Bulk WHOIS / RDAP Lookup (Domain Portfolio Audit)
Registrar, dates and locks of every domain in a portfolio — in one sortable table.
Free preview.
- Free preview: the summary counts of every domain, with the first half of the table (up to 10 rows) and its findings; a single domain is shown with its results hidden.
- Locked until you unlock it: download and copy.
- Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews. Batch runs unlock with a pass only.
Ways to unlock shows how to get the full result.
Printing this result is locked in the free preview.
Domains to look up
Registration data
- 0Registered
- 0Expired or ending
- 0Expire within 30 days
- 0Within 31–90 days
- 0No transfer lock
- 0Not registered
- 0Failed or no RDAP
| Findings | Status | Nameservers |
|---|
Dates are the registry’s, in UTC. With a pass, Copy and CSV take the rows shown, in the order shown. Contact details are never shown or exported, even where a registry publishes them.
Locked in the free preview. Opens the ways to unlock this result.
Locked in the free preview. Batch runs unlock with a pass.
Locked in the free preview. Query results unlock with a pass.
About the Bulk WHOIS / RDAP Lookup (Domain Portfolio Audit)
Paste a list of domains — a portfolio export from your registrar, a spreadsheet column or a few hundred names — and get each one’s registrar, creation, last-change and expiry dates, status codes, nameservers and DNSSEC straight from the official registry over RDAP, the structured successor of WHOIS. The results land in a sortable, filterable table with an audit of what needs attention: domains that have expired or expire soon, are in a grace or redemption period, are on hold, have no nameservers or have no transfer lock.
The lookups go from your browser to each registry, four at a time and at most two at a time per registry, and a registry that asks to slow down is retried after a pause. Contact data is never shown or exported — not even where a registry publishes it — so the table and the CSV contain no personal data.
How to use it
- Paste up to 300 domains, one per line or separated by commas, or load a .txt or .csv file. From a table with a heading row, such as a registrar’s CSV export, only the column headed Domain (or Domain name, Host, URL…) is read, so nameservers and contact addresses in the other columns are not taken for domains. URLs, e-mail addresses and subdomains are reduced to the registered domain, and duplicates are removed.
- Press Look up all. The table fills in as the registries answer.
- Use the filters — Expiring within 90 days, Needs attention, Not registered, Failed — or type a registrar or a domain into the filter box; select a column heading to sort by it.
- Press Retry failed for lookups that did not finish, then, with a Premium pass, Download CSV or Copy table to paste the rows shown into a spreadsheet.
Examples
google.com
Registered · MarkMonitor Inc. (IANA ID 292) · created 1997-09-15 · expires 2028-09-14 Registrar locks: transfer, update, delete · Registry locks: transfer, update, delete ns1.google.com ns2.google.com ns3.google.com +1 more · DNSSEC: not signed
Verisign, the .com registry, names the registrar and holds the dates, status codes and nameservers, so one lookup per domain is enough.
example-shop.com example-shop.net example-shop.in
example-shop.com — Expires in 12 days. example-shop.net — No transfer lock: ask the registrar to turn on its transfer lock (clientTransferProhibited) against hijacking. example-shop.in — Nothing to flag
old-campaign.example
In redemption: The registrar has deleted the domain; only the current owner can still restore it, usually for a fee.
Common uses
- Auditing a company’s or a client’s domain portfolio before renewals: what expires when, at which registrar, and which domains lack a transfer lock.
- Consolidating domains held at several registrars into one renewal list.
- Checking a list of brand or typo domains to see which are registered and which are still available.
- Due diligence before buying a business or a domain portfolio.
What each column means
- Registrar: the accredited registrar the registry names for the domain, with its IANA ID for generic TLDs.
- Created, Last changed, Expires: the registry’s registration, last changed and expiration events, as UTC dates. The days left count from now.
- Status: the EPP status codes as RDAP reports them (RFC 8056). The registrar’s locks (
client … prohibited) and the registry’s (server … prohibited) are grouped; grace periods, holds and pending deletion are named. - Nameservers: the delegation the registry publishes; none means the domain does not resolve.
- DNSSEC: whether the registry holds a DS record, so validating resolvers can detect forged answers.
- Findings: expiry within 30 or 90 days, expired, auto-renew grace period, redemption or pending deletion, on hold, no nameservers, and no transfer lock (checked for generic TLDs only, because many country-code registries do not use these status codes).
