Typosquatting.ai
TECHNICAL

WHOIS vs RDAP: What Changed, and What Still Uses WHOIS

The data did not change much. What changed is whether a program can read it reliably, and where the gaps are.

by Typosquatting.ai Research16 September 2026updated 23 September 202610 min read

WHOIS is the original port 43 text protocol for querying registration data; RDAP is the structured HTTPS and JSON replacement that generic top-level domain registries and registrars were required to adopt.

This guide covers the date the transition took effect, what was wrong with WHOIS, a side-by-side comparison of the two protocols, the same domain in both formats, which country-code endings have RDAP and which do not, and how to read tools that still say WHOIS.

The date that matters: 28 January 2025

ICANN's announcement of 27 January 2025 set the following day, 28 January 2025, as the date from which the Registration Data Access Protocol became the definitive source for generic top-level domain registration data, and from which registries and registrars were no longer required to run WHOIS. ICANN had required gTLD operators to have an RDAP service running since 26 August 2019, so for most of them the sunset simply removed an obligation to keep the old service alongside.

Two things follow. For .com, .net, .org and the newer generic endings, RDAP is now the record of truth, and any WHOIS server still answering is a courtesy that may disappear. For country-code endings, which are not under ICANN contract, nothing was mandated, and that is where the coverage map below becomes necessary.

What WHOIS was, and what was wrong with it

WHOIS, specified in RFC 3912, is a query protocol in which a server listens on TCP port 43 and returns whatever text it likes. It worked for decades and it had four structural problems that no amount of care could fix.

The output had no defined format. Every registry and registrar laid out its response differently, so any program consuming it was a collection of parsers, each guessing at one provider's layout, each breaking when that provider changed a label.

There was no defined way to find the right server, so clients carried hand-maintained lists. There was no internationalisation: RFC 3912 says plainly that the protocol has no mechanism for indicating the character set in use. And there was no security at all, no access control, no integrity and no confidentiality, which meant every requester got the same text. That became untenable once the same field could be public for a company and personal data for an individual.

Finally there was no standard error signalling. A rate limit, an outage and an absent record could all look similar in a text blob, which is precisely the distinction that matters most in an investigation.

WHOIS vs RDAP at a glance

The comparison below is the whole difference in one table. Every row on the RDAP side is a defined behaviour in an RFC; every row on the WHOIS side is a description of common practice, because WHOIS defined almost nothing.

AspectWHOISRDAP
TransportPlain text over TCP port 43HTTPS, ordinary web requests
FormatUnstructured text, layout per registryJSON with named fields (RFC 9083)
Finding the serverReferral chains and hand-kept listsIANA bootstrap file maps endings to servers (RFC 9224)
ErrorsProse in the text, if anythingHTTP codes: 404 no object, 429 rate limited, 5xx failure
InternationalisationNo character set signallingUTF-8 JSON; Unicode and ASCII forms of a name
AuthenticationNone; everyone sees the same textOptional; a server may return more to an authenticated client
Privacy and redactionRedacted since 2018 by policy, ad hoc in textRedacted by policy, with structured notices saying so

What RDAP changed, in detail

A defined format
Responses are JSON with a structure specified in RFC 9083, so a client reads named fields such as events, status, entities and nameservers instead of parsing prose.
A defined way to find the server
IANA publishes a bootstrap file at data.iana.org/rdap/dns.json mapping each ending to its service address, so discovery is deterministic rather than folklore. RFC 9224 describes the registry.
HTTP semantics
Requests are ordinary HTTPS. RFC 7480 says a missing object is a 404, a rate limit is a 429, and a server problem is a 5xx. The three failure cases are finally distinguishable, which is the single biggest practical improvement.
Internationalisation
Names and text carry defined encoding. A domain object has an ldhName in ASCII and, for internationalised names, a unicodeName alongside it.
Differentiated access
RFC 7481 sets out security services WHOIS never had, including authentication and access control. A registry can return more to an authorised requester than to an anonymous one, which is what allows public responses to be redacted without discarding the data entirely.

