
A domain owner lookup starts with the registration record: query WHOIS or its successor RDAP for the domain and you get the registrar, the creation and expiry dates, the name servers and the registrant — as far as privacy rules allow. For most personal domains the name is redacted, so contact goes through the registrar's relay form instead.
How to find out who owns a domain
Every registered domain has a record held by the registry that runs its top-level domain (Verisign for .com and .net, Public Interest Registry for .org, a national operator for each country code). The registrar you pay for the domain maintains the customer details. Two protocols expose that record:
- WHOIS is the original plain-text protocol from the 1980s: a client opens TCP port 43 on the registry's server and prints whatever comes back. Every registry formats the reply its own way. See RFC 3912.
- RDAP (Registration Data Access Protocol) replaces it with JSON over HTTPS. Field names are the same for every TLD that supports it: dates live in
events, contacts inentities, statuses instatus. The response format is defined in RFC 9083.
For generic TLDs, ICANN made RDAP the authoritative source in 2025 and stopped requiring registries and registrars to run port-43 WHOIS. Many still do, but when a WHOIS client returns an empty or truncated answer for a .com domain, RDAP is where the data now lives. The simplest front end is ICANN's own lookup.icann.org, which finds the right RDAP server for you. Country-code TLDs are a mixed picture: some publish RDAP, many (including .io and .ru) still answer only over WHOIS. For a fuller walk-through of the protocol, see our WHOIS guide.
Reading the record: what each field tells you
Here is a trimmed real-world reply for a .com domain registered by a company:
Domain Name: GITHUB.COM
Registrar: MarkMonitor, Inc.
Creation Date: 2007-10-09T18:20:50Z
Registry Expiry Date: 2028-10-09T18:20:50Z
Domain Status: clientTransferProhibited
Registrant Organization: GitHub, Inc.
Registrant Country: US
Registrant Email: Select Request Email Form at https://domains.markmonitor.com/whois/github.com
Name Server: dns1.p08.nsone.net
| Field | Meaning | What to look for |
|---|---|---|
Registrant Organization / Registrant Name | The holder of the domain | A company name is often shown; for individuals expect "REDACTED FOR PRIVACY" or a privacy service |
Registrant Country, State/Province | Where the registrant is based | Usually left visible even when the name is redacted |
Registrar | The company the domain is registered through | Where to send messages, transfer requests and complaints |
Creation Date | Registration date | The basis for domain age |
Registry Expiry Date | Paid-up-to date at the registry | A past date means the domain is in a grace or redemption period |
Updated Date | Last change to the record | A recent change may mean a new owner, registrar or name servers |
Domain Status | EPP status codes | clientTransferProhibited is a routine lock; serverHold or redemptionPeriod mean the domain does not resolve |
Name Server | Authoritative DNS | Shows who hosts the zone: the registrar, a CDN or a DNS provider |
Registrar Abuse Contact Email | Complaint address | Use it for phishing, malware and spam reports |
Registries of "thin" TLDs such as .com store only the registrar-level data; the registrant block comes from the registrar. That is why a full reply can contain two expiry dates (Registry Expiry Date and Registrar Registration Expiration Date) that differ by hours.
Why the owner is hidden, and how to reach them anyway
Since the EU's GDPR took effect in May 2018, registrars redact personal data for individuals by default, and many apply the same rule to everyone. Some ccTLDs go further: the Russian .ru registry shows "Private Person" for individuals and now leaves the organisation field blank as well. Redaction does not make the owner unreachable:
- Registrar relay. The redacted
Registrant Emailusually points to a web form or an anonymised forwarding address. Your message reaches the owner without exposing their address. - The site itself. Imprint, contact and privacy-policy pages. EU businesses generally have to publish a legal name and address; online shops in most jurisdictions have similar disclosure rules.
- The TLS certificate. Organisation-validated (OV) and extended-validation (EV) certificates carry the verified company name in the
Ofield. Domain-validated certificates, including Let's Encrypt, contain only the hostname. - Abuse channels. For phishing or malware, write to the registrar's abuse address and to the hosting provider. The host is identified from the site's IP address — see how to find a site's hosting and IP.
- Legal disclosure. ICANN policy lets registrars disclose redacted data on a legitimate, documented request, and courts can order it. A casual "who is this?" email will not be enough.
If you are trying to buy a taken name, check the status and expiry date first; sometimes the name is already on its way back to the pool. Our guide on checking domain availability covers the signs.
