Definition ยท Subdomain Enumeration

What is WHOIS?

WHOIS, specified in RFC 3912, is a simple text-based protocol for querying registration data held by domain registries, registrars, and regional internet registries. A domain lookup typically returns the registrar, creation and expiry dates, status codes, and authoritative name servers; an IP lookup returns the organisation a netblock is allocated to and its contact details.

RDAP, the structured replacement

RDAP (the Registration Data Access Protocol) serves the same data over HTTPS as JSON, with defined query paths, authentication support, and internationalisation. It is the direction registries are moving in, and it is the better choice for automation because the response is structured rather than free-form registry-specific text.

Redaction and its consequences

Registrant names, addresses, and email addresses are widely redacted or replaced by privacy services, particularly for domains registered by individuals and those within scope of data protection rules. Domain ownership attribution from WHOIS alone is therefore unreliable. The technical fields โ€” name servers, dates, status, and IP allocations โ€” remain useful and are rarely hidden.

Why it matters for external exposure

WHOIS and RDAP answer two questions that matter for attack surface work. Which domains and netblocks are actually ours โ€” including ones registered by a marketing team or acquired with a subsidiary? And which of them is about to expire, taking a service down or freeing a name for someone else to register? For typosquatting investigations, registration dates and name server patterns are often the only linkage between look-alike domains.

WHOIS is a standard OSINT source in reconnaissance, complements passive DNS and certificate transparency logs for enumeration, and underpins the scoping stage of asset discovery.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.