How do I find out who owns a domain?
"Who owns this domain" almost never has a one-line answer any more. What you can get reliably is the registrar, the dates and the name servers; what you cannot get, for most domains registered since 2018, is a person.
Run a WHOIS lookup on the domain. It will tell you the registrar, the creation and expiry dates, the name servers and the status codes — but for most domains registered after 25 May 2018 the registrant’s name, email and address are replaced by "REDACTED FOR PRIVACY". The information is still held by the registrar; it is simply no longer published. To reach the actual owner you go through the registrar’s anonymised forwarding address, or through the abuse contact if you have a legal or security reason.
Worked out 2026-09-10 (IST) · gTLD behaviour under ICANN’s Registration Data PolicyWhat a WHOIS record still tells you in 2026
Redaction removed the personal fields and left everything operational intact. This is the realistic expectation for a .com or .in domain registered by a private individual today.
| Field | Still public? | What it is worth to you |
|---|---|---|
| Registrar & IANA ID | Yes, always | Who to complain to, and where the domain lives |
| Creation date | Yes, always | Age is the strongest single trust signal on a domain |
| Expiry date | Yes, always | When it lapses, and whether it is about to |
| Updated date | Yes, always | A recent change can mean a transfer or a new owner |
| Name servers | Yes, always | Reveals the host or DNS provider, often the real operator |
| Domain status (EPP) codes | Yes, always | Locks, holds and whether it is mid-deletion |
| DNSSEC | Yes, always | Signed or unsigned |
| Registrant name | Rarely — redacted | Visible on most company and some ccTLD domains |
| Registrant organisation | Sometimes | Often left public when the registrant is a business |
| Registrant email | No — anonymised | Replaced by a forwarding address or a web form |
| Registrant address & phone | No — redacted | Country is usually still shown |
| Abuse contact email & phone | Yes, mandatory | The one channel a registrar must answer |
Five routes to a human, in the order worth trying
- The anonymised registrant email. Privacy services publish a forwarding address that relays to the owner. It is the intended channel and it works more often than people expect.
- The website itself. An imprint, a privacy policy, a contact page or a GST number on an Indian site will name the operator faster than any lookup.
- The name servers and the certificate. Name servers name the host; a TLS certificate often carries an organisation name and always carries every SAN hostname, which links sibling domains together.
- The registrar’s abuse contact. Mandatory under the Registrar Accreditation Agreement and monitored. Use it for phishing, malware or trademark abuse — not for “I want to buy this domain”.
- A formal disclosure request. Law enforcement, a court order, or ICANN’s Registration Data Request Service for a documented legitimate interest.
Where redaction does not apply
Not every domain hides its registrant. You will still see full details on many corporate registrations, on domains held by organisations that chose to stay public, and on several country-code TLDs whose registries set their own policy rather than ICANN’s. .us forbids proxy registration outright. Historic records also survive: a domain registered before May 2018 may have had public details for years, and those years are indexed in archives even though the live record no longer shows them.
Sources: ICANN Registrar Accreditation Agreement 2013, ICANN Transfer Policy, ICANN Expired Registration Recovery Policy, ICANN Registry Agreement Specification 4 (RDAP), IETF RFC 9083 and RFC 5731 (EPP status codes), and the EU General Data Protection Regulation as applied by ICANN’s Registration Data Policy.
Check your own numbers
Look up any domain and read the registrar, dates, name servers and status codes.
Frequently asked
Is WHOIS lookup legal?
Yes. WHOIS and its successor RDAP are public directory services that ICANN requires registries and registrars to operate. Querying them is not merely legal, it is the intended use. What changed with GDPR is how much personal data those services return, not whether you may ask.
Can the domain owner see that I looked them up?
No. A WHOIS or RDAP query goes to the registry or registrar, not to the domain owner, and it does not touch the domain's own web server. Rate limits mean the registry sees your IP address, but the registrant is not notified.
Why does WHOIS show a different company from the website?
Three common reasons. The domain may be registered through a reseller, so you see the reseller's upstream registrar. It may use a privacy or proxy service, which substitutes its own details. Or the site may be hosted by an agency that registered the domain in its own name - which is worth catching before you pay them, because whoever is named on the registration controls the domain.
What is the difference between a registrar and a registry?
The registry runs the top-level domain and holds the authoritative database - Verisign for .com, NIXI for .in, PIR for .org. The registrar is the retailer you buy from and the party you have a contract with - GoDaddy, Namecheap, BigRock, Cloudflare. WHOIS data flows from the registrar to the registry, which is why a thin registry sometimes shows less than the registrar does.
Related answers
Need domain and DNS checks inside your own product?
We build WHOIS, RDAP, DNS and SSL lookups as embeddable widgets or a plain JSON API in your branding, wired to your own lead form. Tell us which checks you need and we will send a working demo.
Request received
Thanks — we will reply within one business day. Meanwhile, all 164 tools are free to use, no signup.