All tools

Domain tool

Whois Lookup

کسی بھی ڈومین کی رجسٹریشن، expiry اور nameservers معلوم کریں

WHOIS (and RDAP) reveals who registered a domain, which registrar sold it, creation and expiry dates, and nameservers. Personal data is often redacted for privacy, but you can still verify ownership flow and DNS delegation for .pk, .com, and other TLDs.

ProtocolRDAPTLDs.pk · .com · 1500+

What Is a Whois Lookup?

Whois is a protocol used to query databases that store information about registered internet resources — primarily domain names and IP addresses. A Whois lookup reveals who owns a domain, when it was registered, when it expires, and which nameservers it uses.

Traditionally, Whois used a simple text-based protocol on port 43. Modern implementations use RDAP (Registration Data Access Protocol), which provides structured JSON responses and is the standard embraced by ICANN (Internet Corporation for Assigned Names and Numbers). SpeedTester.pk uses RDAP for more reliable and comprehensive data.

What You Can Learn from Whois

  • Registration Date: When was the domain first registered? Older domains often have more trust with search engines.
  • Expiry Date: When will the domain expire? Domains close to expiry may be available to purchase soon.
  • Registrar: Which company manages the domain registration (e.g., GoDaddy, Namecheap, PKNIC).
  • Nameservers: Which DNS servers are authoritative for the domain — tells you about hosting provider.
  • Domain Status: Statuses like "clientTransferProhibited" indicate locked domains that cannot be transferred.

Pakistani Domain Registration (.pk)

Pakistani domains under the .pk TLD are managed by PKNIC (Pakistan Network Information Centre). The .pk namespace includes popular sub-domains like .com.pk for commercial entities, .org.pk for organizations, .net.pk for network providers, .edu.pk for educational institutions, and .gov.pk for government bodies.

To register a .pk domain, you must provide a local presence in Pakistan or a legitimate Pakistani business registration in some cases. International domain extensions (.com, .net, .io, etc.) can be registered through international registrars without restrictions.

The complete guide

Everything you need to know

WHOIS is the public record office of the internet. Behind every domain name — google.com, ptcl.com.pk, your nephew’s blog — there is a registration record showing who registered it, when, with which registrar, when it expires, and which nameservers it currently points to. The tool above queries that record in seconds and translates it into plain English. This guide is the most complete walkthrough we could write about WHOIS, RDAP and domain ownership in Pakistan in 2026: how the registration system works, why .pk domains run through PKNIC and follow different rules from .com or .net, what GDPR redaction hid and what it left visible, how to use WHOIS for due diligence before buying a domain, how to spot a phishing or trademark-squatting attempt, what to do when your domain is hijacked, and the full lifecycle from registration to expiry to redemption to drop. By the end you will read a WHOIS panel like a domain investor reads a contract.

14 min read3,136 words20 sectionsUpdated May 2026
01

Foundations

What WHOIS actually is — the public registry of every domain

Every time someone registers a domain — example.com, mybusiness.pk, anything — a record is created in a database run by the registry that operates that top-level domain (TLD). For .com that registry is Verisign. For .pk it is PKNIC. For .org it is the Public Interest Registry. The record contains who registered it, through which registrar (GoDaddy, Namecheap, PKNIC retail, etc.), when, when it expires, and which nameservers handle DNS for it.

WHOIS is the protocol that lets the public read those records. It dates from the early 1980s — RFC 812 in 1982, RFC 920 in 1984 — and was originally a plain text query: send a domain name on TCP port 43, get back a text record. Forty years later the protocol is the same, but the data behind it has been profoundly reshaped by privacy laws and a modern replacement called RDAP.

When you query a domain in the panel above, our service contacts the appropriate registry, parses the response into structured fields, and presents them with explanations. For .pk domains we query PKNIC; for gTLDs we query through the registrar of record; for ccTLDs we use the relevant national registry.

