← NewsNews

RDAP Replaced WHOIS for gTLDs on 28 January 2025

Since 28 January 2025 RDAP is the definitive source of gTLD registration data and WHOIS is no longer required. What changed and what to check in your tooling.

Published: · 2 min read

Event date: 2025-01-28 · Source: ICANN Update: Launching RDAP; Sunsetting WHOIS, published 2025-01-27.

What happened

On 27 January 2025 ICANN announced that, as of 28 January 2025, the Registration Data Access Protocol (RDAP) is the definitive source for registration information about generic top-level domains, "in place of sunsetted WHOIS services". From that date, gTLD registries and ICANN-accredited registrars are no longer contractually obliged to run WHOIS, neither the port 43 service nor the web-based one. They have had to offer RDAP since 2019, so the two ran side by side for more than five years.

Nothing was switched off centrally on that day. The obligation ended; each registry and registrar decides for itself whether and how long it keeps a WHOIS server running.

Who is affected

  • gTLDs only: .com, .net, .org, .info and the new gTLDs such as .app or .xyz. Country-code TLDs (.de, .uk, .tr and the others) are not bound by ICANN contracts. Some run RDAP, some only WHOIS, some neither.
  • Anyone with scripts that parse WHOIS text: expiry monitors, brand-protection tools, registrar-migration scripts, abuse desks. A gTLD WHOIS server may stop answering, answer with a pointer to RDAP, or change its output without notice.
  • Ordinary domain owners: nothing to do. Your registration, your contact details and your privacy settings are the same; only the protocol used to read them has changed.

What to do

  1. Move gTLD lookups to RDAP. The answer is JSON over HTTPS with standardised field names, so the fragile per-registry text parsing disappears. Find the right server through the IANA bootstrap registry (RFC 9224) instead of hard-coding it:
$ curl -s https://data.iana.org/rdap/dns.json | head
$ curl -sL https://rdap.org/domain/example.com | jq '.status, .events'

rdap.org is a public redirector that does the bootstrap step for you.

  1. Expect redaction either way. RDAP does not reveal more personal data than WHOIS did. Non-public registrant data for gTLDs can be requested through ICANN's Registration Data Request Service (RDRS); the registrar decides on each request.
  2. Keep WHOIS as a fallback for ccTLDs, and treat "no answer" as "could not be checked". A failed lookup never means that a domain is free to register.
  3. Respect rate limits. RDAP servers answer with HTTP 429 when you query too fast; back off instead of retrying in a loop.
  4. Read the status values correctly: RDAP writes EPP status codes as words with spaces (client transfer prohibited for clientTransferProhibited).

How to check

The OrbitProbe WHOIS lookup queries RDAP directly and shows the registrar, dates, status codes and nameservers together with the server the answer came from. When registration data for an extension cannot be read, it says so instead of guessing. Whether a particular extension publishes RDAP at all is listed in the TLD directory.

Background

Sources