Domain age: finding the registration date
Domain age is simply the time since Creation Date (the registration event in RDAP). All registries report timestamps in UTC, so two tools can legitimately show adjacent calendar days. Three caveats matter more than the number itself:
- A drop resets the clock. If a domain expires, is deleted and gets registered again, the creation date is the new one. A name used since 2005 can look six months old.
- A transfer does not. Moving the domain to another registrar or selling it without deletion keeps the original date, so age says nothing about how long the current owner has held it.
- Domain age is not site age. Many domains sit parked for years. To see when real content appeared and what it was, use archived snapshots — our Wayback Machine guide shows how.
# Linux / macOS
whois example.com | grep -iE "creation date|expiry date"
# RDAP (jq for readable output)
curl -sL https://rdap.org/domain/example.com | jq '.events'
# Windows PowerShell, no extra tools
Invoke-RestMethod https://rdap.org/domain/example.com | Select-Object -ExpandProperty events
rdap.org is a redirector: it reads the IANA bootstrap registry and forwards the query to the RDAP server responsible for the TLD, which is why -L matters in the curl command.
Registrar, registry, DNS and hosting are four different parties
"Where is this domain registered?" often hides a different question. Knowing which party does what tells you whom to contact:
| Party | Role | How to identify it |
|---|---|---|
| Registry | Runs the TLD database and its authoritative servers | Follows from the extension; listed in the IANA root zone database |
| Registrar | Sells and renews the domain, holds the owner's details | Registrar field |
| DNS provider | Answers queries for A, MX and TXT records | NS records |
| Web host | Runs the server the site lives on | A record, then the network owner of that IP |
Only the registrar knows the domain holder. The host knows only whoever pays for the server. When a gTLD domain lapses, it typically enters a registrar grace period of up to 45 days, then a 30-day redemption period, then five days of pending delete before it is released — details in our article on expiring and dropped domains.
Domain history: past owners, content and DNS
Ownership history
Registries only answer with the current state. Historical WHOIS comes from commercial databases that saved replies over the years. Since 2018 their value for personal domains is limited, because snapshot after snapshot reads "REDACTED FOR PRIVACY". The useful signals are indirect: a change of registrar, name servers or registrant organisation, and above all a new creation date, which almost always means the domain was dropped and re-registered.
Content history
Web archive snapshots show what the site published and when the topic changed. A domain that hosted a casino or doorway pages a few years ago is worth knowing about before you buy it.
DNS and certificate history
Passive DNS services record answers seen by resolvers and reveal where a domain pointed in the past. Certificate Transparency logs are the open alternative: every publicly trusted TLS certificate is logged, so you can see when certificates were issued for the domain and its subdomains, and by which CA.
Who owns a TLD such as .io, .ai or .tv?
Buying example.io gives you a registration, not a piece of the extension. The TLD itself belongs to a registry acting for a country, an organisation or ICANN's contract framework:
- .io — the country code of the British Indian Ocean Territory, popular with tech companies as a generic extension.
- .ai — Anguilla, a British Overseas Territory in the Caribbean; registration fees are a notable source of the territory's revenue.
- .tv and .me — Tuvalu and Montenegro.
- .com and .net — Verisign, under contract with ICANN; .org — Public Interest Registry.
- .gov — restricted to US government bodies.
For any other extension, the IANA root zone database lists the sponsoring organisation and the technical operator.
How to check a domain's owner, age and registrar
- Run the domain through the WHOIS lookup for registrar, dates, statuses and whatever registrant data is public.
- Check NS, A and MX records with the DNS lookup to see where the zone, the site and the mail are hosted.
- Look up the site's IP in the IP lookup to find the network owner — the right recipient for a hosting abuse report.
whois example.com # Linux/macOS; Debian/Ubuntu: sudo apt install whois
whois -h whois.verisign-grs.com example.com # ask the .com registry directly
dig +short NS example.com
dig +short A example.com
On Windows without WSL, the Sysinternals whois64.exe utility or the PowerShell RDAP call above covers the same ground.
FAQ
Is a domain owner lookup free?
Yes. Current WHOIS and RDAP data is free from registries, registrars and online tools. Only historical WHOIS and passive DNS archives are usually paid.
Can I get the name of a private owner?
Not from public records. Use the registrar's relay form, or a formal disclosure request backed by a legitimate reason or a court order.
Does selling or transferring a domain change its age?
No. The creation date survives transfers and ownership changes. It only resets when the domain is deleted and registered again.
Why do lookup tools show different dates?
Registries report UTC while tools convert to local time; the registry and registrar keep separate expiry dates; and some tools show cached replies.
What does clientTransferProhibited mean?
It is a lock the registrar sets to stop unauthorised transfers. It is normal and does not indicate a dispute.