WHOIS is a query-response protocol used to look up registration information for domain names, IP addresses, and autonomous systems. When someone registers a domain, their contact information, registration dates, and technical details are stored in a publicly accessible WHOIS database maintained by domain registrars and regional internet registries.
A WHOIS record typically contains: the registrant's name and organisation (though privacy protection often redacts this), the registrar through which the domain was registered, the creation date (when the domain was first registered), the expiry date (when the registration lapses), the nameservers controlling the domain's DNS, and the domain status codes indicating whether it can be transferred, deleted, or modified.
WHOIS data is valuable for due diligence when purchasing a domain, identifying domain ownership for business or legal purposes, security research to trace phishing or malicious domains, checking domain age for SEO evaluation, and finding contact information to report abuse or discuss domain acquisition.
Since GDPR came into effect in 2018, many registrars now redact personal information from public WHOIS records, replacing registrant details with "REDACTED FOR PRIVACY" or proxy contact details. Full WHOIS data may still be accessible through legal channels or accredited registrar requests for legitimate purposes.