RDAP Lookup

Query modern RDAP registration data for a domain and inspect registrar, dates, status and entities.

RDAP Lookup lets you query modern Registration Data Access Protocol (RDAP) information for a domain. Enter a domain name to inspect the registration details made available through RDAP, including the associated registrar, important registration dates, domain status values and listed entities.

This tool is useful for domain owners, IT teams, security and abuse analysts, researchers and anyone investigating domain registration information. It can help you understand which registrar is associated with a domain, review dates such as creation, update or expiry dates when provided, and identify status codes that describe the domain’s current registration state.

  • Registrar: the registrar identified in the RDAP response.
  • Dates: registration-related timestamps returned for the domain, such as creation, update or expiration information.
  • Status: codes that indicate conditions or restrictions applied to the domain.
  • Entities: organizations or contacts referenced by the response, such as registrar or registrant-related records when available.

RDAP results depend on the registry and registrar data available for the domain, so fields may differ between domains. Use the findings as a current registration-data reference rather than assuming every record contains the same level of detail. For broader domain investigation, explore the other domain intelligence tools. If you need legacy registration-data context, compare the results with a WHOIS lookup; for DNS records and configuration details, use a DNS lookup.

Enter a domain or hostname without a path unless the tool specifically requests a URL.

How to interpret the result

Treat each lookup as a point-in-time observation. DNS can change, registration data can be redacted, CDNs can obscure origin infrastructure, and third-party intelligence providers can have coverage limits.

Understanding RDAP Lookup

RDAP, or the Registration Data Access Protocol, is the modern web-based protocol used to query domain registration data. It provides structured information about a domain name, including the registrar, registration and expiration events, domain status codes, nameservers, and the entities associated with the registration record.

The WHOISDR RDAP Lookup tool helps you inspect this information for a domain without manually locating an RDAP server or reading an unfamiliar JSON response. Enter a domain such as example.com, and the tool queries available RDAP registration data so you can review the returned record in a more accessible format.

RDAP is related to the older WHOIS system, but it is not simply a different display for the same protocol. RDAP uses HTTP and structured JSON responses, supports standardized objects and relationships, and can provide clearer references to registrars, registries, entities, and events. The data available still depends on the domain extension, the relevant registry or registrar, and privacy or data-protection policies.

What RDAP Data Contains

An RDAP response is made up of structured objects. The exact fields vary between registries and registrars, but a domain record commonly includes the following categories.

  • Domain name: The domain queried and, in some cases, related identifiers or internationalized domain name information.
  • Registrar: The registrar responsible for the domain registration, when the registry publishes that relationship.
  • Events: Important dates such as registration, last update, and expiration. Some records may also include transfer, deletion, or other lifecycle events.
  • Status codes: EPP status values describing restrictions or operational conditions, such as transfer locks, pending operations, suspension, or redemption states.
  • Entities: Organizations or people associated with the record, such as a registrar, registrant, administrative contact, or technical contact.
  • Nameservers: Authoritative nameservers delegated to the domain, where the registry includes them in the response.
  • Links and references: URLs or relationships that identify the source of an object or point to related RDAP resources.

Not every field is present for every domain. A generic top-level domain and a country-code domain may follow different publication rules. A registrar may also redact personal information or provide only an abuse contact. The absence of a field does not necessarily mean that the underlying information does not exist.

How the RDAP Lookup Tool Works

  1. Submit a domain: Provide a domain name, normally without a protocol such as https:// and without a page path. For example, use example.com rather than https://example.com/about.
  2. Identify the appropriate RDAP service: RDAP queries must be directed to a service that handles the relevant top-level domain. The lookup process uses the domain extension to locate the applicable registration data service.
  3. Retrieve the registration response: The service returns structured RDAP data when a record is available and the service is reachable. Responses can contain domain objects, entity objects, event information, statuses, and related links.
  4. Present the result: The tool displays the useful registration details so you can inspect the record without needing to parse raw JSON manually.

RDAP is a registration-data protocol, not a complete investigation of a website. It does not by itself confirm that a domain is safe, that its owner is trustworthy, that its website is operational, or that its DNS configuration is correct. Use the result as one source of domain intelligence and combine it with other checks when the question requires more context.

How to Read the Results

Registrar and registry information

The registrar is the service through which the domain was registered or is currently managed. It may be different from the company that operates the top-level domain registry. For example, a registry maintains the central database for an extension, while a registrar provides registration services to customers.

Registrar information is useful when you need to identify where a domain is managed, determine where an abuse or support report may belong, or understand whether two domains are associated with the same registrar. A shared registrar is not proof that domains have the same owner or operator.

Registration and expiration events

Look for event labels such as registration, last changed, and expiration. A registration date can indicate when the current domain record was created, but it may not reveal the age of a brand, website, or business. Domains can be transferred, allowed to expire, deleted, and registered again.

The expiration date is also not always a definitive shutdown date. Registrars and registries may provide renewal periods, grace periods, redemption periods, or other lifecycle stages. An expired domain can remain in service temporarily, and a domain that has not yet reached its listed expiration date can still be suspended or placed under another restriction.

