Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
- Domain Generation Algorithm (DGA)
- Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
- Fast-Flux
- An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
- Metadata
- Data about data. In document forensics, metadata includes file-creation timestamps, last-modified dates, author fields, revision history, and embedded GPS coordinates in images....
- OSINT
- Open-Source Intelligence. Investigation using publicly available sources: social media, satellite imagery, news archives, public databases. In deepfake casework, OSINT corroborates or contradicts...
- Passive Collection
- OSINT collection that queries third-party databases and archived sources without sending any traffic directly to the target's systems, avoiding any trace on...
- Passive DNS
- A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a...
- Sock Puppet
- A fictitious online identity created and controlled by an investigator to observe or interact with a target without revealing the investigation. The...
Explained in these topics
- DNS and Domain Investigation
- Web OSINT and Digital Footprint AnalysisA public query protocol that returns registration data for a domain name or IP address block, including registrant name, contact address, registrar, and regist...