WHOIS lookup.
Read the registry's record for a domain: registrar, dates, nameservers, and transfer lock. Confirm who controls a client domain and how long remains before renewal.
The registry's record, not a scraped guess.
The lookup queries the registry over RDAP — the structured protocol that replaced legacy WHOIS — so every field comes from the authoritative source, parsed instead of screen-scraped.
registrar
The company the domain is registered through — the account you'd need access to when it's time to renew, transfer, or fix DNS delegation.
expiration date
The registry's expiry date and the exact number of days remaining. We flag anything inside 30 days and fail anything already past.
created & updated
When the domain was first registered and when the record last changed. A recent unexplained update on a domain you own is worth investigating.
nameservers
The nameservers delegated at the registry — the actual root of your DNS. If these point at the wrong provider, no amount of record editing elsewhere matters.
status codes
The EPP status flags on the registration, like clientTransferProhibited (transfer lock) or the redemptionPeriod that means a domain already lapsed.
subdomain handling
Registration data exists per registered domain, so a lookup for app.example.com automatically falls back to example.com to find the record.
How domains actually get lost.
auto-renew that silently died
The card on file expired, the renewal charge bounced, and the warning emails went to an inbox nobody reads. The domain works right up to the expiry date, then everything on it — website, email, API — goes dark at once.
registered under one person's account
The domain lives in the personal registrar account of a founder, an ex-employee, or a former agency. Renewal works until that person stops paying attention, and recovery means tracking them down — or lawyers.
no transfer lock
Without clientTransferProhibited set, a stolen registrar password is enough to move the domain to another registrar. Getting a hijacked domain back can take weeks of dispute process while your email delivers to someone else.
stale nameserver delegation
DNS moved to a new provider but the registry still delegates to the old one — or to both. Records get edited in the new dashboard while resolvers keep answering from the old zone, and the mismatch surfaces as intermittent, maddening failures.
redemption period sticker shock
After expiry most gTLDs go through a ~30-day redemption period. The domain can still be recovered — but at a redemption fee that's often ten times the renewal price. After that, it drops and the auction snipers pick it up.
Domain registration, answered.
The registration record the registry holds for a domain: which registrar it's registered through, when it was created and last updated, when the registration expires, which nameservers it delegates to, and the EPP status codes on the registration — such as transfer locks. It answers “who controls this domain, and is it about to lapse?”
RDAP is the structured, JSON-based replacement for the legacy WHOIS protocol, mandated by ICANN for gTLDs since 2019. It carries the same registration data but in a machine-readable format from the authoritative registry, instead of free-form text that has to be screen-scraped. This tool queries RDAP, so the fields are parsed exactly as the registry publishes them.
DNS stops resolving, which takes down the website, email, and anything else on the domain at once. Most gTLDs then enter a grace period where the original owner can renew at the normal price, followed by a ~30-day redemption period with a much higher recovery fee. After that the domain is deleted and released — usually straight into drop-catching auctions.
Since GDPR took effect in 2018, registries and registrars redact registrant contact details from public records. What remains reliable and public is the registrar, the dates, the nameservers, and the status codes — which is what this lookup reports.
Some registries — mostly country-code TLDs like .de or .au — either don't run an RDAP service or don't publish expiry data in it. The lookup reports what the registry exposes; an unpublished expiry is noted as informational rather than treated as a problem.
They're EPP flags describing what operations the registration allows. clientTransferProhibited is the transfer lock — you want it set. serverHold means the registry has suspended the domain from DNS. redemptionPeriod or pendingDelete means the registration already lapsed and is on its way to being released.
Set auto-renew, keep the payment method current, and still renew manually when a year remains if the domain matters — registrars let you extend up to 10 years out. The failure mode is never “forgot the date”; it's an auto-renewal that broke silently months earlier.
Registration is one part of the client domain.
The free scan checks SSL & domain expiry, email auth & DMARC, look-alikes, and blacklists together from public records. One result, no signup.
Keep checking the same failure point.
Use the related tools one at a time, or run all four posture checks together.