What is a whois domain?
A WHOIS query pulls the registration information attached to a domain name from the official registry databases. You enter a domain, and the tool reaches out to whichever registry is in charge of that extension: Verisign for .com and .net, AFNIC for .fr, DENIC for .de, Nominet for .uk. Each extension has its own registry, and that registry is the authoritative source for the data.
What comes back is whatever the domain owner or their registrar declared at registration time: the owner's identity if it's public, the registrar handling the domain, creation and expiration dates, configured DNS servers. Think of it as the administrative ID card of a domain name. A whois lookup is the standard way of pulling that card up.
What's inside a whois domain record?
A complete whois domain record breaks down into several blocks. The “registrant” block identifies the legal owner of the domain. The “admin” block is the administrative contact, often the same person for individuals. The “tech” block is the technical contact, usually the registrar or the hosting provider. Those three contacts can have different details or be identical depending on the setup.
The other important fields are the registrar (the company where the domain was purchased), the creation, last update and expiration dates, the nameservers pointing to whichever DNS infrastructure the domain uses, and the domain status. That status field deserves attention: “clientTransferProhibited” means transferring the domain to another registrar is locked, “pendingDelete” means the domain is on its way to deletion and will be released soon.
Why is WHOIS data so often hidden these days?
Since GDPR came into force in May 2018, most European registrars and many others worldwide have masked the personal data of domain owners in public WHOIS results. Before that, it was normal to see the name, postal address and phone number of whoever owned a domain. Today those fields are replaced with generic placeholders or relay email addresses.
This is what people call WHOIS Privacy or WHOIS Guard. Some registrars sell it as a paid add-on, others enable it by default on every domain. The domain is still registered to a real person or company, that information just isn't publicly accessible anymore. For legal disputes or law enforcement requests, the actual data can still be obtained through official channels, but not from a regular whois domain lookup.
Using WHOIS to vet a domain before buying it
A WHOIS check is the first move before buying any domain you've got your eye on. Running a domain whois on the name tells you immediately whether it's available. If the result is “No match for domain,” the name is up for grabs. If a record comes back, the domain is taken, but check the expiration date: if it's coming up and the owner isn't renewing, you might be able to catch it with a backorder service.
Pay attention to the domain status too. A domain marked “redemptionPeriod” is in the grace window after expiration. The previous owner can still recover it by paying a redemption fee, but it's on the verge of being released. A domain in “pendingDelete” status will be removed within five days and dropped, which usually kicks off a race between backorder tools. This kind of timing intel only shows up in a domain whois, nowhere else in real time.
Domain WHOIS vs IP WHOIS: not the same thing
These two tools share a name but query completely different databases. A whois lookup domain query talks to domain name registries and registrars to fetch information about a registered domain name. An IP WHOIS talks to the RIRs, the regional internet registries like RIPE NCC or ARIN, to find out who owns a block of IP addresses.
The information you get back is different too. A domain WHOIS gives you the owner, the registrar, expiration dates and nameservers. An IP WHOIS gives you the organization or operator responsible for the block, the ASN number, the CIDR range and abuse contacts. They actually complement each other well. If you want to know who's behind a site, you start with a domain WHOIS to identify the owner and registrar, then do an IP WHOIS on the server's address to figure out who's hosting it. Two angles on the same infrastructure.
What WHOIS can't tell you
The biggest limitation is WHOIS Privacy. As personal data protection has spread globally, WHOIS records have become less and less informative about who actually owns a domain. You'll often know which registrar manages it and when it expires, but not who's actually behind it.
The second limitation is freshness. Changes to a record can take a few hours to propagate through public WHOIS databases. For nameservers in particular, the WHOIS data can lag behind what the DNS is actually serving. Some registries also have looser update policies than others. And WHOIS tells you nothing about the actual content of the site, where it's truly hosted, or the reputation of its owner. It's an administrative tool, not a risk assessment platform on its own.