Skip to content
Osintpro

WHOIS Lookup That Produces Evidence, Not a Dump

A free WHOIS box gives you a wall of text you then screenshot. Osintpro runs the same lookup and returns findings: registration age, registrar of record, transfer locks and delegation, each with the record it came from and the UTC moment it was retrieved.

Run it below on a domain you are authorized to assess. Nothing is sent to the target.

See pricing
  • Passive collection only.
  • Public sources.
  • Findings carry their record.
  • Domains only, never a person.

Run the lookup and keep the evidence.

The registration module reads RDAP, the structured successor to port-43 WHOIS. Turn the other modules off if you only want registration data. The scope you declare is stamped on the report header before anything runs.

  • It runs in your browser. Queries go to public DNS and RDAP endpoints, not through us.

  • Nothing reaches the subject. The domain you enter is never contacted, probed or scanned.

  • A domain, never a person. There is no input on this panel that accepts an individual.

  • Findings carry their evidence. Raw record, source endpoint and the UTC moment of retrieval.

Domain footprint sweep

passive collection only

stamped on the report
Samples:

Every finding will carry four things

  • 1 Severity. What the record means for the decision in front of you.
  • 2 The raw record. Exactly as the source returned it, unedited.
  • 3 The source endpoint. The request that produced it, so it can be re-run.
  • 4 The UTC retrieval time. Records change. Without this it is an assertion.

Reads dns.google and rdap.org from your browser. Nothing is sent to the domain you enter.

Tick the authorization box, then run the sweep. Enter the domain you are authorized to assess, then run the sweep. Run the sweep. The report lands here.

WHOIS is being replaced by RDAP, and that matters for evidence.

Classic WHOIS answers on port 43 in free text. Every registry formats it differently, most of it has been redacted since GDPR, and there is no machine-readable structure to it. That is why a WHOIS screenshot is hard to defend: you cannot show which server answered, in what format, or when.

RDAP, the Registration Data Access Protocol, is the standardized replacement. It answers over HTTPS in JSON, it is served by the authoritative registry or registrar for the name, and it carries explicit event records for registration, expiry and last change. ICANN required generic top level domain registries and registrars to run RDAP from 2019, and the port-43 requirement was retired in 2025.

Osintpro queries RDAP, keeps the raw JSON as the evidence, and records the endpoint that answered. When a reviewer asks where a registration date came from, the answer is a URL they can re-run, not a cropped screenshot.

What redaction did and did not remove

Registrant name, address, phone and email are usually redacted for individuals under privacy rules. What survives redaction is what an investigator actually uses most: the creation date, the expiry date, the last change date, the registrar of record, the registry status codes and the delegated nameservers. Those four fields answer most vendor and fraud questions on their own.

What each domain status code actually tells you.

Status codes are the most under-read part of a WHOIS or RDAP record. They describe who has locked the name and against what. A domain with no locks at all, carrying an organization's mail, is a real finding.

clientTransferProhibited

Who set it
The registrar
What it means for your case
The name cannot be transferred away without the lock being lifted. Its absence on a business-critical domain is a hijacking exposure worth raising.

clientUpdateProhibited

Who set it
The registrar
What it means for your case
Nameservers and contacts cannot be changed. Strong protection against a compromised registrar login silently repointing mail.

serverTransferProhibited

Who set it
The registry
What it means for your case
A registry-level lock, usually part of a paid registry lock service. Its presence signals a mature brand-protection posture.

clientHold

Who set it
The registrar
What it means for your case
The name has been pulled from the zone and will not resolve. Often a payment or abuse action. Read it as a live event, not a historical one.

pendingDelete

Who set it
The registry
What it means for your case
The name is scheduled for deletion. If a counterparty is doing business on it, that is material.

redemptionPeriod

Who set it
The registry
What it means for your case
The name expired and is in the grace window before deletion. Frequently the first visible sign that a company has stopped paying its bills.

inactive

Who set it
The registry
What it means for your case
No nameservers are delegated. The domain exists on paper and does nothing.

ok / active

Who set it
Default
What it means for your case
No registrar or registry lock is set. Not an error, but for a domain carrying mail and identity it is the weakest position available.