Compare dates carefully. A recent update may reflect a change to nameservers, registrar information, contact details, or another record field rather than a new registration. RDAP events describe registration-record activity; they do not necessarily describe when a website was launched or when its content changed.

Status codes

Status values are often among the most informative parts of an RDAP response. Common EPP-style statuses include:

  • clientTransferProhibited: A registrar-level transfer restriction is applied.
  • serverTransferProhibited: A registry-level transfer restriction is applied.
  • clientUpdateProhibited or serverUpdateProhibited: Updates are restricted at the registrar or registry level.
  • clientDeleteProhibited or serverDeleteProhibited: Deletion is restricted at the registrar or registry level.
  • pendingTransfer: A transfer request is in progress or awaiting completion.
  • redemptionPeriod: The domain may be in a recovery period after expiration or deletion, subject to the registry’s rules.
  • pendingDelete: The domain may be scheduled for deletion after a defined lifecycle stage.

Status interpretation depends on the extension and the domain’s current lifecycle. A transfer lock is a normal defensive setting for many domains and is not, by itself, evidence of malicious activity. Conversely, a status that looks ordinary does not establish that a website is legitimate. Read statuses together with dates, registrar information, DNS data, and the context of your investigation.

Entities and redacted contact data

RDAP can identify entities associated with a domain, including registrar, registrant, administrative, and technical roles. Public responses may show an organization name, a role, an abuse mailbox, or a privacy-service label instead of a person’s name, address, telephone number, or email address.

Redaction is common and can result from privacy services, registry policy, registrar policy, or data-protection requirements. A redacted record should not be interpreted as proof that the domain is suspicious. It simply means the public response does not expose certain contact details. If you need to report abuse or resolve a registration issue, use the published registrar or registry contact process rather than attempting to infer private information.

Nameservers and related objects

When nameservers are included, they show which DNS hosts are delegated for the domain at the registry level. This can help you compare a registration record with the domain’s current DNS behavior. However, nameservers in RDAP are not the same as every DNS record published by the domain, and they do not reveal the complete zone configuration.

For a detailed view of DNS records, delegation, mail exchange, text records, or authoritative responses, use the DNS Lookup tool. RDAP and DNS answer different questions and should not be treated as interchangeable.

Practical Uses for RDAP Lookup

Checking a domain before registration or acquisition

RDAP can help determine whether a domain appears to have an existing registration record, which registrar manages it, and what lifecycle dates or statuses are visible. This is useful during domain acquisition research, but it is not a substitute for checking the registrar’s current availability and purchase process. A domain may be registered but listed for sale, reserved, premium-priced, or subject to a transfer restriction.

For a direct availability-oriented check, use the Domain Availability tool when available. RDAP is better suited to inspecting an existing registration record than to establishing whether a domain can be registered at a particular price.

Investigating suspicious or unexpected domains

When a domain appears in an email, redirect, invoice, or security alert, RDAP can provide useful context. Review its registration and update dates, registrar, statuses, entities, and nameservers. A newly registered domain or a recent record change may be relevant to an investigation, but neither fact alone proves abuse.

Use RDAP alongside website and infrastructure checks. The Domain Intelligence tools can help place registration data in a wider context, while a SSL Checker can be used to inspect certificate details and a DNS lookup can show current resolution data.

Supporting domain portfolio reviews

Organizations can use RDAP to review domains associated with known registrars, renewal dates, statuses, and published entities. This can help identify records that need verification, domains approaching expiration, or unexpected changes to registration information.

Do not rely on a single public field as the definitive inventory key. Domains may use different registrars, privacy services, legal entities, or contact arrangements. Compare RDAP results with internal ownership records and registrar accounts.

Verifying registration claims

If a person or organization claims to control a domain, the RDAP record can provide supporting or conflicting information about the listed registrar, entities, and dates. It cannot prove that the listed entity controls the website, controls the hosting account, or currently operates the content. Domain control should be verified through an appropriate administrative or technical challenge when the stakes are high.

Common Mistakes to Avoid

  • Including a full URL: Query the domain name rather than a URL with a protocol, path, query string, or fragment.
  • Assuming a blank field is an error: Missing contact data may be intentional redaction or a registry policy choice.
  • Treating expiration as immediate deletion: Expiration can be followed by grace, recovery, or other registry-defined stages.
  • Confusing registrar and registrant: The registrar manages the registration service; the registrant is the associated holder or organization when disclosed.
  • Reading status codes in isolation: A transfer lock or update restriction is not automatically suspicious.
  • Assuming registration age equals website age: A domain can change owners, be re-registered, or remain unused for long periods.
  • Using RDAP as a security verdict: Registration data is context, not a malware scan, reputation score, or ownership guarantee.
  • Ignoring the top-level domain: Country-code and generic top-level domains may expose different fields and follow different processes.

Troubleshooting an RDAP Lookup

If no result is returned, first check the spelling and extension. Remove https://, www., paths, and punctuation that is not part of the domain name. Internationalized domain names may need to be represented using their correct Unicode form or an ASCII-compatible encoding.

