How to Find Out Who Owns a Domain Name
A domain's registration record tells you who it is registered through, when it was created and when it expires — but the owner's own details are usually hidden for privacy. Here is what a lookup shows today, how to reach the owner anyway, and the lawful routes to data that is not public.
By the W.is team · Updated
Look up any domain:
Step 1: Run an RDAP/WHOIS lookup
Enter the domain in the box above, or go to an address such as w.is/example.com. W.is asks the registry that runs the TLD — over RDAP where available, WHOIS otherwise — and shows:
- Registrar — the company the domain is registered through. It is almost always published and is your main point of contact.
- Dates — created, updated and expires. A domain registered last week tells a different story from one registered in 1998.
- Status codes — for example clientHold or serverHold, which mean the domain has been taken out of the DNS, often after a complaint or non-payment.
- Name servers — which DNS provider hosts the domain.
- Registrant fields — organization, state or province and country, when the registry publishes them.
Below the summary is the raw RDAP or WHOIS response, where contacts appear as entities with roles such as registrant, registrar and abuse. If the result shows an email address or phone number, check there whose it is — for many gTLD domains it belongs to the registrar's abuse desk, not the owner.
For .com and .net, the registry holds no registrant data at all. Its RDAP record usually links to the registrar's own RDAP record for the domain, which is where any published registrant details appear.
Why owner details are usually hidden
Until 2018, a WHOIS lookup on most generic TLDs showed the owner's name, postal address, phone number and email. That changed when the EU's General Data Protection Regulation (GDPR) took effect on May 25, 2018. ICANN adopted a Temporary Specification for gTLD registration data the same month, and its successor, the Registration Data Policy, keeps the same approach: registries and registrars no longer publish registrants' personal data. Most registrars apply this worldwide, not only to EU residents.
In a gTLD record today you will typically see “REDACTED FOR PRIVACY” (or the fields simply missing) for the name, street address, phone and email, while the state or province, the country and sometimes an organization name remain visible. RDAP servers can list exactly which fields they redacted, using the extension defined in RFC 9537.
Many owners also use a privacy or proxy service, often offered by the registrar itself. The record then shows the service's details — names such as “Domains By Proxy, LLC” or “Withheld for Privacy ehf” — instead of the owner's. That company is not the owner, although under its own terms it may disclose the owner's identity in some situations.
How to contact the owner
A redacted record does not make the owner unreachable. ICANN rules require registrars to offer a way to email a domain's registrant without revealing their address: an anonymized relay email address or a web contact form. Look for it in the registrant entity's email field or remarks in the raw RDAP response, or on the registrar's website, where it is often called something like “contact the domain owner”.
If the record shows a privacy or proxy service, write to the address it lists; messages are normally passed on to the owner. Keep it short, say who you are and why you are writing, and do not expect a guaranteed reply. If the domain has a working website, its contact page is often faster.
Reporting phishing, malware and spam
If a domain is being used to harm people, you do not need to know the owner. Every ICANN-accredited registrar must publish an abuse contact and investigate the reports it receives. In RDAP it is the entity with the abuse role nested inside the registrar entity; in gTLD WHOIS it is the “Registrar Abuse Contact Email” line. Since April 5, 2024, ICANN's contracts also require registrars and gTLD registries to take action against well-evidenced DNS abuse: malware, botnets, phishing, pharming, and spam used to deliver them.
- Include the full URLs, the dates and times you saw the problem, screenshots and, for spam or phishing emails, the full message headers.
- For problems with the content of a website, such as copyright infringement, the hosting provider is usually the right contact. The site's IP address shows which network hosts it; an IP lookup tool such as IP.im can tell you.
- If a gTLD registrar does not respond, you can file a complaint with ICANN Contractual Compliance.
Requesting non-public data (RDRS)
If you have a legitimate need for the registrant's identity — law enforcement, cybersecurity investigations, enforcing trademarks or other rights, or legal proceedings — you can ask for the redacted data. Registrars are expected to review reasonable requests for disclosure and decide case by case under the applicable privacy law.
ICANN's Registration Data Request Service (RDRS) is a free system for making such requests. It launched in November 2023 as a two-year pilot, and ICANN's Board has decided to keep it running while a long-term solution is developed. You create an account, identify yourself, and explain which domain you are asking about and why; RDRS passes the request to the registrar, which decides whether to disclose. Keep in mind that:
- RDRS covers generic TLDs only, not country-code TLDs.
