What the WHOIS record tells you
| Field | Why it matters |
|---|---|
| Created | Domain age - very new domains are a common phishing signal |
| Expires | Forgetting to renew can take a site and its email offline |
| Registrar | The company the domain was bought through - and where to report abuse |
| Name servers | Who runs the DNS - often reveals the hosting or CDN provider |
| Status | Locks against transfer or deletion, or problems like "redemption period" |
Checking if a website is legit
Domain age is one of the strongest quick signals.
Real shops and banks have domains that are years old. Scam shops and phishing pages usually use domains registered days or weeks ago.
Combine the WHOIS age with the URL Scanner and the SSL Checker for a fuller picture.
Frequently asked questions
What is a WHOIS lookup?
WHOIS shows the public registration record of a domain: the registrar, when it was registered, when it expires, its name servers and its status. This tool uses RDAP, the modern standard that replaced classic WHOIS.
Why is the owner's name hidden?
Since GDPR in 2018, most registrars hide personal contact details. You usually see only the registrar and an abuse contact. To reach the owner, use the registrar's contact form.
How can WHOIS help spot a scam site?
Look at the registration date. A "bank" or "big shop" whose domain was registered a few days ago is a classic sign of phishing. ScanWith flags domains younger than 30 days.
How do I report an abusive domain?
Send the evidence to the registrar's abuse email shown in the results. For phishing, also report the link to Google Safe Browsing and your email provider.
Why does my domain show "client transfer prohibited"?
That is a normal lock set by your registrar to stop unauthorised transfers. It is a good thing - unlock it only when you intend to move the domain.