Definition ยท Subdomain Enumeration
What is WHOIS?
WHOIS, specified in RFC 3912, is a simple text-based protocol for querying registration data held by domain registries, registrars, and regional internet registries. A domain lookup typically returns the registrar, creation and expiry dates, status codes, and authoritative name servers; an IP lookup returns the organisation a netblock is allocated to and its contact details.
RDAP, the structured replacement
RDAP (the Registration Data Access Protocol) serves the same data over HTTPS as JSON, with defined query paths, authentication support, and internationalisation. It is the direction registries are moving in, and it is the better choice for automation because the response is structured rather than free-form registry-specific text.
Redaction and its consequences
Registrant names, addresses, and email addresses are widely redacted or replaced by privacy services, particularly for domains registered by individuals and those within scope of data protection rules. Domain ownership attribution from WHOIS alone is therefore unreliable. The technical fields โ name servers, dates, status, and IP allocations โ remain useful and are rarely hidden.
Why it matters for external exposure
WHOIS and RDAP answer two questions that matter for attack surface work. Which domains and netblocks are actually ours โ including ones registered by a marketing team or acquired with a subsidiary? And which of them is about to expire, taking a service down or freeing a name for someone else to register? For typosquatting investigations, registration dates and name server patterns are often the only linkage between look-alike domains.
Related concepts
WHOIS is a standard OSINT source in reconnaissance, complements passive DNS and certificate transparency logs for enumeration, and underpins the scoping stage of asset discovery.