A failed lookup does not always mean that the domain is unregistered. The RDAP service for the extension may be temporarily unavailable, may not publish a complete response, or may require a different query path. Newly registered, recently transferred, expired, or recently deleted domains can also produce changing results while registry systems update.

If the response loads but contains limited information, review the available registrar, registry, event, status, and entity sections before concluding that data is missing. Some services return a valid domain record while redacting most contact details. If you need additional confirmation, compare the result with the registrar’s own domain management or lookup service and repeat the check later.

Accuracy, Scope, and Limitations

RDAP results reflect the response available from the relevant registration-data service at the time of the query. Records can change after transfers, renewals, updates, deletions, policy changes, or registry synchronization. WHOISDR presents the returned registration information, but it cannot make an unavailable or redacted field public.

Different extensions implement RDAP with different policies and levels of detail. Some provide registrar referrals, while others expose only registry-level information. Date formats and event labels may vary, and a record may contain links to additional objects that are not visible in every response.

RDAP also has a narrow scope. It does not establish website ownership, hosting location, content authenticity, user intent, domain safety, or the complete history of a domain. It does not replace legal records, registrar account evidence, DNS analysis, certificate inspection, or a security investigation. Treat results as time-sensitive technical information and preserve the query time if the result is being used in an incident record.

Privacy and Security Considerations

Public RDAP data may include business contact information, role-based email addresses, registrar abuse contacts, and other operational details. Handle this information responsibly and follow applicable privacy, acceptable-use, and data-protection requirements. Do not use exposed contact data for unsolicited messages, harassment, credential attacks, or attempts to bypass legitimate privacy controls.

Registration data can support defensive work such as abuse reporting, domain portfolio management, and incident triage. It should be combined with evidence from email headers, DNS records, website behavior, certificates, and server logs before making a high-impact decision. A domain that uses privacy protection is not automatically unsafe, and a domain with visible organization data is not automatically trustworthy.

When to Use Related WHOISDR Tools

Use RDAP Lookup when your primary question concerns domain registration data, registrar relationships, lifecycle events, statuses, or published entities. Choose related tools when you need a different layer of information:

  • Use WHOIS Lookup when you need to compare legacy WHOIS output with modern RDAP data or investigate a service that still exposes information through WHOIS.
  • Use DNS Lookup to inspect current DNS records, delegation, mail routing, and other answers returned by authoritative DNS servers.
  • Use SSL Checker to review certificates, certificate names, validity periods, and TLS-related details.
  • Use Domain Availability when the goal is to assess whether a domain may be available for registration rather than to inspect an existing record.
  • Use broader Domain Intelligence tools when you need to combine registration, DNS, certificate, and website observations.

Used appropriately, RDAP Lookup provides a clear starting point for understanding a domain’s public registration record. The most reliable conclusions come from interpreting its registrar, events, statuses, entities, and nameservers together, checking the timestamp and source context, and validating important findings with the relevant WHOISDR tools.

Frequently asked questions

What is RDAP Lookup used for?

RDAP Lookup retrieves registration data for a domain through the Registration Data Access Protocol. It can help you inspect the registrar, registration and expiration dates, domain status codes, and available registrant or administrative entities.

What information can RDAP Lookup show?

Depending on the registry and the domain, results may include the registrar, domain events and dates, status codes, nameservers, and contact or organization entities. The amount of information varies by registry policies and applicable privacy rules.

Is RDAP Lookup the same as a WHOIS lookup?

RDAP is the modern successor to the traditional WHOIS protocol and returns structured data, commonly in JSON format. RDAP Lookup uses RDAP registration services, so its results and presentation may differ from a WHOIS response.

Can RDAP Lookup confirm whether a domain is available?

RDAP results can indicate whether a domain is registered or whether the queried service has no registration record for it. An absent record is not a guarantee that the name can be registered, so confirm availability with an appropriate registrar.

Why are registrant details missing or redacted?

Registries and registrars may withhold personal information because of privacy policies, data protection requirements, or proxy and privacy services. A result can still include non-personal details such as the registrar, domain status, dates, or nameservers.

What do domain status codes in the results mean?

Status codes describe conditions or restrictions applied to a domain, such as transfer, update, or deletion locks. Their exact meaning can depend on the registry, so review the code definitions or linked registry documentation when interpreting an unfamiliar status.

Why might registration and expiration dates differ between sources?

Different services may display different event types, apply different formatting, or use cached data. RDAP reports the events supplied by the authoritative registration service, but dates can change after renewals, transfers, or other domain lifecycle events.

What should I do if RDAP Lookup returns an error or incomplete result?

Check that the domain name is entered correctly and try again without extra spaces or a URL path. If the issue persists, the domain's registry or RDAP service may be unavailable, may not support the query, or may limit the data it returns.

Current-state checks

Free tools focus on live public data and diagnostic signals available at the time of the request.

Actionable follow-ups

Use related DNS, registration, network and web tools to verify a finding rather than relying on one signal in isolation.

Pro investigation workflow

Save evidence snapshots, export CSV, run bulk lookups and combine current data with historical intelligence.