Docs/APIs/WHOIS Lookup

WHOIS Lookup

Lookup domain registration

OperationalCredits 8 per callp50 1552msDomain DataStar

Overview

WHOIS Lookup is a domain WHOIS API: it queries the registry for a domain name and returns its registration record (registrar, creation, update and expiry dates, EPP status codes and authoritative nameservers) plus domain age computed from the creation date. Paid plans extend it to IP address and ASN WHOIS.

Live Test WHOIS Lookup API →

Endpoint

One host, one path per API. The block below shows this call in four languages; every one of them is the same HTTP request. Making requests covers the timeouts, retries and parameter rules that apply to all of them. The SDKs wrap the same call in a typed client.

GEThttps://api.apiverve.com/v1/whoislookup
curl "https://api.apiverve.com/v1/whoislookup?domain=myspace.com" \
  -H "x-api-key: your_api_key_here"

Replace your_api_key_here with the key from your dashboard. When the inputs arrive as a list rather than one at a time, batch requests run up to 200 of them through this same API in a single call.

Authentication

Send your key in the x-api-key header. That is the only auth step — there is no token exchange and no per-endpoint scope to configure. Authentication covers creating, rotating and revoking keys.

401 is the only auth verdict

A 401 means the key is missing, invalid or expired. A 403 means the key is valid but not permitted here — blocked by a key restriction or an IP allow-list. Running out of credits is a 429.

Parameters

Sent in the query string. Premium parameters are accepted on every plan but only take effect on plans that include them.

ParameterTypeDescription
domainRequiredstringThe domain name for which you want to get the registration data (e.g., myspace.com)
domain

Response

Every API returns the same three top-level keys, so one response handler covers your whole integration: status, error and data. Only data changes shape. Response format covers the envelope, the other output formats and how premium fields are withheld.

Sample response
{
  "status": "ok",
  "error": null,
  "data": {
    "domainName": "MYSPACE.COM",
    "registryDomainID": "3877095_DOMAIN_COM-VRSN",
    "createdDate": "1996-02-22T05:00:00Z",
    "expiryDate": "2029-02-23T05:00:00Z",
    "updatedDate": "2023-01-17T00:16:21Z",
    "domainStatus": [
      "client delete prohibited https://icann.org/epp#client delete prohibited",
      "client renew prohibited https://icann.org/epp#client renew prohibited",
      "client transfer prohibited https://icann.org/epp#client transfer prohibited",
      "client update prohibited https://icann.org/epp#client update prohibited"
    ],
    "dNSSEC": "unsigned",
    "registrar": "GoDaddy.com, LLC",
    "registrarIANAID": "146",
    "registrarURL": "http://www.godaddy.com",
    "registrarAbuseContactEmail": "[email protected]",
    "registrarAbuseContactPhone": "tel:480-624-2505",
    "nameServers": [
      "ns-cloud-a2.googledomains.com",
      "ns-cloud-a3.googledomains.com",
      "ns-cloud-a4.googledomains.com",
      "ns-cloud-a1.googledomains.com"
    ],
    "domain": "myspace.com",
    "fetchedAtUTC": "2025-12-17T01:54:05.069Z",
    "tld": "com",
    "status": "active",
    "domainAgeDays": 11094,
    "domainAgeYears": 30.4,
    "isRecentlyRegistered": false,
    "trustScore": 93,
    "trustLevel": "high"
  }
}

Response fields

Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.

FieldTypeExampleDescription
domainNamestring"MYSPACE.COM"The domain name in uppercase format
registryDomainIDPremiumstring"3877095_DOMAIN_COM-VRSN"Unique registry identifier for the domain
createdDatestring"1996-02-22T05:00:00Z"Domain creation date in ISO 8601 format
expiryDatestring"2029-02-23T05:00:00Z"Domain expiration date in ISO 8601 format
updatedDatestring"2023-01-17T00:16:21Z"Domain last updated date in ISO 8601 format
domainStatusarray[client delete prohibited https://icann.org/epp#client delete prohibited, ...]Array of domain status flags with EPP codes
dNSSECPremiumstring"unsigned"DNSSEC status (signed or unsigned)
registrarstring"GoDaddy.com, LLC"Domain registrar company name
registrarIANAIDPremiumstring"146"Registrar's IANA ID number
registrarURLstring"http://www.godaddy.com"Registrar's website URL
registrarAbuseContactEmailPremiumstring"[email protected]"Registrar abuse contact email address
registrarAbuseContactPhonePremiumstring"tel:480-624-2505"Registrar abuse contact phone number
nameServersarray[ns-cloud-a2.googledomains.com, ...]Array of authoritative nameserver hostnames
domainstring"myspace.com"Domain name in lowercase format
fetchedAtUTCPremiumstring"2025-12-17T01:54:05.069Z"When this record was fetched from the registry (ISO 8601); cached for up to 24 hours
tldstring"com"Top-level domain extension
statusstring"active"Current domain registration status
domainAgeDaysnumber11094Age of the domain in days, derived from the creation date
domainAgeYearsnumber30.4Age of the domain in years (one decimal), derived from the creation date
isRecentlyRegisteredPremiumbooleanfalseWhether the domain was registered within the last 90 days — a common fraud/phishing signal
trustScorePremiumnumber930-100 trust score derived from domain age, registration recency, expiry runway and DNSSEC
trustLevelPremiumstring"high"Categorical trust level (low, medium, high) derived from the trust score

Errors

Read the HTTP status first, then error for the specific reason. The body names the parameter that has to change. Error handling covers the full status list and which of them are worth retrying.

StatusMeaningWhat to do
400Input was rejectedRead error; it names the parameter.
401Key missing or invalidCheck the header name and the key value.
403Key valid, but not permittedA key restriction or IP allow-list; see key scoping.
429Rate limited, or out of creditsRead error to tell them apart; see rate limits.

Start from a template

A working app built on this API, ready to deploy with your own key. Vercel asks for the key when you deploy; the code is on GitHub to change first.

Use cases

Expiration Monitoring
Domain portfolio managers inspect expiration dates and registrar details to schedule timely renewals before web properties lapse or drop.
Phishing Detection
Security teams flag newly created sender domains during user onboarding by reading domain age in days directly from the registration record.
Trademark Infringement Review
When auditing suspicious brand lookalikes, legal specialists identify the sponsoring registrar and nameserver hosts to route takedown notices accurately.
Vendor Infrastructure Auditing
Evaluate third-party vendor websites by verifying active domain status codes, current registration timelines, and authoritative nameserver delegations.

Other ways to use WHOIS Lookup

Set up WHOIS Lookup on APIVerve, or reach the same source a different way. Your APIVerve account and credits work on all of them — one key, one balance.

Give it to an AI agentConnect over MCP and your agent calls it as a native tool — Claude, Cursor, ChatGPT.VerveKit →Reference →
Google Sheets or ExcelA =VERVE() formula fills a column — no script, no export, recalculates in place.VerveSheets →Reference →
Ground an agent on itA cited, machine-checkable fact your model can't produce on its own.VerveContext →Reference →

More in Domain Data:

Was this page helpful?