Skip to content

RDAP vs WHOIS: What Changed and How to Read a Lookup

RDAP replaced WHOIS for generic domains in 2025. See what differs, how to read an RDAP response and what it shows about a domain that is expiring.

8 min read

The short version of RDAP vs WHOIS: RDAP (Registration Data Access Protocol) is the replacement for WHOIS. It returns the same registration data, meaning registrar, dates, nameservers and status, but as structured JSON over HTTPS, answered by the server that is authoritative for the domain. For generic extensions, ICANN ended the obligation to run WHOIS on 28 January 2025. For someone checking expiring domains, the lifecycle is the same. What changed is where the answer comes from and how it is spelled.

What is RDAP, and what changed

RDAP was developed in the Internet Engineering Task Force (IETF) to replace WHOIS, a plain-text protocol on its own port (43). Every WHOIS server formatted its answer in its own way, so the same field could carry a different label from one server to the next, and tools had to guess.

According to ICANN, RDAP has been available since 2019. The two ran in parallel until 28 January 2025, when ICANN sunset WHOIS for generic top-level domains: registries and registrars are no longer required to offer it, with a few exceptions listed on ICANN’s RDAP page. A WHOIS server may still answer, but a tool that depends on port 43 can stop working for an extension without notice.

ICANN names four advantages of RDAP: support for internationalization, secure access to data, authoritative service discovery, and the ability to give different users different levels of access.

RDAP vs WHOIS side by side

WHOIS RDAP
Format Free text, different on every server JSON with fixed field names
Transport Plain text on port 43 HTTPS
Finding the right server The client has to know or guess it A published bootstrap file maps each extension to its server
Non-Latin names and contacts No standard handling Built into the standard
Access control Everyone gets the same answer The server can show more to authorized users
Status for gTLDs No longer required since 28 January 2025 Required

For a buyer, the first row matters most. A lookup tool reads the same fields for every domain, so the expiry date and status you see are less likely to be a parsing mistake.

How an RDAP lookup finds the right server

There is no single RDAP database. So what is an RDAP server? It is a web service, run by a registry or registrar, that answers for the domains it is responsible for.

To find it, a client reads the bootstrap file that IANA publishes. The file for domain names pairs each extension with the base URL of its server. For .com, the entry points to Verisign, so the query is a normal web address:

https://rdap.verisign.com/com/v1/domain/example.com

The bootstrap also shows where RDAP stops. Country-code extensions set their own rules, and some have no entry in the file. At the time of writing, .tr, .se, .nu, .it and .es are among them. Those domains cannot be queried over RDAP, and you have to use the registry’s own lookup.

Reading an RDAP lookup for an expiring domain

A raw RDAP response is long, but four parts carry everything a buyer needs. Here is a trimmed example with made-up values:

{
  "ldhName": "EXAMPLE.COM",
  "status": ["pending delete"],
  "events": [
    {"eventAction": "registration", "eventDate": "2011-05-14T09:20:11Z"},
    {"eventAction": "expiration", "eventDate": "2026-01-14T09:20:11Z"},
    {"eventAction": "last changed", "eventDate": "2026-03-03T10:41:07Z"}
  ],
  "entities": [{"roles": ["registrar"]}],
  "nameservers": []
}

Status values are spelled differently

WHOIS shows the EPP codes in camelCase, such as pendingDelete. RDAP uses its own vocabulary: lower case, with spaces. The standard that maps one to the other (RFC 8056) gives these pairs:

EPP code (WHOIS) RDAP status
ok active
autoRenewPeriod auto renew period
redemptionPeriod redemption period
pendingDelete pending delete
clientTransferProhibited client transfer prohibited
clientHold client hold
serverHold server hold

The meaning is identical. But if you filter RDAP data for pendingDelete, you will find nothing, because the value is pending delete. What each status allows is covered in the guide to domain status codes.

Events hold the dates

Dates sit in an events list, each with an action and a timestamp:

  • registration: when the domain was first registered.
  • expiration: the date the registration ends, the one a domain expiration lookup reports.
  • last changed: the last time the record was modified.

For an expiring domain, last changed is the useful one. When a registry moves a name into a new stage, the record changes, so this date normally marks the start of the current status. Read status and dates together: a date alone does not tell you the stage.

Entities and nameservers

The entity with the role registrar tells you where the domain is registered, which decides where it could be auctioned before it ever drops. An empty nameserver list late in the lifecycle is expected: a name in redemption has been removed from the zone.

A worked example: from RDAP to the drop day

Say you look up a .com and the response shows the status pending delete and a last changed date of 3 March.

  1. The status tells you the stage: pending delete lasts exactly five days, and nobody can renew, restore or register the name during it.
  2. The last changed date tells you when that stage began: 3 March.
  3. A .com or .net name is released in the daily drop on the sixth day after it entered pending delete, so add six days: 9 March.
  4. The .com and .net drop starts at around 12:00 UTC.

So the name becomes available on 9 March, first come, first served. Other generic extensions release five full days after the status began, at their own daily drop. The drop date calculator does this arithmetic from the live record, the pending delete list shows names already in this stage, and the guide on when expired domains become available covers the earlier stages.

What RDAP does not show

RDAP is a snapshot of the current record. Three things are outside it:

  • The owner. Since 2018, most owner details are redacted. The field is marked as redacted, which is where messages such as "the RDAP server redacted the value" come from. Dates, registrar, nameservers and status remain public. For those with a legitimate interest in non-public data, ICANN runs the Registration Data Request Service.
  • Past owners. There is no history in the response. That is a separate search, covered in the guide to WHOIS history.
  • What the site was. Registration data says nothing about content, links or spam. That takes an archive and backlink check, which is what the hunter.domains filters do for the domains it lists.

How to run an RDAP domain lookup

You have three practical options:

  1. ICANN’s lookup tool. lookup.icann.org is ICANN’s own RDAP-based search.
  2. A lookup that explains the fields. The free WHOIS lookup on this site reads the registry record over RDAP and puts a plain sentence next to each status.
  3. A plain HTTPS request. Take the base URL from the bootstrap file, add domain/ and the name, and open it in a browser or a script. A registered name returns JSON. A name the server has no record of returns HTTP 404, and a server that is rate-limiting you returns 429.

An "RDAP WHOIS lookup" is the same thing under an older name: what matters is that the answer comes from the registry.

Frequently asked questions

Is WHOIS being replaced by RDAP?

For generic extensions it already has been. ICANN sunset WHOIS for generic top-level domains on 28 January 2025, and registration data is now provided through RDAP. A WHOIS server may still answer, but it is no longer required to. Country-code extensions decide for themselves.

Is RDAP free to use?

Yes. RDAP is an open standard, and public lookups cost nothing, through ICANN’s lookup tool or a direct request to a registry’s server. Servers can limit how fast you query, so a script that checks a long list should pace itself.

Why does an RDAP lookup say the value was redacted?

Because personal data is withheld from the public answer. Since 2018, most owner details are redacted, and RDAP marks the field instead of leaving it out. It is not an error and says nothing bad about the domain.

Does every domain extension support RDAP?

No. Generic extensions such as .com, .net and .org offer it. Country-code extensions follow their own rules, and several have no server in IANA’s bootstrap file, for example .tr, .se, .nu, .it and .es at the time of writing. For those, use the registry’s own lookup.

Related articles

Don't miss the next good domain.

Set your rule and leave the rest to us. You hear the moment a matching domain is found.

Get started free