You can still learn a great deal about who is behind a website — but not the way guides written before 2018 describe it. A WHOIS lookup used to hand over the owner’s name, postal address, phone number and email. Privacy law changed that, and for most domains those fields now read “REDACTED FOR PRIVACY”. What remains is still enough to judge whether a site deserves your card details, if you know which signals to read.
What a WHOIS lookup still tells you
Since the GDPR took effect in 2018, registrars have withheld personal registrant details from public WHOIS results by default. The records that survive are the administrative ones, and they are the useful ones anyway:
| Field | What it tells you |
|---|---|
| Creation date | The single most useful field. A shop claiming twenty years in business on a domain registered five weeks ago has answered your question. |
| Expiry date | Domains registered for one year at a time are cheaper to abandon. Long registrations suggest intent to stay. |
| Registrar | Who sold the domain, and where a complaint would go. |
| Name servers | Which host or CDN the site runs on. |
| Status codes | Flags such as clientHold, which means the domain is suspended rather than merely broken. |
| Country | Often still present even when the name is redacted. |
ICANN runs the authoritative free lookup, and any registrar’s WHOIS page draws on the same registry data. Older articles that send you to a specific commercial WHOIS site are not pointing at better data — there is only one source, and the redaction applies to all of them equally.
Six checks that do more than WHOIS
1. Read the certificate, not just the padlock. Click the padlock in the address bar and view the certificate. A free domain-validated certificate proves only that someone controlled the domain, which is why scam sites have padlocks too. An organisation-validated certificate carries a verified company name — that is the one worth something.
2. Look the site up in the Wayback Machine. The Internet Archive shows what a site looked like over time. A shop with no history before last month, or one whose entire design and product line changed overnight, is telling you something a WHOIS record cannot.
3. Check the domain against Google Safe Browsing. Google publishes the current safety status of any site it has assessed. It will not catch everything, but it catches known phishing and malware hosts immediately.
4. Find the company, not the domain. A legitimate business selling to the public generally has a registration number somewhere on the site. Search that number in the relevant national company register. No number, no registered address and no phone is a stronger signal than anything in a WHOIS record.
5. Reverse image search the staff photos. The About page team of a fraudulent site is usually stock photography. One reverse image search settles it in seconds.
6. Read the reviews you did not find on the site. Testimonials hosted on a website prove nothing. Independent review platforms, and the absence of any mention anywhere, both carry more information.
How to look up hosting and technology
A DNS lookup resolves the domain to an IP address and shows the mail, name server and text records attached to it — useful for spotting when several suspicious sites share one host. Technology profilers read a page’s source and report the platform, analytics and payment tools behind it. Neither identifies a person, but a storefront running no recognised payment processor is worth pausing over.
What none of this can tell you
It is worth being clear about the limits. Redaction is the default now, so a hidden registrant name is normal and not itself a warning sign — most legitimate domains look exactly the same way. Privacy services are cheap and legal. A site can be registered years ago, carry a valid certificate, sit on reputable hosting and still be fraudulent, because all of those are things a determined operator can buy. Treat the checks as a way to rule sites out quickly, not to certify one as safe.
Frequently asked questions
Why does WHOIS not show the owner’s name any more?
Because of privacy regulation. Since the GDPR came into force in 2018, registrars redact personal registrant data from public WHOIS output by default, for domain holders worldwide rather than only in Europe.
Is there any way to see the redacted details?
Not publicly. Law enforcement and rights holders can request them through formal channels, and a registrar will forward a message to the owner without disclosing the address. Any service claiming to sell you current redacted registrant data should be treated with suspicion.
What is the fastest way to check whether a shopping site is genuine?
Look at the domain creation date and search for the company’s registration number. Those two take under a minute and eliminate most fraudulent storefronts, which are typically weeks old and legally anonymous.
Does a padlock mean a website is safe?
No. It means traffic to the site is encrypted, nothing more. Certificates are free and automated, so criminals use them as routinely as everyone else.
Can I find out who owns a website from its IP address?
You will find the hosting company, not the site owner. On shared hosting or behind a CDN, that address is common to thousands of unrelated sites.
How old should a website be before I trust it?
There is no threshold that makes a site safe, but age is a good filter: a very new domain making established-brand claims is contradicting itself, and that contradiction is the useful part.
Related reading
For the wider picture, see how to protect yourself from cybersecurity threats, a worked example in the USPS package tracking scam explained, and what to do when malware strikes your own website.


