Home/Glossary/WHOIS Database

WHOIS Database

A public directory that stores registration information for domain names and IP address blocks.

NetworkingAlso called: "whois lookup", "domain registration"

WHOIS records reveal who owns a domain, when it was registered, and when it expires.

Information available

  • Registrant: Domain owner's contact details (often redacted for privacy).
  • Registrar: Company that sold the domain.
  • Registration/expiration dates: When domain was created and when it renews.
  • Nameservers: DNS servers authoritative for the domain.

Investigative uses

  • Identify phishing domains by checking creation date.
  • Find domain owner for abuse reporting.
  • Monitor domain expiration for brand protection.
  • Research infrastructure patterns in threat campaigns.