How to Find Out Who Owns a Domain Name
Updated 11 September 2026 · 6 min read
There are plenty of legitimate reasons to find out who owns a domain. You might want to buy it, report abuse coming from it, check whether a business is real, or contact the owner about a trademark issue. The starting point is always the domain's registration record, but these days that record often won't show the owner's name.
This guide explains what registration lookups show, why so much of the data is hidden, how to contact an owner you can't identify, how to request hidden data through official channels, and what other clues can tell you who runs a site.
Step 1: Look up the registration record
Every registered domain has a record held by its registry and registrar. You can query it with:
- Our WHOIS Lookup, which shows the record in a readable format
- ICANN's lookup service at lookup.icann.org, for domains under generic top-level domains such as
.com,.organd.net
Behind these tools are two protocols. WHOIS is the original, text-based one. RDAP, the Registration Data Access Protocol, is its structured replacement, and ICANN requires registries and registrars for generic top-level domains to support it.
A registration record typically includes:
- Registrar: the company the domain was registered through
- Registrant: the person or organization that holds the domain, when shown
- Dates: creation, expiration and last update
- Nameservers: where the domain's DNS is hosted
- Status codes: such as
clientTransferProhibited, which is a normal lock against unauthorized transfers - Registrar abuse contact: an email address and phone number for reporting abuse
Why the owner's details are often hidden
If you look up a random domain today, there's a good chance the registrant's name, address and email say something like REDACTED FOR PRIVACY, or show the name of a privacy service instead of the owner.
There are two reasons:
- Data protection law. Since the EU's General Data Protection Regulation took effect in 2018, most registrars redact personal data from public records by default, and many apply this worldwide, not just to European customers.
- Privacy and proxy services. Many registrars offer a service that replaces the owner's details with the service's own contact information. This is legal and common.
Organizations sometimes still appear by name, particularly when a company registered the domain and chose to publish its details. But you should expect redaction for individuals and small businesses.
Hidden details aren't a sign that a site is suspicious. Most people simply don't want their home address in a public database.
Step 2: Contact the owner through the registrar
Redaction doesn't make an owner unreachable. Most registrars provide a way to reach the registrant without revealing their details:
- A web contact form, often linked from the registrar's own lookup page
- An anonymized email address shown in the record, which forwards to the owner
If you want to buy the domain, this is the polite first step. Keep the message short: who you are, which domain, and what you're asking. Many owners won't answer unsolicited offers, so don't read too much into silence.
If the domain is listed for sale, the record or the website itself may show a marketplace or broker. For purchases, use an escrow service rather than paying a stranger directly.
Step 3: Use the abuse contact for abuse only
For generic top-level domains, registrars must publish an abuse contact. Use it to report:
- Phishing or fraud
- Malware distribution
- Spam
- Other illegal activity involving the domain
When you report, include specifics: the full URLs, what happened, when, and any evidence such as email headers or screenshots. A clear report is far more likely to get action.
The abuse contact is not the place for purchase inquiries, general complaints about content you disagree with, or requests for the owner's identity.
Step 4: Request nonpublic data if you have a legitimate reason
If you have a legitimate interest in the hidden details, for example in a legal matter, a cybersecurity investigation or an intellectual property dispute, there are formal ways to ask.
ICANN operates the Registration Data Request Service (RDRS), which lets people with a legitimate interest submit requests for nonpublic registration data for generic top-level domains to participating registrars. You can find it on ICANN's website. Keep in mind:
- Not every registrar participates.
- A request isn't a guarantee of disclosure. The registrar decides based on the request and applicable law.
- Some requests, such as those from law enforcement, typically go through separate channels.
For trademark disputes, the Uniform Domain-Name Dispute-Resolution Policy (UDRP) provides a process for complaints about domains registered in bad faith. That's a legal route, usually handled with a lawyer.
For country-code domains like .uk, .de or .pk, the registry sets its own rules on what's published and how to request more. Check the registry's website for its policy.
Other clues about who runs a site
Registration data is only one source. Often the site itself, its DNS and its SSL certificate tell you more.
The website
Start with the obvious places:
- Contact, About and Team pages
- The privacy policy, which in many jurisdictions has to name the organization responsible for collecting personal data
- Terms of service, which often name the operating company
- An imprint page, required for many businesses in Germany and some other countries
- The footer, which may include a company name, registration number or address
DNS records
DNS records show which services a domain uses. Run the domain through our DNS Lookup and look at:
- NS records: which DNS or hosting provider manages the domain
- MX records: which email provider it uses, such as a business email service or the host's own mail server
- TXT records: verification records for services like search consoles, email platforms and marketing tools, plus SPF records listing authorized email senders
A domain with business email set up and several verified services is almost certainly an active organization. A domain with no MX records and default nameservers may be parked. Our DNS records explained guide covers what each record means.
The SSL certificate
Certificates come in validation levels:
- Domain Validated (DV) certificates only prove control of the domain. They don't include an organization name.
- Organization Validated (OV) and Extended Validation (EV) certificates include the verified name of the organization, and often its location.
If a site uses an OV or EV certificate, the organization field tells you who the certificate authority verified. Check it with our SSL Checker. Many legitimate sites use DV certificates, so the absence of an organization name proves nothing.
An example walkthrough
Say you're considering buying example-garden.com, and the lookup shows everything redacted.
- Registration lookup: the registrar is listed, the creation date is 2014, and the registrant fields say
REDACTED FOR PRIVACY. There's a link to the registrar's contact form. - Website: the domain shows a parked page with a "This domain may be for sale" notice and a marketplace link.
- DNS: the nameservers belong to a parking service, and there are no MX records, so there's no business email running on it.
- Decision: the domain is parked and listed for sale. Use the marketplace listing, or send a short message through the registrar's contact form, and complete any purchase through escrow.
If instead the site had been an active store with a named company in its privacy policy and an OV certificate showing the same company, you'd already have your answer without the registration record at all.
What not to do
- Don't harass owners or use abuse channels to pressure them into selling.
- Don't assume privacy means wrongdoing. Redaction is the default for most registrations.
- Don't trust third-party "owner" data blindly. Some sites display old or scraped records that may be years out of date.
The short version
Start with a WHOIS or RDAP lookup. If the owner's details are redacted, contact them through the registrar's form or anonymized email, use the abuse contact only for real abuse, and use formal channels like RDRS or UDRP when you have a legitimate legal need. Then look at the website itself, its DNS records and its SSL certificate, which often reveal more about who's behind a domain than the registration record does. For the timeline side of the same research, see how to check domain age.