The same domain in WHOIS and in RDAP

The clearest way to see the difference is to ask both services about the same name. The two records below are what the .com registry returned for example.com on the same day, the first over port 43 and the second over HTTPS, each trimmed to the lines that matter.

whois -h whois.verisign-grs.com example.com
Domain Name: EXAMPLE.COM / Registry Domain ID: 2336799_DOMAIN_COM-VRSN / Updated Date: 2026-08-14T08:01:43Z / Creation Date: 1995-08-14T04:00:00Z / Registry Expiry Date: 2027-08-13T04:00:00Z / Registrar: RESERVED-Internet Assigned Numbers Authority / Registrar IANA ID: 376 / Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited / Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited / Name Server: ELLIOTT.NS.CLOUDFLARE.COM / Name Server: HERA.NS.CLOUDFLARE.COM / DNSSEC: signedDelegation
curl -H 'accept: application/rdap+json' https://rdap.verisign.com/com/v1/domain/example.com
{ "objectClassName": "domain", "ldhName": "EXAMPLE.COM", "status": ["client delete prohibited", "client transfer prohibited", "client update prohibited"], "events": [{"eventAction": "registration", "eventDate": "1995-08-14T04:00:00Z"}, {"eventAction": "expiration", "eventDate": "2027-08-13T04:00:00Z"}, {"eventAction": "last changed", "eventDate": "2026-08-14T08:01:43Z"}], "entities": [{"objectClassName": "entity", "handle": "376", "roles": ["registrar"], "publicIds": [{"type": "IANA Registrar ID", "identifier": "376"}]}], "nameservers": [{"objectClassName": "nameserver", "ldhName": "ELLIOTT.NS.CLOUDFLARE.COM"}, {"objectClassName": "nameserver", "ldhName": "HERA.NS.CLOUDFLARE.COM"}], "secureDNS": {"delegationSigned": true} }
What to notice
The facts are identical: the same creation date, the same registrar ID, the same nameservers, the same locks. The WHOIS text uses labels such as Creation Date that another registry might call Created On or Registered; the RDAP record uses an events array whose eventAction is always registration. Status codes are spelled clientTransferProhibited in the text and client transfer prohibited in the JSON, and the JSON has no registrant block at all rather than a placeholder line.

What did not change

RDAP is a delivery mechanism, not a disclosure policy. It did not make redacted data public, and it did not standardise how much each registry chooses to publish. Redaction of registrant contact details has been the default for gTLDs since ICANN's Temporary Specification took effect on 25 May 2018, and that policy applies to both services equally. Two registries can both be fully compliant and return very different levels of detail.

The underlying facts are the same facts. Creation dates, registrars, statuses and nameservers were in WHOIS too. The gain is reliability of access, not new information.

And the split between names and numbers is unchanged. Domain registries answer for domains; the five regional internet registries answer for IP addresses and autonomous system numbers, and they run RDAP too. ARIN describes its service as an HTTP-based REST-style protocol with responses in JSON, in contrast to the text-based port 43 protocol it still runs alongside.

What still uses WHOIS: country-code coverage

The transition was driven by contractual requirements on generic endings. Country-code registries make their own arrangements, and the result is three groups. Some are listed in the IANA bootstrap file and behave like a gTLD. Some run an RDAP service but have not asked IANA to list it, so a client that trusts the bootstrap alone will miss them. And some publish no RDAP at all, offering only port 43 WHOIS or a web form, sometimes with a captcha.

The table shows where a handful of large endings stood when the bootstrap file published on 16 September 2026 was checked, together with each registry's own description of its service. Coverage changes, so check the file before relying on this.

EndingIn IANA bootstrapWhere the record lives
.ukYesrdap.nominet.uk; Nominet's RDAP serves multiple registry operators' endings
.frYesrdap.nic.fr
.nlYesrdap.sidn.nl
.brYesrdap.registro.br
.caYesrdap.ca.fury.ca/rdap
.auYesrdap.cctld.au/rdap
.deNordap.denic.de, which DENIC describes as test operation; port 43 WHOIS continues
.ch and .liNordap.nic.ch; anonymous users see no holder or technical contact
A registry can run RDAP without a bootstrap entry, and RFC 9224 itself says there is no guarantee an object will have one. rdap.org keeps a list of all known RDAP servers, including unlisted ones, and redirects a query to the right place.

