RDAP Lookup
Query modern RDAP registration data for a domain and inspect registrar, dates, status and entities.
RDAP Lookup lets you query modern Registration Data Access Protocol (RDAP) information for a domain. Enter a domain name to inspect the registration details made available through RDAP, including the associated registrar, important registration dates, domain status values and listed entities.
This tool is useful for domain owners, IT teams, security and abuse analysts, researchers and anyone investigating domain registration information. It can help you understand which registrar is associated with a domain, review dates such as creation, update or expiry dates when provided, and identify status codes that describe the domain’s current registration state.
- Registrar: the registrar identified in the RDAP response.
- Dates: registration-related timestamps returned for the domain, such as creation, update or expiration information.
- Status: codes that indicate conditions or restrictions applied to the domain.
- Entities: organizations or contacts referenced by the response, such as registrar or registrant-related records when available.
RDAP results depend on the registry and registrar data available for the domain, so fields may differ between domains. Use the findings as a current registration-data reference rather than assuming every record contains the same level of detail. For broader domain investigation, explore the other domain intelligence tools. If you need legacy registration-data context, compare the results with a WHOIS lookup; for DNS records and configuration details, use a DNS lookup.
How to interpret the result
Treat each lookup as a point-in-time observation. DNS can change, registration data can be redacted, CDNs can obscure origin infrastructure, and third-party intelligence providers can have coverage limits.
Understanding RDAP Lookup
RDAP, or the Registration Data Access Protocol, is the modern web-based protocol used to query domain registration data. It provides structured information about a domain name, including the registrar, registration and expiration events, domain status codes, nameservers, and the entities associated with the registration record.
The WHOISDR RDAP Lookup tool helps you inspect this information for a domain without manually locating an RDAP server or reading an unfamiliar JSON response. Enter a domain such as example.com, and the tool queries available RDAP registration data so you can review the returned record in a more accessible format.
RDAP is related to the older WHOIS system, but it is not simply a different display for the same protocol. RDAP uses HTTP and structured JSON responses, supports standardized objects and relationships, and can provide clearer references to registrars, registries, entities, and events. The data available still depends on the domain extension, the relevant registry or registrar, and privacy or data-protection policies.
What RDAP Data Contains
An RDAP response is made up of structured objects. The exact fields vary between registries and registrars, but a domain record commonly includes the following categories.
- Domain name: The domain queried and, in some cases, related identifiers or internationalized domain name information.
- Registrar: The registrar responsible for the domain registration, when the registry publishes that relationship.
- Events: Important dates such as registration, last update, and expiration. Some records may also include transfer, deletion, or other lifecycle events.
- Status codes: EPP status values describing restrictions or operational conditions, such as transfer locks, pending operations, suspension, or redemption states.
- Entities: Organizations or people associated with the record, such as a registrar, registrant, administrative contact, or technical contact.
- Nameservers: Authoritative nameservers delegated to the domain, where the registry includes them in the response.
- Links and references: URLs or relationships that identify the source of an object or point to related RDAP resources.
Not every field is present for every domain. A generic top-level domain and a country-code domain may follow different publication rules. A registrar may also redact personal information or provide only an abuse contact. The absence of a field does not necessarily mean that the underlying information does not exist.
How the RDAP Lookup Tool Works
- Submit a domain: Provide a domain name, normally without a protocol such as
https://and without a page path. For example, useexample.comrather thanhttps://example.com/about. - Identify the appropriate RDAP service: RDAP queries must be directed to a service that handles the relevant top-level domain. The lookup process uses the domain extension to locate the applicable registration data service.
- Retrieve the registration response: The service returns structured RDAP data when a record is available and the service is reachable. Responses can contain domain objects, entity objects, event information, statuses, and related links.
- Present the result: The tool displays the useful registration details so you can inspect the record without needing to parse raw JSON manually.
RDAP is a registration-data protocol, not a complete investigation of a website. It does not by itself confirm that a domain is safe, that its owner is trustworthy, that its website is operational, or that its DNS configuration is correct. Use the result as one source of domain intelligence and combine it with other checks when the question requires more context.
How to Read the Results
Registrar and registry information
The registrar is the service through which the domain was registered or is currently managed. It may be different from the company that operates the top-level domain registry. For example, a registry maintains the central database for an extension, while a registrar provides registration services to customers.
Registrar information is useful when you need to identify where a domain is managed, determine where an abuse or support report may belong, or understand whether two domains are associated with the same registrar. A shared registrar is not proof that domains have the same owner or operator.
