A snapshot, not a history

A public WHOIS, RDAP or DNS lookup reports the state of a domain at the moment it is queried. It is not a historical record: it cannot show what the registrant data said a year ago, what the nameservers were before the most recent change, or how many times a domain has been re-registered. Investigators who need that history must turn to a dedicated historical DNS or historical WHOIS dataset maintained by a specialist provider, understanding that such datasets have their own coverage gaps and are not a complete archive of every domain at every point in time.

What a registration or DNS report does not include

A standard public domain report returns what is published under the domain name itself, such as RDAP registration fields and DNS record types like A, AAAA, NS, MX and TXT. It does not perform a reverse IP lookup to enumerate other domains hosted on the same address, which requires either a specialist reverse-IP or passive DNS dataset or direct cooperation from the hosting provider. It also does not perform a reverse DNS (PTR) lookup of an arbitrary IP address, since that is a separate query against the in-addr.arpa or ip6.arpa zone for the address rather than a record published by the domain owner.

Email authentication evidence has a similar boundary: a domain report can retrieve and evaluate the SPF and DMARC TXT records published for a domain, and can confirm an MTA-STS policy if one is published, but it does not discover DKIM selectors, since there is no public, enumerable list of selectors a domain might use. Finding the DKIM selector actually used for a given message requires reading the DKIM-Signature header of that specific preserved email, which names the selector and signing domain directly.

Redaction, privacy services and jurisdiction

Since data protection rules such as the GDPR took effect, most generic top-level domain WHOIS and RDAP output omits personal registrant details or replaces them with a privacy or proxy service, regardless of whether the domain is used legitimately or abusively. Country-code top-level domains vary considerably in what they publish and through what access method, and some require a local presence or a stated legal basis to obtain even registrant country data. None of this is evidence of concealment on its own; it is the default state of the public record for the large majority of domains today.

Working within the limits

A sound investigation treats a public WHOIS, RDAP, DNS, certificate transparency and network RDAP report as one evidentiary layer among several, states plainly which questions it could not answer, and directs the investigator to the appropriate specialist source, historical DNS providers, reverse-IP or passive DNS datasets, the preserved email itself for DKIM, or a direct PTR query for an address, rather than guessing or treating an absence of data as a finding in itself.

  • Treat a lookup as a timestamped snapshot, not a history.
  • Use a dedicated historical DNS/WHOIS provider for change-over-time questions.
  • Use a specialist reverse-IP or passive DNS source to find co-hosted domains.
  • Read the DKIM-Signature header of the preserved email for selector and domain.
  • Query in-addr.arpa/ip6.arpa directly for PTR records of a specific IP.
  • Expect redaction on most WHOIS/RDAP records and do not treat it as suspicious alone.

Sources and further reading

ICANN, Registration Data Access ProtocolICANN, Registration data policyRFC 6376, DomainKeys Identified Mail (DKIM) SignaturesRFC 8461, SMTP MTA Strict Transport Security (MTA-STS)
This resource supports investigative triage. It is not legal advice, an attribution finding or a certification that a website is safe.