WHOIS Lookup
A public database of a domain’s registration data – since the GDPR, owner details are usually anonymised.
What does WHOIS Lookup mean?
WHOIS is a public query protocol used to retrieve a domain’s registration data: the responsible registrar, creation and expiry date, and – historically – the name and contact details of the domain owner. Since the GDPR came into force in 2018, most registrars hide personal owner data of European domain holders by default or show only an anonymised privacy-proxy entry; the registrar and registration date, however, usually remain visible.
What does remain visible is a surprisingly useful remainder: the registration date, the date of the last change, the expiry date, the registrar’s name, the registered name servers and the domain’s status codes. Technically, WHOIS is increasingly being replaced by RDAP, a more modern protocol with structured responses and tiered access rights – for consumers the substance of the information stays the same.
German domains are a special case: since 2018 the registry DENIC has no longer published owner data in open lookups. For .de domains you will therefore usually only learn the technical key facts. That is not an indication of concealment but simply current practice – anyone deriving suspicion from an anonymous .de WHOIS record is systematically mistaken.
For fake-shop checks, WHOIS is nonetheless useful: the domain’s creation date (see Domain Age) can be read from it, as can red flags such as a registrar frequently associated with bulk registrations or domain parking, or an expiry date coming up shortly for a supposedly established shop.
The real insight comes from comparing the record with what the shop claims about itself. An example: the site advertises “your specialist retailer since 2009”, the domain was registered seven weeks ago according to WHOIS, the certificate is equally young, and the name servers belong to a cheap hosting provider abroad. Each item on its own could be explained – together they contradict the self-presentation so clearly that paying in advance is out of the question.
The opposite case is just as revealing: a domain has existed for many years but, according to WHOIS, was transferred to another registrar only recently and has freshly changed name servers. That is a typical pattern after a change of owner or after an expired domain was taken over. The good reputation of the old content is then used for something entirely different – a look at a web archive shows what used to sit at the address.
Running a query needs no expertise. Almost every registrar offers a WHOIS search box, and the registries themselves operate RDAP interfaces that deliver the same data in structured form. All that matters is entering the bare domain – without “https://”, without “www.” and without a path. Subdomains have no record of their own; what counts is always the registered domain itself.
The name servers are particularly informative. They reveal who runs the address technically. If several suspicious shops share the same, not widely used name servers, that points to a common operator or at least to the same kit. Consumers can rarely verify this directly, but it explains why fake shops often resemble one another right down to the layout.
The status codes are worth a look as well. Entries such as “clientHold” mean the registrar has taken the domain out of service – a clear indication that complaints have already been made. “pendingDelete” signals a domain shortly before expiry. Neither fits a shop that is currently demanding advance payment and promising delivery next week.
Historical data closes the gap that data protection leaves behind. Archive services store older WHOIS snapshots and earlier versions of websites. Anyone wanting to see whether a domain used to belong to someone else or hosted something entirely different will often get further that way than through the current query – especially with old domains carrying new, suspicious content.
It is worth being honest about the limits: WHOIS says nothing about who runs the shop, who processes the orders or where the money goes. It supplies technical key data and points in time. That is precisely where its value lies – as a fast, free counter-check against the claims made on the page, not as an investigative tool.
Context is important: an anonymised WHOIS entry is not, in itself, a fraud signal – the vast majority of legitimate domain owners in the EU also use a privacy service for data-protection reasons. WHOIS only becomes meaningful in combination with other features such as a very young domain, a legal notice that does not match the registrant’s country, or an expiry date only weeks away.
Unsure about a specific shop?
Our fake-shop check evaluates over 30 trust features – free and in seconds.
Check a shop for free