Registration and expiration events
Look for event labels such as registration, last changed, and expiration. A registration date can indicate when the current domain record was created, but it may not reveal the age of a brand, website, or business. Domains can be transferred, allowed to expire, deleted, and registered again.
The expiration date is also not always a definitive shutdown date. Registrars and registries may provide renewal periods, grace periods, redemption periods, or other lifecycle stages. An expired domain can remain in service temporarily, and a domain that has not yet reached its listed expiration date can still be suspended or placed under another restriction.
Compare dates carefully. A recent update may reflect a change to nameservers, registrar information, contact details, or another record field rather than a new registration. RDAP events describe registration-record activity; they do not necessarily describe when a website was launched or when its content changed.
Status codes
Status values are often among the most informative parts of an RDAP response. Common EPP-style statuses include:
clientTransferProhibited: A registrar-level transfer restriction is applied.serverTransferProhibited: A registry-level transfer restriction is applied.clientUpdateProhibitedorserverUpdateProhibited: Updates are restricted at the registrar or registry level.clientDeleteProhibitedorserverDeleteProhibited: Deletion is restricted at the registrar or registry level.pendingTransfer: A transfer request is in progress or awaiting completion.redemptionPeriod: The domain may be in a recovery period after expiration or deletion, subject to the registry’s rules.pendingDelete: The domain may be scheduled for deletion after a defined lifecycle stage.
Status interpretation depends on the extension and the domain’s current lifecycle. A transfer lock is a normal defensive setting for many domains and is not, by itself, evidence of malicious activity. Conversely, a status that looks ordinary does not establish that a website is legitimate. Read statuses together with dates, registrar information, DNS data, and the context of your investigation.
Entities and redacted contact data
RDAP can identify entities associated with a domain, including registrar, registrant, administrative, and technical roles. Public responses may show an organization name, a role, an abuse mailbox, or a privacy-service label instead of a person’s name, address, telephone number, or email address.
Redaction is common and can result from privacy services, registry policy, registrar policy, or data-protection requirements. A redacted record should not be interpreted as proof that the domain is suspicious. It simply means the public response does not expose certain contact details. If you need to report abuse or resolve a registration issue, use the published registrar or registry contact process rather than attempting to infer private information.
Nameservers and related objects
When nameservers are included, they show which DNS hosts are delegated for the domain at the registry level. This can help you compare a registration record with the domain’s current DNS behavior. However, nameservers in RDAP are not the same as every DNS record published by the domain, and they do not reveal the complete zone configuration.
For a detailed view of DNS records, delegation, mail exchange, text records, or authoritative responses, use the DNS Lookup tool. RDAP and DNS answer different questions and should not be treated as interchangeable.
Practical Uses for RDAP Lookup
Checking a domain before registration or acquisition
RDAP can help determine whether a domain appears to have an existing registration record, which registrar manages it, and what lifecycle dates or statuses are visible. This is useful during domain acquisition research, but it is not a substitute for checking the registrar’s current availability and purchase process. A domain may be registered but listed for sale, reserved, premium-priced, or subject to a transfer restriction.
For a direct availability-oriented check, use the Domain Availability tool when available. RDAP is better suited to inspecting an existing registration record than to establishing whether a domain can be registered at a particular price.
Investigating suspicious or unexpected domains
When a domain appears in an email, redirect, invoice, or security alert, RDAP can provide useful context. Review its registration and update dates, registrar, statuses, entities, and nameservers. A newly registered domain or a recent record change may be relevant to an investigation, but neither fact alone proves abuse.
Use RDAP alongside website and infrastructure checks. The Domain Intelligence tools can help place registration data in a wider context, while a SSL Checker can be used to inspect certificate details and a DNS lookup can show current resolution data.
Supporting domain portfolio reviews
Organizations can use RDAP to review domains associated with known registrars, renewal dates, statuses, and published entities. This can help identify records that need verification, domains approaching expiration, or unexpected changes to registration information.
Do not rely on a single public field as the definitive inventory key. Domains may use different registrars, privacy services, legal entities, or contact arrangements. Compare RDAP results with internal ownership records and registrar accounts.
Verifying registration claims
If a person or organization claims to control a domain, the RDAP record can provide supporting or conflicting information about the listed registrar, entities, and dates. It cannot prove that the listed entity controls the website, controls the hosting account, or currently operates the content. Domain control should be verified through an appropriate administrative or technical challenge when the stakes are high.
Common Mistakes to Avoid
- Including a full URL: Query the domain name rather than a URL with a protocol, path, query string, or fragment.