Reading tools and writing that still say WHOIS

The word persists, partly from habit and partly because many interfaces labelled WHOIS lookup are now RDAP clients underneath. ICANN's own lookup at lookup.icann.org is one of them. That is usually fine, and occasionally it hides something worth knowing.

The question worth asking of any registration tool is what it does when the answer is not a record. If it reports a timeout or a rate limit as not registered, it will tell you a name is available when it is merely unanswered, and that error survives into whatever you do next. A tool that reads WHOIS text for a country ending and RDAP JSON for a generic one is also parsing two very different things, and the WHOIS half will be the one that breaks quietly.

The command-line whois program has not gone away and remains the quickest way to query a country-code registry that offers nothing else. For a generic ending, though, the honest tool now speaks RDAP, and a whois command that still answers for .com is relaying a service nobody is obliged to maintain.

What this means for a lookalike investigation

A check that spans many endings will return a mixture of full RDAP records, records from services outside the bootstrap, port 43 text and outright gaps, and presenting that mixture honestly is part of the job. The checker on this site reads RDAP through the bootstrap and reports an ending it cannot reach as Unknown rather than as unregistered; how to read the record it returns, field by field, is covered in the RDAP guide.

Common questions

what is the difference between whois and rdap
WHOIS returns unstructured text over TCP port 43 in a layout each registry chose, with no standard way to find the server, no error codes and no authentication. RDAP returns JSON over HTTPS with named fields, an IANA bootstrap file for finding the right server, HTTP status codes, and optional authenticated access. The facts inside are largely the same.
is whois still available
For generic top-level domains, registries and registrars have not been required to run WHOIS since 28 January 2025, so any port 43 service still answering for .com or .org is a courtesy. Many country-code registries still run WHOIS, and some offer nothing else.
does rdap replace whois for all domains
Only for generic top-level domains under ICANN contract. Country-code registries decide for themselves: some are in the IANA bootstrap, some such as .de and .ch run RDAP outside it, and some publish no RDAP at all. The regional internet registries run RDAP for IP addresses and AS numbers.
why does rdap show less information than whois used to
It does not, on the same registry. Registrant contact details have been redacted by ICANN policy since 25 May 2018 in both services. RDAP simply says so in a structured notice, where WHOIS printed a placeholder line or nothing.
how do i look up a domain with rdap
Find the ending in the IANA bootstrap file at data.iana.org/rdap/dns.json, then request domain/<name> from the base URL it gives with an Accept header of application/rdap+json. Or use a client such as lookup.icann.org or client.rdap.org, which do the bootstrap step for you.

Sources and further reading

  1. ICANN: launching RDAP, sunsetting WHOIS (28 January 2025)
  2. ICANN: RDAP background and key dates
  3. ICANN: Registration Data Access Protocol (RDAP)
  4. ICANN: Temporary Specification for gTLD Registration Data
  5. RFC 3912: WHOIS protocol specification
  6. RFC 7480: HTTP usage in RDAP
  7. RFC 7481: Security services for RDAP
  8. RFC 9082: RDAP query format
  9. RFC 9083: JSON responses for RDAP
  10. RFC 9224: Finding the authoritative RDAP service
  11. IANA: RDAP bootstrap file for DNS
  12. IANA: Bootstrap Service Registry for Domain Name Space
  13. Verisign: RDAP record for example.com
  14. ARIN: Whois and RDAP
  15. Nominet: RDAP terms of service
  16. DENIC: RDAP service for .de
  17. DENIC: whois service for .de
  18. SWITCH: RDAP for .ch and .li
  19. About RDAP.org
  20. ICANN Lookup
  21. Wikipedia: Registration Data Access Protocol
  22. Typosquatting.ai: RDAP explained
  23. Typosquatting.ai: methodology and data sources

Keep reading in Domain intelligence