跳至主要內容

WHOIS 網域查詢

使用現代化 WHOIS 協定 RDAP,檢查是誰註冊了網域、何時到期、其名稱伺服器以及 DNSSEC 狀態。

查詢網域註冊詳細資訊

Try sample:

Data retrieved via Registration Data Access Protocol (RDAP) RFC 7480-7484. Under ICANN specifications and GDPR data protection regulations, personal registrant contact information is redacted by registries.

WHOIS:現代化為 RDAP

註冊資料可提供網域的註冊商、關鍵日期和名稱伺服器,這在您規劃轉移、追蹤到期日或審查網域時非常有用。此工具使用 RDAP,這是註冊局必須支援的結構化 JSON 協定,也是 port-43 WHOIS 的繼任者。

此工具為您提供

  • 網域的註冊商、註冊日期、最後變更日期和到期日期。
  • 名稱伺服器、網域狀態碼和 DNSSEC 簽署狀態。
  • 當網域看似未註冊且可能開放申請時,提供明確的提示。

EPP domain status codes reference

EPP (Extensible Provisioning Protocol) status codes define the administrative locks and operational state of a domain name across registrars and registries:

Status codeApplied byMeaning & security impact
clientTransferProhibitedRegistrarPrevents unauthorized transfer requests to another registrar (anti-hijacking lock).
clientUpdateProhibitedRegistrarLocks DNS nameservers and contact information from being modified without unlocking.
clientDeleteProhibitedRegistrarProtects the domain against accidental deletion requests.
serverHoldRegistrySuspends DNS resolution at the registry level (e.g. pending legal dispute or non-payment).
ok / activeRegistryStandard operational status with no pending actions or restrictions.

Domain & SSL requirements for venue WiFi captive portals

When configuring custom domains for guest WiFi splash pages and network access control (NAC), adhere to these best practices:

  • Dedicated Hostname: Delegate a dedicated subdomain (such as wifi.venue.com or guest.brand.com) via CNAME to your captive portal provider rather than using apex domains.
  • Automated TLS/SSL Provisioning: Ensure the domain has a valid, unexpired public SSL certificate signed by a trusted Certificate Authority (CA). Self-signed certificates cause instant browser security blocks on iOS and Android.
  • Authoritative DNS Resilience: Host your domain on redundant Anycast DNS nameservers to guarantee sub-millisecond captive portal resolution during peak venue footfall.
  • DNSSEC Integrity: Enable DNSSEC at your registrar to validate that guest login requests cannot be intercepted or spoofed by malicious local access points.

Frequently asked questions about WHOIS & RDAP

What is RDAP and how does it replace traditional port-43 WHOIS?

RDAP (Registration Data Access Protocol, RFC 7480-7484) is the standardized JSON-over-HTTPS protocol designed by the IETF and ICANN to succeed legacy port-43 WHOIS. Unlike unstructured plaintext WHOIS queries, RDAP provides machine-readable JSON responses, internationalized domain name (IDN) support, secure transport layer encryption (HTTPS), and standardized privacy redaction for GDPR compliance.

How do I check if a domain has DNSSEC enabled?

DNSSEC (Domain Name System Security Extensions) adds cryptographic signatures to DNS records to protect against DNS spoofing and cache poisoning. In this tool, the DNSSEC status queries the top-level domain (TLD) registry for active DS (Delegation Signer) records. A 'Signed' result indicates active cryptographic delegation.

What do EPP status codes like clientTransferProhibited and clientDeleteProhibited mean?

EPP (Extensible Provisioning Protocol) status codes indicate the operational and lock states of a domain name. Codes starting with 'client' (such as clientTransferProhibited, clientUpdateProhibited, and clientDeleteProhibited) are registrar-level security locks that prevent unauthorized transfers, domain hijacking, and accidental deletions.

Why are registrant personal contact details redacted in WHOIS lookups?

Under ICANN's Temporary Specification and global data protection laws (such as GDPR and CCPA), registries and registrars are legally mandated to redact personal identifying information - including registrant names, street addresses, and phone numbers - from public queries. Registrars provide anonymized web forms or privacy relays for legitimate technical inquiries.

Why is domain and DNS verification essential for guest WiFi captive portals?

Enterprise guest WiFi captive portals require fully qualified domain names (FQDNs) and valid SSL/TLS certificates (e.g. splash.yourvenue.com) to establish secure HTTPS connections without triggering browser security warnings or Apple/Android Captive Network Assistant (CNA) failures. Redundant authoritative nameservers and active DNSSEC prevent DNS resolution failures during guest login.

Standing up a new venue domain?

Captive portals, splash pages, and resident sign-up all need a domain and certificates that just work. Purple handles the hosting so you launch guest WiFi faster.

Book a 20-min demo
Free Desktop App

Netforge Network Multi-Tool

Run offline network health checks, path analysis, and latency diagnostic scans directly from your desktop.

Download Multi-Tool