Cybersecurity Lab
WHOIS Investigation Lab
A public registry investigation lab for understanding domain ownership signals, registration metadata, and privacy limits.
In Progress2026Beginner
Objective
Learn what WHOIS and RDAP can reveal, what privacy controls hide, and how to cite public registry data responsibly.
Tools Used
WHOISRDAPICANN LookupPublic registries
Steps Performed
- Looked up domain registration metadata from public sources.
- Compared WHOIS and RDAP output.
- Documented registrar, nameserver, date, and privacy observations.
Key Findings
- Registration privacy can limit direct ownership visibility.
- Registrar and nameserver patterns can still provide useful context.
- Registry data should be cited with lookup date and source.
Screenshots
WHOIS output
RDAP output
Investigation notes
Lessons Learned
- WHOIS investigation is useful for OSINT but has privacy and accuracy limits.
- Responsible reporting avoids exposing unnecessary personal data.
Future Improvements
- Create a privacy-aware reporting template.
- Compare historical domain data sources.
References
- ICANN Lookup
- RDAP documentation