How the lookups work
IANA’s bootstrap files map each top-level domain that has an RDAP service to the server responsible for it (RFC 9224); each domain is then asked for at domain/<name> (RFC 9082) and the JSON answer (RFC 9083) is read defensively. The same code powers the single-domain WHOIS Lookup, including its checked additions for country-code TLDs that run RDAP but are missing from the bootstrap.
Most registries accept requests from web pages, so the lookups run in your browser and spread across the registries. The few that do not are asked through MySmartCoPilot’s server, which only contacts the registries the bootstrap (or the WHOIS Lookup’s checked additions) names, and allows a limited number of such lookups per hour.
No personal data in the results
RDAP records can contain contact entities — registrant, administrative, technical, billing and abuse contacts with names, postal addresses, e-mail addresses and phone numbers. Most are redacted under privacy rules such as ICANN’s Registration Data Policy, but some registries still publish them. This tool keeps only the registrar’s name and IANA ID from the entities and drops everything else before anything is shown, copied or exported. For a single domain’s contacts and abuse desk, use the WHOIS Lookup or the Abuse Contact Finder.
Limitations
- Up to 300 domains in one run. Registries limit how many lookups they answer from one address: a registry that keeps answering HTTP 429 is retried three times with growing pauses, then the row is marked so you can retry it later.
- Top-level domains without an RDAP service listed by IANA — .co and .eu, for example — cannot be looked up from a web page; their rows say so. Classic WHOIS (port 43) cannot be reached from a browser.
- Some country-code registries publish no expiry date or do not use the EPP status codes, so their rows show fewer details.
- Lookups that go through MySmartCoPilot’s server count against an hourly limit; when it is reached, the remaining domains of those registries fail with a message saying when to try again.
- The dates are the registry’s. A registrar may show its own expiry date, for example during an auto-renew grace period; the registrar’s control panel is the final word for your own domains.
Privacy
Domain names are sent from your browser to IANA’s bootstrap service and to each domain’s registry RDAP server, without cookies; those servers see your IP address and the names you look up. Registries that refuse browser requests are asked through MySmartCoPilot’s server, which does not store lookups; its log records only the registry’s host name and the status code. Nothing is saved in your browser, and no contact data is shown or exported.
Frequently asked questions
What do I get without a pass?
Without a pass, Bulk WHOIS / RDAP Lookup (Domain Portfolio Audit) shows the summary counts of every domain, with the first half of the table (up to 10 rows) and its findings; a single domain is shown with its results hidden. Until you unlock it, the result can’t be downloaded or copied. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.
How many domains can I look up at once?
Up to 300 per run. For a longer list, run it in parts: the page tells you how many were left out and which one comes next. Lookups run four at a time and at most two at a time per registry, so how long a run takes depends on how quickly each registry answers.
Why are there no owner names, e-mail addresses or phone numbers?
On purpose. Registration records can contain personal data, so this tool keeps only the registrar, dates, status codes, nameservers and DNSSEC, and never shows or exports contacts — even when a registry publishes them. To reach a domain’s owner or abuse desk, open the single WHOIS Lookup, which shows the registrar’s contact form when there is one.
What is the difference between WHOIS and RDAP?
Both publish registration data. WHOIS is free-form text on port 43, which web pages cannot reach; RDAP is structured JSON over HTTPS with standard status codes and a bootstrap that finds the right server automatically. ICANN requires generic-TLD registries and registrars to run RDAP, so it is the reliable way to read the data in bulk.
Why does a domain show “No RDAP service”?
Its top-level domain has no RDAP server listed in IANA’s bootstrap files, so the registry data cannot be read from a web page. IANA’s root zone database names the registry and links to its website, where its own search may help.
What does “No transfer lock” mean?
Neither the registrar’s lock (clientTransferProhibited) nor the registry’s (serverTransferProhibited) is set, so the domain could be moved to another registrar with its authorisation code. Many registrars switch it on by default; if not, turn it on in the registrar’s control panel. The check is made only for generic TLDs such as .com, because many country-code registries handle transfers without these status codes.
Can I open the results in Excel or Google Sheets?
Yes, with a pass (in the free preview both are locked). Download CSV writes a UTF-8 file that Excel and Google Sheets open directly, with formula-like text neutralised. Copy table copies the rows shown as tab-separated text that pastes into separate cells.