Visible data since the GDPR
WHOIS is a public query protocol used to retrieve a domain’s registration data: the responsible registrar, creation and expiry date, and formerly also the name and contact details of the domain owner. Since the GDPR came into force in 2018, most registrars hide personal owner data of European domain holders by default or show only an anonymised privacy-proxy entry; the registrar and registration date, however, usually remain visible.
What usually remains visible is a useful remainder: the registration date, the date of the last change, the expiry date, the registrar’s name, the registered name servers and the domain’s status codes. Technically, WHOIS is increasingly being replaced by RDAP, a more modern protocol with structured responses and tiered access rights. For consumers the substance of the information stays the same.
German domains are a special case: since 2018 the registry DENIC has no longer published owner data in open lookups. For .de domains you will therefore usually only learn the technical key facts. That is current practice and no indication of concealment. An anonymous .de WHOIS record is therefore no ground for suspicion against the domain owner.
Use for checking a shop
For checking a shop, WHOIS is nonetheless useful: the domain’s creation date (see Domain Age) can be read from it, as can red flags such as a registrar frequently associated with bulk registrations or domain parking, or an expiry date coming up shortly for a supposedly established shop.
It is revealing to compare the record with what the shop claims about itself. An example: the site advertises “your specialist retailer since 2009”, the domain was registered seven weeks ago according to WHOIS, the certificate is equally young, and the name servers belong to a cheap hosting provider abroad. Each item on its own could be explained. Together they contradict the self-presentation so clearly that paying in advance is out of the question.
The opposite case occurs as well: a domain has existed for many years but, according to WHOIS, was transferred to another registrar only recently and has freshly changed name servers. That is a typical pattern after a change of owner or after an expired domain was taken over. The good reputation of the old content is then used for something different. A look at a web archive shows what used to sit at the address.
Running a query needs no expertise. Almost every registrar offers a WHOIS search box, and the registries themselves operate RDAP interfaces that deliver the same data in structured form. Enter the bare domain, without “https://”, without “www.” and without a path. Subdomains have no record of their own; what counts is always the registered domain itself.
Technical details and archive data
The name servers reveal who runs the address technically. If several suspicious shops share the same, not widely used name servers, that points to a common operator or at least to the same kit. Consumers can rarely verify this directly, but it explains why fake shops often resemble one another right down to the layout.
The status codes are worth a look as well. Entries such as “clientHold” mean the registrar has taken the domain out of service. That is a clear indication that complaints have already been made. “pendingDelete” signals a domain shortly before expiry. Neither fits a shop that is demanding advance payment at the same time and promising delivery next week.
Historical data closes the gap that data protection leaves behind. Archive services store older WHOIS snapshots and earlier versions of websites. Anyone wanting to see whether a domain used to belong to someone else or hosted something different will often get further that way than through the current query, especially with old domains carrying new, suspicious content.
Limits of the lookup
WHOIS has limits. It says nothing about who runs the shop, who processes the orders or where the money goes. It supplies technical key data and points in time. That makes it a fast, free counter-check against the claims made on the page. It is not an investigative tool.
An anonymised WHOIS entry is not, in itself, a fraud signal. Many legitimate domain owners in the EU also use a privacy service for data-protection reasons. WHOIS only becomes meaningful in combination with other features such as a very young domain, a legal notice that does not match the registrant’s country, or an expiry date only weeks away.