Codes are defined by ICANN in the EPP status code registry. Osintpro renders the raw code, the plain meaning and the record it came from, so nobody has to remember this table.

The four questions a registration record actually answers.

How old is this counterparty, really?

A domain registered eleven weeks ago behind a business claiming twenty years of trading is the single most common signal in vendor and invoice fraud. Registration date is the cheapest fraud check that exists.

Who do I serve notice on?

The registrar of record is who receives a takedown, a UDRP filing or a transfer dispute. Corporate registrars such as MarkMonitor or SafeNames also tell you the other side has a brand-protection program.

Is the name defended?

Status codes show which locks are set. For your own estate this is an audit item. For a target it tells you how much operational maturity sits behind the brand.

Who controls the zone?

The delegated nameservers name the vendor that can change every record on the domain, including where its mail goes. It is the highest-leverage account in the estate and it is public.

When does it lapse?

An expiry date inside ninety days on a domain that carries production mail is an operational risk finding, and it is one of the few OSINT findings that comes with a deadline.

Has it changed recently?

The last-changed event, compared against a previous case, shows movement. Re-run a case next quarter and the diff is the finding.

Why not just use a free WHOIS box.

Free WHOIS lookups are fine. They are just not evidence.

Use whatever you like for a quick check. The problem starts when the answer has consequences. A free box gives you text on a screen with no retrieval timestamp, no record of which server answered and no link back into a case. Registration data changes, so an undated claim about it cannot be verified later, by you or by anyone reviewing your work.

Osintpro turns the same lookup into a finding with a source endpoint and a UTC timestamp, inside a case that already records what you were authorized to look at. That is the entire difference, and it is the difference that matters when a vendor is rejected or a claim goes to counsel. We say the same thing, at more length, about free OSINT tools generally.

Questions people ask about WHOIS lookups.

Run an RDAP or WHOIS lookup on the domain. For most registrations you will get the registrar, the creation and expiry dates, the status codes and the nameservers, but not the registrant name. Personal contact details have been redacted by default since GDPR, so ownership is usually established from the surrounding evidence rather than from a name field.

Registrars began redacting registrant name, email and postal address to comply with GDPR, and the practice became the default worldwide rather than only in Europe. What remains public is the operationally useful part: registration age, registrar of record, transfer and delete status codes, delegated nameservers, and the dates of the last change.

WHOIS is unstructured text served over port 43 with no standard format. RDAP returns structured JSON over HTTPS from the authoritative registry or registrar, with explicit event records for registration, expiry and last change. ICANN has retired the port-43 WHOIS requirement, so RDAP is now the record you should be citing in a finding.

Yes, if you capture it properly. A screenshot of a lookup box is weak because nobody can tell which endpoint answered or when. A defensible record keeps the raw response, the source endpoint that served it and the UTC time it was retrieved, which lets a reviewer re-run the same query and get the same answer or see what changed.

Manual lookups do not scale past a handful of domains. Bulk work means querying RDAP endpoints programmatically, handling registry rate limits and the country-code registries that never adopted RDAP, then normalizing the responses. Running a list through a case tool is the usual answer, because the output has to be comparable across domains to be worth anything.

No. The query goes to the registry or registrar that holds the registration record, not to the domain's own infrastructure. Nothing is sent to the subject, no host is contacted and nothing appears in the subject's logs, which is why registration checks are safe to run before an engagement is authorized.

Run one scoped sweep and see what a sourced finding looks like.

The demo is free, it takes a domain and never a person, and it produces the same evidence chain the paid report does.

See how a case runs
  • Passive collection only, from public sources.
  • A domain, never a person. There is no input for one.
  • Your case data stays yours. No card required.

Scope in, evidence out. The demo needs no card.