Registration data is a starting point
Registration data can identify the sponsoring registrar, domain status and registration events. RDAP provides structured, machine-readable results and has replaced WHOIS as the definitive source for generic top-level domain registration information. Country-code registries can have different access arrangements.
A registration date tells you when a recorded registration event occurred. It does not establish when a business began, who created a website, or whether the same operator has held the domain continuously. Treat update dates carefully: routine changes can produce an update event.
When the registrant is redacted
Public registration records may omit personal information because of privacy rules or use a proxy contact. Redaction and privacy services are common for legitimate domains and are not evidence of criminal activity.
Use the registrar’s abuse contact for substantiated abuse reports. Where a lawful investigation requires nonpublic registration data, follow the applicable registrar, registry or disclosure procedure. Do not substitute assumptions about the privacy provider for the identity of the operator.
Preserving the response
Keep the raw JSON response, source endpoint and timestamp alongside extracted fields. An empty field can mean redacted, not supplied or unavailable; those states should not be conflated.
- Distinguish registration, expiration and last-changed events.
- Record registry and registrar roles separately.
- Corroborate contact claims with independent evidence.
- Keep original responses so later changes can be assessed.