  • Every TLD has a registry that maintains the master record for its domains.
  • WHOIS is the protocol used to read those records publicly.
  • Each registrar adds a customer-facing layer on top of the registry record.
  • Our tool unifies all of this into one panel.
A→ 93.184.216.34AAAA→ 2606:2800::1CNAME→ www.example.comMX→ mail.example.com (10)NS→ ns1.example.comTXT→ v=spf1 include:_spf.google.com
02

History

From WHOIS to RDAP: how the protocol modernised

WHOIS was a beautiful 1980s artefact: TCP port 43, send a string, receive a string. It worked because the early internet was a small academic community where everyone knew everyone. As the network commercialised, the limitations became obvious — no encryption, no standard format, every registry returned slightly different fields, and no authentication for differentiated access.

RDAP — the Registration Data Access Protocol — was finalised in 2015 (RFCs 7480–7484) as the modern replacement. It runs over HTTPS, returns structured JSON, supports internationalised domain names natively, allows authenticated queries for tiered access, and conforms to a uniform schema across all registries. ICANN required all gTLD registries to support RDAP by 2019.

Today both protocols coexist. WHOIS is still the lingua franca for ccTLDs and quick command-line lookups; RDAP is the engine behind modern panels (including ours) because it returns clean, parseable data. PKNIC supports WHOIS today and RDAP rollout is in progress.

..com.pk.org
03

Players

Registry, registrar, registrant — three R’s, three roles

Three parties touch every domain. The registry operates the central database for an entire TLD — Verisign runs .com, PKNIC runs .pk, Identity Digital runs .info, and so on. Registries do not sell to the public; they sell to registrars in bulk.

The registrar is the customer-facing seller. GoDaddy, Namecheap, Cloudflare Registrar, Google Domains (now Squarespace), and locally PKNIC retail itself, Hostbreak, Webzone, and others. The registrar collects your details, holds the relationship, and forwards instructions to the registry over a protocol called EPP.

The registrant is you — the person or organisation listed as the legal owner of the domain. When WHOIS shows ‘Registrant Name: John Doe’, that is the registrant. There are also separate Admin, Tech and Billing contacts, though most modern registrars use the same person for all four.

  • Registry: operates the TLD database (one per TLD).
  • Registrar: sells domains to the public (many per TLD).
  • Registrant: the legal owner of the specific domain.
  • EPP: the protocol registrars use to talk to registries.
300sTTL
04

.pk

.pk domains and PKNIC — the rules that are different here

PKNIC is the registry for all .pk domains and their second-level variants — .com.pk, .org.pk, .net.pk, .edu.pk, .gov.pk and others. It is operated under contract from the Pakistan government and follows policies that differ in several practical ways from gTLDs.

.pk domains historically required documentary verification (CNIC for individuals, business registration for companies) and the fee structure used a two-year minimum. Recent policy updates have streamlined this, but the rules are still stricter than .com — for example, .gov.pk and .edu.pk are restricted to verifiable government and educational entities only.

Premium and trademarked names are pre-reserved. The .pk WHOIS, while often less detailed than gTLDs, still shows registrar, status, dates and nameservers — the essentials for diagnosing a domain’s health.

CLIENTRESOLVERQUERYANSWER
05

GDPR

The 2018 redaction — what GDPR removed and what it kept

Until 2018, public WHOIS for most gTLDs returned full registrant contact information — name, email, phone, postal address. The GDPR forced ICANN to redact personal data for European registrants by default; in practice almost every registrar chose to redact globally rather than maintain two policies. As a result, most modern WHOIS records for .com, .net, .org and similar show ‘REDACTED FOR PRIVACY’ in the contact fields.

What is still public: registration date, expiry date, last update date, registrar name, domain status codes, and nameservers. That is enough to verify legitimacy, plan migrations, and detect imminent expiry — which is what most of us actually need WHOIS for.

ccTLDs make their own decisions. .pk WHOIS retains more detail for business registrants; .uk redacts heavily; .de essentially blocks public contact data. The tool above shows whichever fields the relevant registry chose to publish.

