Docs/APIs/WHOIS Lookup

WHOIS Lookup

Lookup domain registration

OperationalCredits 10 per callp50 1552msDomain DataStar

Overview

Whois Lookup works by querying the WHOIS database to retrieve the registration data of a domain name. It returns the domain owner's name, contact information, domain registrar, and more in a structured format.

Endpoint

One host, one path per API. The block below shows this call in four languages; every one of them is the same HTTP request. Making requests covers the timeouts, retries and parameter rules that apply to all of them. The SDKs wrap the same call in a typed client.

GEThttps://api.apiverve.com/v1/whoislookup
curl "https://api.apiverve.com/v1/whoislookup?domain=myspace.com" \
  -H "x-api-key: your_api_key_here"
const res = await fetch('https://api.apiverve.com/v1/whoislookup?domain=myspace.com', {
  headers: { 'x-api-key': 'your_api_key_here' },
});

if (!res.ok) throw new Error(`${res.status} ${await res.text()}`);

const { data } = await res.json();
console.log(data);
import requests

res = requests.get(
    "https://api.apiverve.com/v1/whoislookup?domain=myspace.com",
    headers={"x-api-key": "your_api_key_here"},
    timeout=15,
)
res.raise_for_status()

print(res.json()["data"])
package main

import (
	"fmt"
	"io"
	"net/http"
)

func main() {
	req, _ := http.NewRequest("GET", "https://api.apiverve.com/v1/whoislookup?domain=myspace.com", nil)
	req.Header.Set("x-api-key", "your_api_key_here")

	res, err := http.DefaultClient.Do(req)
	if err != nil {
		panic(err)
	}
	defer res.Body.Close()

	out, _ := io.ReadAll(res.Body)
	fmt.Println(string(out))
}

Replace your_api_key_here with the key from your dashboard. When the inputs arrive as a list rather than one at a time, batch requests run up to 200 of them through this same API in a single call.

Authentication

Send your key in the x-api-key header. That is the only auth step — there is no token exchange and no per-endpoint scope to configure. Authentication covers creating, rotating and revoking keys.

401 is the only auth verdict

A 401 means the key is missing, invalid or expired. A 403 means the key is valid but not permitted here — blocked by a key restriction or an IP allow-list. Running out of credits is a 429.

Parameters

Sent in the query string. Premium parameters are accepted on every plan but only take effect on plans that include them.

ParameterTypeDescription
domainRequiredstringThe domain name for which you want to get the registration data (e.g., myspace.com)
domain

Response

Every API returns the same three top-level keys, so one response handler covers your whole integration: status, error and data. Only data changes shape. Response format covers the envelope, the other output formats and how premium fields are withheld.

Sample response
{
  "status": "ok",
  "error": null,
  "data": {
    "domainName": "MYSPACE.COM",
    "registryDomainID": "3877095_DOMAIN_COM-VRSN",
    "createdDate": "1996-02-22T05:00:00Z",
    "expiryDate": "2029-02-23T05:00:00Z",
    "updatedDate": "2023-01-17T00:16:21Z",
    "domainStatus": [
      "client delete prohibited https://icann.org/epp#client delete prohibited",
      "client renew prohibited https://icann.org/epp#client renew prohibited",
      "client transfer prohibited https://icann.org/epp#client transfer prohibited",
      "client update prohibited https://icann.org/epp#client update prohibited"
    ],
    "dNSSEC": "unsigned",
    "registrar": "GoDaddy.com, LLC",
    "registrarIANAID": "146",
    "registrarURL": "http://www.godaddy.com",
    "registrarAbuseContactEmail": "abuse@godaddy.com",
    "registrarAbuseContactPhone": "tel:480-624-2505",
    "nameServers": [
      "ns-cloud-a2.googledomains.com",
      "ns-cloud-a3.googledomains.com",
      "ns-cloud-a4.googledomains.com",
      "ns-cloud-a1.googledomains.com"
    ],
    "domain": "myspace.com",
    "fetchedAtUTC": "2025-12-17T01:54:05.069Z",
    "tld": "com",
    "status": "active",
    "domainAgeDays": 11094,
    "domainAgeYears": 30.4,
    "isRecentlyRegistered": false,
    "trustScore": 93,
    "trustLevel": "high"
  }
}

Response fields

Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.

