Technology
WHOIS Intelligence for Online Enforcement
WHOIS and RDAP records still show the registrar, nameservers, dates and status of a pirate domain even when the owner is redacted, which is often enough to route a complaint and place a domain in its history.
WHOIS is the long-standing lookup service for domain registration data. For years it was the first stop in any piracy investigation: query the domain, find the registrant's name and email, and see what else they had registered. That approach has largely stopped working. Privacy and proxy services became routine, and data protection rules led registries and registrars to redact personal data from public output for most generic top-level domains. Analysts who still use WHOIS to find owners are usually disappointed. Analysts who use it to find routes and timelines still get a great deal from it.
What a redacted record still shows
Even a heavily redacted record usually contains:
- The registrar and its published abuse contact, which tells you who can act on the domain itself and where a complaint should go.
- Nameservers, which show which DNS provider serves the domain and often reveal a reverse proxy or a particular hosting company.
- Creation, update and expiry dates. A site claiming years of history on a domain created last week is a replacement. An update that coincides with a known blocking order suggests a response to it.
- Status codes. Hold statuses mean the domain has been suspended; transfer and delete prohibitions show what has been locked, and by whom.
- Registrant country or organisation, where the registrar chooses to show them, and the name of any privacy service in use.
Country-code domains follow their own rules. Some registries publish more, some publish less, and some release anything beyond the basics only on a formal request.
WHOIS and RDAP
RDAP, the Registration Data Access Protocol, is the structured successor to the old text-based WHOIS service. It returns the same core data as JSON over HTTPS, with consistent field names and references to the registrar's own record. For automated collection this is a real improvement. Parsing free-text WHOIS output from many registrars, each with its own layout and quirks, was a steady source of errors. A modern collection pipeline queries RDAP where it is available and falls back to WHOIS where it is not, storing the raw response alongside the parsed fields.
History beats the current snapshot
The current record of a pirate domain is often the least informative one. Historical registration data, collected over time by the investigator or by specialist providers, can show the period before a privacy service was added, an email address that was briefly exposed, an organisation name that appeared and then vanished, or the moment the domain changed registrar after a suspension.
Reverse lookups work on that history. An email address or organisation found in an old record can be searched across other domains' historical records to find related registrations. The results need care: an address belonging to a web design agency or a domain reseller may sit on large numbers of unrelated domains.
Routing a complaint to the right desk
The most common practical use of registration data in enforcement is routing. Infringing content on a site is usually raised with the hosting provider first. When the host does not respond, or the site sits behind a proxy that conceals the host, the registrar becomes relevant. Some registrars act on clear evidence that a domain is dedicated to large-scale infringement. Many decline, treating content as a matter for the host or the courts. Practice varies by registrar and by jurisdiction, and a complaint that reaches the right abuse desk with complete, time-stamped evidence fares better than one sent to a general inbox.
Where the registrant's identity is genuinely needed, for instance to support legal action, the route is a disclosure request to the registrar or registry, or formal legal process. Each has its own requirements, and none guarantees an answer.
Reading a record without over-reading it
Registration data is easy to over-interpret. A privacy service is shared by enormous numbers of customers, so two domains using the same one are not thereby related. A reseller account may register domains for many unconnected clients. Expired domains are picked up by strangers, so a record from before the expiry describes a different holder. Domains bought on the secondary market inherit nothing from the previous owner except the name.
The safe practice is to store every registration fact with the time it was observed and the source it came from, and to weigh it alongside hosting, page and account evidence rather than as proof on its own. That kind of correlation is the core of OSINT investigation. The notices that follow, addressed to hosts, registrars and platforms, are part of content protection.
- Domain Intelligence
- Technology