BrowserOperating systemHome routerISP resolverAuthoritative
06

Privacy

WHOIS privacy services and proxy registrations

Even outside GDPR, registrars sell WHOIS privacy as an add-on. Instead of your name and address, the public record shows the privacy provider’s details — typically WhoisGuard (Namecheap), Domains by Proxy (GoDaddy), or Cloudflare’s free service. Your real identity is held by the registrar and only revealed via legal process.

For most personal sites and small businesses, privacy protection is a no-brainer — it stops scrapers, spam, and stalkers without affecting any legitimate use. For corporate brand protection or trust-sensitive use cases (banks, government suppliers), public registration is sometimes preferred precisely because it demonstrates accountability.

Cloudflare Registrar is notable for including privacy free at cost-price registration. PKNIC does not currently offer a built-in privacy service for .pk; many registrants there list a business address by default.

DNS
07

Lifecycle

The domain lifecycle — registration to drop, day by day

A domain’s life follows predictable stages. Active: registered and resolving normally; expiry date in the future. Auto-renew grace (~30 days after expiry for most gTLDs): registrar may try to auto-renew; domain often still resolves. Redemption period (30 more days): domain stops working, owner can still recover for a hefty fee (usually $80–200 plus the renewal cost). Pending delete (5 days): final waiting period.

After pending delete, the name drops back into the public pool and anyone can register it again. Premium drop-catching services (DropCatch, SnapNames, NameJet) compete to grab valuable names within milliseconds of release. For .pk, the timeline differs — PKNIC publishes its own grace and deletion schedule, generally more lenient.

Knowing where in the lifecycle a domain sits is the first thing to check before buying or migrating. The status field in the WHOIS panel tells you immediately.

  • Active → Expired → Grace → Redemption → Pending Delete → Available.
  • Recovery during redemption costs significantly more than renewal.
  • Drop-catching is a competitive market for valuable expired names.
  • .pk has its own (generally more lenient) timeline.
10MXprimary20MXbackup30MXfallback
08

Status Codes

EPP status codes — what clientHold, transferProhibited and friends mean

WHOIS shows one or more status codes for every domain. They look cryptic but each one is actionable. ‘ok’ or ‘active’ means everything is normal. ‘clientTransferProhibited’ means your registrar has set a transfer lock — good for security, must be removed before changing registrars.

‘clientHold’ or ‘serverHold’ means the registry has stopped publishing the domain in DNS — typical for unpaid renewals, abuse complaints, or court orders. ‘pendingDelete’ means the domain is heading for the drop pool. ‘pendingTransfer’ means a registrar change is in progress and needs the auth code from the gaining side.

Understanding these codes turns ‘why doesn’t my site work?’ into ‘the registrar suspended the domain because of a billing issue’ in two minutes. Always check status codes first when a domain stops resolving.

$ dig speedtester.pk A +short104.21.45.211172.67.140.183$ dig speedtester.pk MX;; ANSWER SECTION:speedtester.pk. 3600 IN MX 10 mail.proton.ch$ dig +trace google.com; <<>> DiG 9.18.18 <<>>status: NOERROR ✓
09

Transfers

Auth codes and registrar transfers in practice

Moving a domain between registrars uses the EPP transfer protocol. The losing registrar generates an auth code (also called EPP code or transfer secret) and shares it with the registrant. The gaining registrar accepts the code, charges the renewal, and the registry processes the transfer — usually with a five to seven day automated approval window.

Common gotchas: clientTransferProhibited must be off, the domain must be at least 60 days past registration or last transfer, contact email must be reachable for confirmation messages, and DNSSEC keys must be removed and re-added at the new registrar to avoid validation failures during the gap.

For .pk transfers between PKNIC-authorised resellers, the process is similar but often involves manual approval steps and identity verification. Plan transfers at least two weeks ahead of any critical event.

DOH · DOT · DNSSEC
10

Due Diligence

Using WHOIS for domain due diligence before purchase

Before buying a domain — whether at auction or from a private seller — WHOIS is your friend. Check the registration date: very new domains sold at premium prices are often dropped junk re-registered hoping to fool buyers. Check the registrar: reputable, easy-to-transfer registrars are safer than obscure resellers.