FieldTypeExampleDescription
domainNamestring"MYSPACE.COM"The domain name in uppercase format
registryDomainIDPremiumstring"3877095_DOMAIN_COM-VRSN"Unique registry identifier for the domain
createdDatestring"1996-02-22T05:00:00Z"Domain creation date in ISO 8601 format
expiryDatestring"2029-02-23T05:00:00Z"Domain expiration date in ISO 8601 format
updatedDatestring"2023-01-17T00:16:21Z"Domain last updated date in ISO 8601 format
domainStatusarray[client delete prohibited https://icann.org/epp#client delete prohibited, ...]Array of domain status flags with EPP codes
dNSSECPremiumstring"unsigned"DNSSEC status (signed or unsigned)
registrarstring"GoDaddy.com, LLC"Domain registrar company name
registrarIANAIDPremiumstring"146"Registrar's IANA ID number
registrarURLstring"http://www.godaddy.com"Registrar's website URL
registrarAbuseContactEmailPremiumstring"abuse@godaddy.com"Registrar abuse contact email address
registrarAbuseContactPhonePremiumstring"tel:480-624-2505"Registrar abuse contact phone number
nameServersarray[ns-cloud-a2.googledomains.com, ...]Array of authoritative nameserver hostnames
domainstring"myspace.com"Domain name in lowercase format
fetchedAtUTCPremiumstring"2025-12-17T01:54:05.069Z"Timestamp when WHOIS data was retrieved
tldstring"com"Top-level domain extension
statusstring"active"Current domain registration status
domainAgeDaysnumber11094Age of the domain in days, derived from the creation date
domainAgeYearsnumber30.4Age of the domain in years (one decimal), derived from the creation date
isRecentlyRegisteredPremiumbooleanfalseWhether the domain was registered within the last 90 days — a common fraud/phishing signal
trustScorePremiumnumber930-100 trust score derived from domain age, registration recency, expiry runway and DNSSEC
trustLevelPremiumstring"high"Categorical trust level (low, medium, high) derived from the trust score

Errors

Read the HTTP status first, then error for the specific reason. The body names the parameter that has to change. Error handling covers the full status list and which of them are worth retrying.

StatusMeaningWhat to do
400Input was rejectedRead error; it names the parameter.
401Key missing or invalidCheck the header name and the key value.
403Key valid, but not permittedA key restriction or IP allow-list; see key scoping.
429Rate limited, or out of creditsRead error to tell them apart; see rate limits.

Use cases

Domain Management
Use the Whois Lookup API to check domain registration data for domain management. Use the data to verify ownership, update contact information, and renew domains
Cybersecurity
Enhance cybersecurity by using the Whois Lookup API to check domain registration data. Use the data to identify suspicious domains, prevent fraud, and protect against cyber threats
Brand Protection
Protect your brand by using the Whois Lookup API to check domain registration data. Use the data to monitor domain registrations, detect trademark infringements, and enforce brand rights
Legal Compliance
Ensure legal compliance by using the Whois Lookup API to check domain registration data. Use the data to investigate domain disputes, resolve ownership issues, and comply with regulations

Other ways to use WHOIS Lookup

Set up WHOIS Lookup on APIVerve, or reach the same source a different way. Your APIVerve account and credits work on all of them — one key, one balance.

Give it to an AI agentConnect over MCP and your agent calls it as a native tool — Claude, Cursor, ChatGPT.VerveKitReference →
Use it in Google Sheets or ExcelA =VERVE() formula fills a column — no script, no export, recalculates in place.VerveSheetsReference →
Ground an agent on itA cited, machine-checkable fact your model can't produce on its own.VerveContextReference →

More in Domain Data:

Was this page helpful?