- Registrar participation is voluntary. If the registrar does not participate, contact it directly — many have their own disclosure request forms.
- ICANN does not hold the data or make the decision; disclosure is never guaranteed.
For trademark disputes there is also the Uniform Domain-Name Dispute-Resolution Policy (UDRP). You can file a complaint against a privacy-protected domain; the dispute resolution provider obtains the registrant's details from the registrar as part of the process.
Country-code domains
Country-code TLDs are not covered by ICANN's gTLD policies, so each registry decides what to publish. Some show more than gTLDs do, such as the name of an organization that holds the domain; others show less. DENIC, for example, stopped publishing .de domain holder data in May 2018 and discloses it only on request to parties with a legitimate interest. Some ccTLDs also have eligibility rules — .ca requires a Canadian presence — which tell you something about the registrant even when the record is redacted.
RDRS does not cover ccTLDs, so for these domains contact the registrar or the registry directly. The TLD list shows the registry and lookup servers for every country-code TLD.
Other lawful clues
Registration data is only one source. Publicly available information often tells you more:
- The website itself. Look at the about, contact, terms and privacy pages. Privacy notices under the GDPR must name the organization responsible, and many countries, such as Germany and Austria, require commercial websites to publish a legal notice (Impressum) with the operator's name and address.
- The TLS certificate. Organization-validated (OV) and extended validation (EV) certificates include the organization's verified name; domain validated (DV) ones do not. Certificate Transparency logs list every certificate issued for a domain.
- DNS records. Name servers and MX records show which DNS and email providers the domain uses, and TXT records sometimes reveal the services it is connected to. A DNS lookup tool such as DNS.is shows them all.
- Hosting. The IP address of the website leads to the network that hosts it and its autonomous system. An IP lookup tool such as IP.im shows both.
- History. Web archives show how the site looked in the past, and commercial services keep historical registration records from before 2018. Ownership may have changed since, so treat old data with care.
- Official registers. Business and trademark registers can connect a brand name on the website to the company behind it.
Use these sources for legitimate purposes only. Do not harass or spam the people you find, respect privacy laws, and if you suspect a crime, report it to the police or the relevant authority instead of investigating on your own.
If you want to buy the domain
- Check whether the domain shows a “for sale” page or is listed on a domain marketplace; that is the simplest route.
- Otherwise, write to the owner through the registrar's contact form or privacy relay, or hire a domain broker to approach them for you.
- Before paying, make sure the person you are dealing with really controls the domain — for example, ask them to add a TXT record you choose or to change the website — and use an escrow service for the payment.
- Look at the expiration date and status too. If the domain is about to lapse, read what happens after a domain expires.
Frequently asked questions
Is it legal to look up who owns a domain?
Yes. RDAP and WHOIS are public services intended for exactly this, and they return only the data the registry and registrar have chosen to publish. What you do with the data is subject to the servers' terms of use and to privacy law; using it for unsolicited marketing, for example, is generally prohibited.
Why does the lookup say “REDACTED FOR PRIVACY”?
Since the EU's General Data Protection Regulation took effect in May 2018, gTLD registries and registrars no longer publish personal data such as the registrant's name, email address, phone number and street address. The record usually still shows the registrar, the key dates, the name servers and the registrant's state or province and country.
Can I find out who owned a domain in the past?
Sometimes. Many registration records were public before May 2018, and some commercial services archive historical WHOIS data. The Internet Archive's Wayback Machine can show what the website looked like at different times. Old records may no longer be accurate, so treat them as clues rather than facts.
How do I report a phishing or malware domain?
Send the evidence to the registrar's abuse contact, which is listed in the RDAP or WHOIS record. For generic TLDs, ICANN requires registrars and registries to act on well-evidenced reports of phishing, malware, botnets, pharming and spam used to deliver them. You can also report the website to its hosting provider.
Related guides
- What is RDAP? — how registration lookups work and how to read the raw response.
- RDAP vs WHOIS — why records look different depending on the protocol.
- Domain expiration — what happens when a domain you want is not renewed.
- Domain status codes — what clientHold, serverHold and other codes mean.
- WHOIS server list — the registry WHOIS server for every TLD.
- TLD list — registry, RDAP and WHOIS details for every TLD.