Check the expiry date: a name that expires next month is one renewal cycle away from leaving the seller’s hands; you want at least a year of runway. Check the historical registrant where possible (DomainTools, Whoisology) — a domain that has cycled through ten owners in five years carries more SEO baggage than a long-held one.

And always do a trademark search alongside the WHOIS check. A domain that incorporates someone else’s brand can be claimed back through UDRP or court action no matter how much you paid for it.

  • Verify registration age, registrar, and expiry runway.
  • Pull historical registrant data when stakes are high.
  • Cross-check with trademark databases.
  • Use escrow services (Escrow.com, Sedo) for any meaningful purchase.
RESPONSE · MSCloudflare22msGoogle38msQuad931msOpenDNS44msPTCL62msJazz58msZong71ms
11

Hijacks

Domain hijacking — prevention, detection, recovery

Domain hijacking is when an attacker gains control of a domain you own — typically by compromising your registrar account email, social-engineering customer support, or stealing the auth code. The damage can be catastrophic: email rerouted, traffic stolen, brand reputation destroyed.

Prevention is mostly registrar hygiene. Use a unique, long password and a hardware key or TOTP for the registrar account. Keep the contact email on a domain you control (never an account on the domain itself — circular dependency). Enable Registrar Lock (clientTransferProhibited and clientUpdateProhibited). For high-value names, ask the registrar about Registry Lock — a manual hold that requires phone confirmation to unlock.

Detection is daily monitoring. Subscribe to domain status alerts; many registrars and third-party services email you any time a record changes. Recovery, if it happens, is a race: file with ICANN’s Transfer Dispute Resolution Policy, contact both registrars immediately, and prepare evidence of ownership.

ISBLHRFSDMULKHIPEWQTA
12

DNSSEC

DNSSEC delegations visible in WHOIS

When DNSSEC is enabled on a domain, the registrar uploads DS (Delegation Signer) records to the registry, which publishes them. The DS records appear in WHOIS and RDAP responses and form the trust anchor that lets validating resolvers verify your DNS responses cryptographically.

Seeing a DS record in WHOIS confirms DNSSEC is active. Its absence is silent — DNSSEC simply doesn’t protect that domain. If you turn on DNSSEC at your DNS provider but the DS record never appears in WHOIS, the chain is broken and validators will treat your responses as untrusted (resulting in resolution failures for users on validating resolvers like 1.1.1.1).

When transferring a DNSSEC-signed domain between registrars, plan to disable DNSSEC at the losing registrar a week before the transfer, transfer, then re-enable at the new registrar with new DS records. Skipping this step is the most common cause of post-transfer outages.

13

Premium

Premium domains, aftermarket prices, and reading historical WHOIS

The premium domain aftermarket is a multi-billion-dollar industry. Short, dictionary, brandable names sell for hundreds to millions. Sedo, Afternic, Dan, GoDaddy Auctions and Atom (formerly Squadhelp) are the largest marketplaces. For .pk, the secondary market is smaller but active for short and city-name domains.

WHOIS history (DomainTools, Whoxy, Whoisology) shows every time the registrant changed and lets you trace ownership chains. This is gold for trademark enforcement, brand protection, and avoiding re-purchasing a name with abuse history.

When evaluating an aftermarket purchase, combine WHOIS history with archive.org snapshots and Majestic/Ahrefs backlink data. A clean history with steady traffic and quality backlinks justifies a premium; a history of spam, parking, and adult content does not.

A→ 93.184.216.34AAAA→ 2606:2800::1CNAME→ www.example.comMX→ mail.example.com (10)NS→ ns1.example.comTXT→ v=spf1 include:_spf.google.com
14

Pakistan Use Cases

Real Pakistani WHOIS scenarios — banks, brands, freelancers

Pakistani banks use WHOIS to monitor look-alike domains (hbi-bank.com, alfaIah.com — note the I instead of l). Brand-protection services (MarkMonitor, Corsearch) automate this at scale, but a small business can do the same manually with weekly WHOIS checks.

