Lesson 1 of 1 in whois
The Filing Cabinet, Not the Machine
Everything whois tells you is what somebody typed on a form. That is its weakness and, occasionally, its whole value.
3 min read
Not yet reviewed
nmap, dig and ffuf all ask a machine a question and report what it says. whois is different in kind: it asks a registry, and the registry has never spoken to the server. Everything it returns is what somebody typed when they registered the name, plus whatever a registrar has been told since.
Note
Hold that distinction the whole way through this module. A whois record that disagrees with reality is not a broken record — it is a record, doing exactly what a record does, which is remembering the day it was written.
What is actually in there
Look up brightpath.example. Find out which registrar holds it and when it was first registered.
The disagreement is the finding
What the registry says
Name Server: ns1.oldhost.example
Name Server: ns2.oldhost.exampleWhat the machine says
The site resolves and is served somewhere else entirely.Somebody migrated hosting and never updated the registration. That tells you there was a migration, roughly when, and that whoever ran the old provider account may still exist — which is a thread, and threads are what reconnaissance produces.
What the dates are for
Creation Date how long this organisation has had this name
Updated Date when the record last changed - often a migration
Registry Expiry when somebody has to remember to renew it
- Line 1A domain registered last week and a domain registered in 2004 are very different propositions, and it is the fastest way to tell a business from something that appeared to look like one.
- Line 3The one that has ended companies. An expired domain can be registered by anybody, and it takes their email, their password resets and their published identity with it.
Take care
Redaction has changed what this tool is for. It used to name a person and frequently an address; now it usually names an organisation or nothing. Anybody teaching whois as a way to find a human being is describing an internet that mostly stopped existing — and if a record *does* still carry a person's details, treat that as somebody's mistake rather than as an invitation.
There is nothing to detect
This is the only module in this course with no defensive beat, and the absence is the point: a whois query goes to a registry, so the target learns nothing. There is no log entry, no alert to tune and no threshold to set.
The defensive work is entirely in what you publish. Check what your own records say, keep the registrant redacted, put an abuse address on it that somebody reads, and put the expiry date in a calendar owned by more than one person.
A whois record lists nameservers that do not match where the site is actually served. What is the most useful reading?