- Assuming a blank field is an error: Missing contact data may be intentional redaction or a registry policy choice.
- Treating expiration as immediate deletion: Expiration can be followed by grace, recovery, or other registry-defined stages.
- Confusing registrar and registrant: The registrar manages the registration service; the registrant is the associated holder or organization when disclosed.
- Reading status codes in isolation: A transfer lock or update restriction is not automatically suspicious.
- Assuming registration age equals website age: A domain can change owners, be re-registered, or remain unused for long periods.
- Using RDAP as a security verdict: Registration data is context, not a malware scan, reputation score, or ownership guarantee.
- Ignoring the top-level domain: Country-code and generic top-level domains may expose different fields and follow different processes.
Troubleshooting an RDAP Lookup
If no result is returned, first check the spelling and extension. Remove https://, www., paths, and punctuation that is not part of the domain name. Internationalized domain names may need to be represented using their correct Unicode form or an ASCII-compatible encoding.
A failed lookup does not always mean that the domain is unregistered. The RDAP service for the extension may be temporarily unavailable, may not publish a complete response, or may require a different query path. Newly registered, recently transferred, expired, or recently deleted domains can also produce changing results while registry systems update.
If the response loads but contains limited information, review the available registrar, registry, event, status, and entity sections before concluding that data is missing. Some services return a valid domain record while redacting most contact details. If you need additional confirmation, compare the result with the registrar’s own domain management or lookup service and repeat the check later.
Accuracy, Scope, and Limitations
RDAP results reflect the response available from the relevant registration-data service at the time of the query. Records can change after transfers, renewals, updates, deletions, policy changes, or registry synchronization. WHOISDR presents the returned registration information, but it cannot make an unavailable or redacted field public.
Different extensions implement RDAP with different policies and levels of detail. Some provide registrar referrals, while others expose only registry-level information. Date formats and event labels may vary, and a record may contain links to additional objects that are not visible in every response.
RDAP also has a narrow scope. It does not establish website ownership, hosting location, content authenticity, user intent, domain safety, or the complete history of a domain. It does not replace legal records, registrar account evidence, DNS analysis, certificate inspection, or a security investigation. Treat results as time-sensitive technical information and preserve the query time if the result is being used in an incident record.
Privacy and Security Considerations
Public RDAP data may include business contact information, role-based email addresses, registrar abuse contacts, and other operational details. Handle this information responsibly and follow applicable privacy, acceptable-use, and data-protection requirements. Do not use exposed contact data for unsolicited messages, harassment, credential attacks, or attempts to bypass legitimate privacy controls.
Registration data can support defensive work such as abuse reporting, domain portfolio management, and incident triage. It should be combined with evidence from email headers, DNS records, website behavior, certificates, and server logs before making a high-impact decision. A domain that uses privacy protection is not automatically unsafe, and a domain with visible organization data is not automatically trustworthy.
When to Use Related WHOISDR Tools
Use RDAP Lookup when your primary question concerns domain registration data, registrar relationships, lifecycle events, statuses, or published entities. Choose related tools when you need a different layer of information:
- Use WHOIS Lookup when you need to compare legacy WHOIS output with modern RDAP data or investigate a service that still exposes information through WHOIS.
- Use DNS Lookup to inspect current DNS records, delegation, mail routing, and other answers returned by authoritative DNS servers.
- Use SSL Checker to review certificates, certificate names, validity periods, and TLS-related details.
- Use Domain Availability when the goal is to assess whether a domain may be available for registration rather than to inspect an existing record.
- Use broader Domain Intelligence tools when you need to combine registration, DNS, certificate, and website observations.
Used appropriately, RDAP Lookup provides a clear starting point for understanding a domain’s public registration record. The most reliable conclusions come from interpreting its registrar, events, statuses, entities, and nameservers together, checking the timestamp and source context, and validating important findings with the relevant WHOISDR tools.
Frequently asked questions
What is RDAP Lookup used for?
What information can RDAP Lookup show?
Is RDAP Lookup the same as a WHOIS lookup?
Can RDAP Lookup confirm whether a domain is available?
Why are registrant details missing or redacted?
What do domain status codes in the results mean?
Why might registration and expiration dates differ between sources?
What should I do if RDAP Lookup returns an error or incomplete result?
Current-state checks
Free tools focus on live public data and diagnostic signals available at the time of the request.
Actionable follow-ups
Use related DNS, registration, network and web tools to verify a finding rather than relying on one signal in isolation.
Pro investigation workflow
Save evidence snapshots, export CSV, run bulk lookups and combine current data with historical intelligence.