Freelancers and agencies in Pakistan often manage 50+ client domains. A WHOIS audit (registrar, expiry, lock status, contact email) once a quarter prevents the embarrassment of a client’s domain expiring on your watch — by far the most common cause of involuntary client-relationship damage.

Government and educational institutions on .gov.pk and .edu.pk have stricter policies. Renewals must come from verified institutional accounts; transfers between registrars require additional documentation. Plan further ahead than for commercial domains.

..com.pk.org
15

Phishing

Spotting phishing and look-alike domains via WHOIS

Phishing kits depend on freshly-registered look-alike domains: hbI-pk.com (capital I), pa.ystdr.com, b1zz-pakistan.org. WHOIS gives you instant red flags. A domain registered in the last 30 days that mimics a brand, registered through a privacy proxy, with a free email contact, is overwhelmingly likely to be malicious.

Anti-fraud teams at banks and large e-commerce sites use scripts that monitor newly-registered domains containing brand keywords and check WHOIS metadata for risk signals. The output goes into takedown queues that contact registrars and hosting providers within hours.

For individual users, the rule of thumb is simple: when an email or SMS asks you to log in via an unfamiliar URL, copy the domain into the panel above. If it was registered yesterday and is privacy-proxied, you have your answer.

300sTTL
16

Bulk

Bulk WHOIS, monitoring, and APIs for portfolio holders

If you hold a portfolio of domains — for branding, defensive registrations, or speculation — manual checks do not scale. Tools like DomainTools, WhoisXML API, Whoxy and our own /api/whois endpoint let you query hundreds of domains programmatically and feed the results into a spreadsheet or alerting system.

Common alerts: 30-day expiry warning, transfer-prohibited unset (potential hijack precursor), nameserver change (potential DNS hijack), DNSSEC DS record removed. Each of these is a sign that something needs human attention before damage spreads.

Rate-limit etiquette matters. Registries publish acceptable-use limits — generally a few queries per second per source IP — and aggressive scraping triggers temporary blocks. Use APIs that already cache results rather than hammering port 43 directly.

BrowserOperating systemHome routerISP resolverAuthoritative
18

Tools

Going further: dig, whois CLI, RDAP, archive.org

The classic command-line whois tool is bundled with macOS and Linux and downloadable for Windows. ‘whois example.com’ returns the raw record. For RDAP, curl https://rdap.org/domain/example.com returns clean JSON. Both are zero-cost ways to get the same data the panel above uses.

DomainTools, Whoxy, ViewDNS and SecurityTrails offer historical WHOIS — invaluable for due diligence and abuse investigation. archive.org’s Wayback Machine pairs perfectly with WHOIS history for understanding how a domain was used over time.

For developers, our /api/whois endpoint returns structured JSON for any domain we support and is rate-limited per IP per hour. Free for individual use, contact for bulk.

DNS
19

Future

What changes in 2026 and beyond — RDAP-only, tiered access, AI abuse

ICANN is moving toward RDAP-only over the next few years, with WHOIS port 43 eventually being deprecated for gTLDs. The data stays the same; the protocol becomes uniform JSON over HTTPS with proper internationalisation. Registries on legacy WHOIS will support both for a long transition period.

Tiered access — where verified law enforcement and security researchers get more detailed contact data than the general public — is being prototyped (the Standardised System for Access and Disclosure, SSAD). Implementation is slow but likely arrives in some form mid-decade.

On the threat side, AI-generated phishing kits register thousands of look-alike domains per day. Defensive monitoring tools are evolving accordingly, with NLP models flagging brand-similar names automatically and feeding takedown queues continuously.

10MXprimary20MXbackup30MXfallback
20

Playbook

Putting it all together — your 2026 WHOIS playbook

For owners: lock every domain (Registrar Lock and, for high-value, Registry Lock), enable DNSSEC, use a contact email on a separate domain you also control, set 90-day expiry alerts, and audit your portfolio quarterly with the panel above or our API.

