WHOIS Beginner Guide: Your First Domain Lookup
Learn how to perform WHOIS lookups from scratch, understand domain registration data, read registrar information, and use WHOIS for basic reconnaissance.
Domain Registration Intelligence
WHOIS is a protocol and methodology for extracting intelligence from domain registration records. Every registered domain leaves a data trail — ownership details, registration dates, name servers — stored in public databases that anyone can query. This intelligence reveals organizational affiliations, infrastructure relationships, and potential attack vectors that would otherwise remain hidden.
Why Use WHOIS?
WHOIS lookups provide valuable intelligence about a target domain:
Prerequisites
Before following this guide, you should understand:
Installing WHOIS
WHOIS comes pre-installed on Kali Linux. On other Linux distributions:
# Debian/Ubuntu
sudo apt install whois
# CentOS/RHEL
sudo yum install whois
# macOS
brew install whois
Your First WHOIS Lookup
Basic Domain Query
# Query a domain
whois example.com
This returns a detailed response containing:
Reading the Output
# Extract just the key fields
whois example.com | grep -E "Registrar:|Creation Date:|Registry Expiry Date:|Name Server:"
Query by IP Address
# Find who owns an IP address
whois 8.8.8.8
This shows the network range, organization, and contact information for the IP address owner.
Query a Specific WHOIS Server
# Use Verisign's WHOIS server for .com domains
whois -h whois.verisign-grs.com example.com
Understanding Domain Status Codes
Domain status codes indicate the current state of a domain:
| Status Code | Meaning |
|-------------|---------|
| clientTransferProhibited | Domain cannot be transferred without owner approval |
| clientUpdateProhibited | Domain cannot be modified without owner approval |
| clientDeleteProhibited | Domain cannot be deleted without owner approval |
| serverTransferProhibited | Registry has locked the domain from transfer |
| ok | Domain is active with no restrictions |
| pendingDelete | Domain is scheduled for deletion |
| redemptionPeriod | Domain is in grace period before deletion |
Practical Examples
Check Domain Expiration
# See when a domain expires
whois example.com | grep -i "expir"
Find Name Servers
# List all name servers
whois example.com | grep -i "name server"
Identify the Registrar
# Find the registrar
whois example.com | grep -i "registrar"
Quick WHOIS Script
#!/bin/bash
DOMAIN=$1
echo "=== WHOIS Summary for $DOMAIN ==="
echo ""
echo "Registrar:"
whois "$DOMAIN" | grep -i "registrar:" | head -1
echo ""
echo "Created:"
whois "$DOMAIN" | grep -i "creation date" | head -1
echo ""
echo "Expires:"
whois "$DOMAIN" | grep -i "registry expiry" | head -1
echo ""
echo "Name Servers:"
whois "$DOMAIN" | grep -i "name server" | sort -u
Common Use Cases
Next Steps
Once you're comfortable with basic WHOIS lookups, explore:
Frequently Asked Questions
Is WHOIS lookup free?
Yes. The basic WHOIS command is completely free and available on all Linux systems. Some advanced features like historical WHOIS data may require paid services.
Can I hide my WHOIS information?
Yes. Many registrars offer WHOIS privacy protection that replaces your personal details with proxy information. Some TLDs like .eu require GDPR-compliant redactions by default.
What is the difference between WHOIS and DNS?
WHOIS provides domain registration information (owner, registrar, dates). DNS provides technical records (IP addresses, mail servers, name servers). Both are essential for domain reconnaissance.
Can I use WHOIS on any domain?
Most generic TLDs (.com, .net, .org) support WHOIS. Some country-code TLDs may have restricted access or require specific queries.
How accurate is WHOIS data?
WHOIS data is maintained by registrars and domain owners. It is generally accurate for registration details but may be outdated for contact information, especially with privacy-protected domains.