Query Domains and IPs Safely with whois

Run whois against a domain or IP and it guesses a sensible server for you, but every query still leaves your terminal for a third party. The installed package here is whois 5.5.22. WHOIS is a plain-text directory protocol, not an encrypted privacy boundary, so treat every query as information sent to a third-party server.

You need a Linux shell, the whois package, and network access to a WHOIS service. No administrator privileges are needed for ordinary lookups. Allow about five minutes for a first query, or longer if you need to identify a registry-specific option. Results, disclaimers and referral behaviour vary between registries, so use the commands below to check the local client rather than relying on a remembered output sample.

1. Confirm the client

Check the installed version and supported options:

whois --version
whois --help

On this system the version check reports Version 5.5.22.. The help output includes --host, --port, --no-recursion, --verbose and -I. The final option first asks whois.iana.org and follows its referral, which also means IANA receives the complete query: do not use it for a sensitive object without deciding that exposure is acceptable.

2. Run a normal lookup

Query a domain that you intend to disclose to a public directory:

whois example.com

The client tries to guess the appropriate server from the object. A domain response commonly contains registrar, status, dates and nameserver fields, but the exact layout is controlled by the remote service. Some servers print a legal disclaimer before the record. Add -H when you want to hide those disclaimers:

whois -H example.com

For a quick local check that does not contact a server, use whois --version again. A failed lookup is not proof that the domain is unregistered: the server may be unavailable, the object may need a different syntax, or a registry may restrict access.

3. Query an IP address deliberately

Pass an address and inspect the network record returned by the service:

whois 192.0.2.10

The documentation says that this client uses whois.arin.net when it cannot make a better guess for an IPv4 address or network name. For an explicit destination, set the host yourself:

whois --host whois.example.net 192.0.2.10

Replace the example host with a real WHOIS service documented by the relevant registry. Do not copy an address from an untrusted page and assume it is authoritative. --host changes where the query goes; it does not make the answer authoritative by itself.

4. Control referrals and server selection

Domain services often refer a registrar or another server. The default client can follow such referrals, while --no-recursion disables recursion from a registry to registrar servers:

whois --no-recursion example.com

Use this when you specifically need the first server's record or want to limit the number of services contacted. The related -R flag is a server-side RIPE option that requests the local copy of a domain object rather than following a referral. RIPE options are not universal, and the manpage warns that options intended for RIPE-like servers may be ignored by other services.

5. Use whois.conf for a narrow exception

The client normally consults its built-in rules. If /etc/whois.conf exists, it reads that file first and tries each query against a matching server before applying those normal rules. Each non-comment line has a case-insensitive object pattern followed by a server name, separated by spaces or tabs. With POSIX regular-expression support, the pattern is an extended regular expression. IDNs must use their ASCII-compatible encoding, such as an ACE form beginning xn--.

Changing /etc/whois.conf requires elevated privileges and changes routing for every user on the machine. Before editing, make a recoverable backup:

sudo cp -p /etc/whois.conf /etc/whois.conf.backup

If the file does not exist, create it with a root editor and add only the rule you need:

sudoedit /etc/whois.conf
\.nz$             nz.whois-servers.net
# Korean IDN TLD
\.xn--3e0b707e$   whois.kr

Test the matching object immediately, then check the file if the result looks wrong:

whois example.nz
sudo sed -n '1,80p' /etc/whois.conf

Do not add a broad pattern merely to make one lookup work: a mistaken regular expression can send unrelated queries to the wrong service.

Recovery: to undo this example, remove only the added lines with sudoedit. If you created the file solely for the test, restore the backup with sudo cp -p /etc/whois.conf.backup /etc/whois.conf, or remove the newly created configuration after checking the target carefully with sudo rm -- /etc/whois.conf. That last command is destructive and should only be used when you have confirmed that no other user depends on the file.

6. Pass server-specific options safely

Options such as -T, -i and -s are mainly understood by RIPE-like services. For example, a type restriction can be sent to a known RIPE service:

whois --host whois.ripe.net -T inetnum 192.0.2.0

When a server-specific query begins with text that could be interpreted as a client option, put -- before the query string. This marks the beginning of the object passed to the remote service:

whois --host whois.ripe.net -- '-T inetnum 192.0.2.0'

Use the server's own documentation to confirm its syntax. The client does not validate that a remote server supports every flag.

Common traps and failure modes

Done means