For investigators: combine current WHOIS with historical WHOIS and Wayback snapshots. Cross-reference with DNS records, MX hosts, and IP geolocation for a full picture. Build a checklist and re-use it.

For everyone: when in doubt about a URL, paste it into the panel above before clicking anything. A 24-hour-old privacy-proxied domain claiming to be your bank is almost certainly not your bank.

  • Lock + DNSSEC + safe contact email = 99% of hijack risk gone.
  • Quarterly portfolio audit catches expiries before they bite.
  • Combine WHOIS, history, Wayback for any serious investigation.
  • Trust the panel above before you trust the email.

Questions, answered

Frequently asked questions

Why is so much information ‘REDACTED FOR PRIVACY’?

Since 2018, GDPR forced registries and registrars to redact personal contact data by default for gTLDs. Operational data — registrar, status, dates, nameservers — is still public, which is enough for most checks.

2018 کے بعد GDPR کی وجہ سے ذاتی رابطہ معلومات چھپا دی گئی ہیں۔ رجسٹرار، اسٹیٹس اور تاریخیں اب بھی public ہیں۔

How do I find out who owns a redacted domain?

For legitimate purposes, contact the registrar listed in the WHOIS — they can forward a message to the registrant. For legal matters, courts and law enforcement can compel the registrar to release the data. There is no public way to bypass redaction.

رجسٹرار کے ذریعے پیغام بھیجا جا سکتا ہے۔ قانونی معاملات میں عدالت یا FIA رجسٹرار سے معلومات لے سکتی ہے۔

Why does my .pk WHOIS look different from .com WHOIS?

Because PKNIC is the registry for .pk and follows its own format and policies. The fields and field names differ from gTLD registries, but the meaning — registrar, status, expiry, nameservers — is the same.

PKNIC .pk کا رجسٹری چلاتا ہے اور اپنا فارمیٹ استعمال کرتا ہے۔ مطلب وہی ہے، صرف فیلڈز کے نام مختلف ہیں۔

What does ‘clientTransferProhibited’ mean?

It is a registrar-level lock that prevents the domain from being transferred to another registrar without first being unlocked. It is good security and should be on by default; turn it off only when you actually want to transfer.

یہ رجسٹرار کا lock ہے جو غیر مجاز ٹرانسفر روکتا ہے۔ یہ آن رہنا چاہیے، صرف ٹرانسفر کے وقت آف کریں۔

How do I transfer my domain to a new registrar?

Unlock the domain at the current registrar, request the EPP auth code, and start the transfer at the new registrar with that code. The transfer is usually approved within five to seven days. Plan around DNSSEC if enabled.

موجودہ رجسٹرار سے lock ہٹائیں، EPP کوڈ لیں، نئے رجسٹرار پر منتقلی شروع کریں۔ 5–7 دن میں مکمل ہو جاتی ہے۔

What happens when a domain expires?

First a 30-day auto-renew grace, then a 30-day redemption period (recoverable for an extra fee), then 5 days pending delete, then it drops back to public availability. Always renew before expiry to avoid the redemption fee.

پہلے 30 دن grace، پھر 30 دن redemption (اضافی فیس کے ساتھ بحالی)، پھر 5 دن pending delete، پھر دوبارہ پبلک۔

Should I buy WHOIS privacy?

For personal sites and small businesses, yes — it stops scrapers, spam and stalkers. For brand-trust-sensitive uses (banks, suppliers to government), public registration sometimes signals more accountability. Cloudflare Registrar includes privacy free.

ذاتی سائٹس کے لیے ہاں، یہ سپام اور سکریپرز سے بچاتی ہے۔ بینکوں اور بڑے اداروں کے لیے کبھی public بہتر ہوتی ہے۔

Can I trust the WHOIS data I see above?

Yes — we query the authoritative registry or registrar in real time and only show what they publish. Cached results are short-lived. If a field is missing, the registry simply chose not to publish it.

جی ہاں — ہم اصل رجسٹری سے براہ راست ڈیٹا لیتے ہیں۔ غائب فیلڈز کو رجسٹری نے خود شائع نہیں کیا ہوتا۔