WHOIS got retired, but RDAP doesn't talk to mortals
The internet was an open phonebook for 40 years, then GDPR closed it to the public. The phonebook is still there, more complete than ever. But if you want a peek, you will face serious challenges.
Back in May 1982, there were 235 hosts on ARPANET. Can you believe that this was the entire internet?
In the same year, an RFC showed up, the 812, “NICNAME/WHOIS”. The goal was that every person behind the host had to register personal data to identify themselves. This clearly was the phonebook of the internet.
All data could be looked up by anyone, anonymously, no limitations. The required data presented in a human-readable format included full name, US postal address, zip code, phone number, network mailbox.
However unbelievable it seems to us today, this was perfectly normal at the time. Those 235 host machines were owned by military and academic research networks. So every person belonged to an identifiable institution. Anonymity was not even a thing since there was nobody to be anonymous from.
The next round on the WHOIS protocol came in 2004. Leslie Daigle was the author of the new RFC 3912. What he did here was an as-is description of the WHOIS protocol, and added several pertinent security observations to it. He clearly stated that “The WHOIS protocol has no provisions for strong security. WHOIS lacks mechanisms for access control, integrity, and confidentiality.” The strongest statement was that “…a protocol like WHOIS would not normally be acceptable to the IETF at the time of this writing.” Thus, the phonebook got its first clear diagnosis.
The next major turn happened eight days before the GDPR act came into effect, on 17 May 2018. ICANN’s Board came out with the Temporary Specification. ICANN’s reasoning was that without this every registry would have made decisions on GDPR on their own. This Temp Spec introduced the redacted for privacy statement that applied to the registrant’s name, postal address, phone number. Their email address had to be anonymized, or a web form being provided instead of that.
What you probably didn’t know was that this Temp Spec applied to all domain registrations. It did not require registrars to differentiate between legal or natural persons. So company data disappeared too from the WHOIS, although GDPR did not require that.
Collecting the data however was reinforced, the Temp Spec stating “maintains robust collection of Registration Data”. The phonebook was still there, but it got closed.
WHOIS is dead, long live RDAP!
The successor of the WHOIS protocol was already there, waiting to replace it. Being defined in the RFC 7480, it got standardized in March 2015, and then became a full Internet Standard, STD 95, in 2021.
RDAP was a starship compared to WHOIS. It had HTTPS as its communication protocol, it had structured JSON data format as output, it had internationalization for wide adoption, and it also had the possibility for differentiated access levels to the data.
The gTLD registries and ICANN-accredited registrars have offered RDAP since 2019. And then, on 28 January 2025 RDAP became the authoritative source for gTLD registration data, and also from that day, registries and registrars are no longer required to run and offer WHOIS. The good old WHOIS has served us well for more than 40 years, and is now retired.
For data privacy however nothing changed. The redacted part even got its own RFC, the 9537, called “Redacted Fields in the RDAP Response”. With RDAP, the protocol even includes the right pathway for the access of data so even if you are not entitled to see it, it will show you how to get it.
The winners are clearly the domain name holders. And even companies, as GDPR didn’t cover them. Those who have lost something here are the trademark attorneys, law enforcement, consumer protection, journalists. The technical data of the domains is still available, however that is useful only for a handful.
An interesting project worth mentioning here is the Registration Data Request Service (RDRS) started by ICANN in November 2023, participation in it being optional. The two-year pilot project ended in November 2025, with conclusions. Quick balance: 3,721 requests, 13,701 registered requestors, 80 participating registrars, together about 46% of domains under management. Of 3,337 closed requests: 2,029 denied, 956 approved, 46 partially approved, 306 already public. Who asked: IP rights holders 1,202 (32.3%), law enforcement 605 (16.3%), consumer protection 258, scientific researchers 209, cybersecurity researchers 135, other 942 (25.3%). Top denial reason: “the contracted party cannot disclose due to applicable law” in 743 cases. So, the denial rate in closed cases was approx. 61%. After drawing the conclusions, the decision was to keep the project running for two more years until a long-term policy solution is being worked out.
For more than 40 the domain lookups were fully open like a phonebook. Anybody could see the data without a request or without a reason. What the request brought us: identified requestor, stated purpose, justification, balancing, decision, turnaround time.
In the times of the phonebook, the question was: what do we know about the domain name? The question completely changed since then. Now it looks like this: who are you to be allowed to know the data of the domain name?
Magyar változat: [zona.hu/a-whoist-nyugdijaztak-az-rdap-nem-all-szoba/]



