You can look up domain ownership through a public database called WHOIS
Every website domain has an owner, and that information is stored in a public database you can search for free. The database is called WHOIS, and it lists the registrant's name, address, phone number, and email — though many owners hide this information behind a privacy service. A WHOIS lookup takes about two minutes and tells you whether the owner's details are public or masked.
The reason this information exists is that domain registrars (the companies that sell domain names) are required by internet governance rules to keep records of who owns each domain. When you register a domain, you provide your contact details to the registrar, and those details go into WHOIS unless you pay extra for privacy protection. This is why some domains show a real person's name and others show "Privacy Service" or the registrar's own details instead.
Key Takeaways
- WHOIS is a free public database where you can search any domain name and see who registered it, unless they paid for privacy protection.
- Most WHOIS lookups take less than two minutes and require only the domain name — you do not need to know anything else about the website.
- If the owner used privacy protection, you will see the registrar's details or a privacy service's details instead of the actual owner's information.
- Some registrars let you contact the owner through a forwarding email even when their details are hidden, though the owner can choose not to respond.
How to do a WHOIS lookup yourself
Go to whois.icann.org (the official WHOIS search run by ICANN, the organization that oversees domain names). Type the domain name into the search box — for example, "google.com" or "nytimes.com" — and click the search button. The results will appear in seconds.
You will see several fields: Registrant Name (the owner), Registrant Organization (if they registered under a business), Registrant Email, Registrant Phone, and Registrant Address. Below that are the same fields for the Administrative Contact and Technical Contact, which may be different people. If all these fields show "Privacy Service" or the registrar's name, the owner has paid to hide their information.
Other WHOIS search sites exist — whois.com, domaintools.com, and lookup.icann.org all work — but they show the same underlying data. Use whichever one loads fastest for you. The information is the same across all of them because they all pull from the same public database.
What to do when the owner's details are hidden
If the WHOIS results show "Privacy Service" or "Registrar" instead of a real name, the owner has paid for privacy protection (usually $5 to $10 per year). This is completely legal and very common. You cannot see their real details through WHOIS, but you have other options.
Many registrars offer a "contact owner" feature on their WHOIS page. If you see this option, you can send a message to the domain owner through the registrar, and the registrar will forward it to them. The owner can choose whether to reply, so there is no may provide they will respond. This is useful if you want to report a problem, ask about buying the domain, or request information about the website.
If there is no contact option, you can try looking for contact information on the website itself. Most websites have an "About Us" page, a "Contact" page, or a footer with an email address. This is often faster than trying to reach the domain owner through WHOIS anyway, because the person running the website may not be the same person who registered the domain.
Understanding what each WHOIS field means
Registrant is the person or organization that owns the domain. This is the legal owner. Administrative Contact is the person authorized to make changes to the domain (like renewing it or changing nameservers). Technical Contact is the person responsible for the domain's technical setup. On many domains, all three are the same person. On larger organizations' domains, they may be different people or departments.
The Registrar is the company where the domain was registered — for example, GoDaddy, Namecheap, or Google Domains. The registrar is not the owner; they are the company that sold the domain to the owner. The Creation Date and Expiration Date tell you when the domain was first registered and when it needs to be renewed. If the expiration date has passed, the domain may no longer be active.
Nameservers are the computers that point the domain name to the actual website. If you see nameservers listed, they tell you which company is hosting the website's files (though not always — some hosting companies use the registrar's nameservers). This information is technical and usually not useful unless you are trying to troubleshoot why a website is not loading.
Why some owners hide their information
Domain privacy protection exists because WHOIS data is public and searchable. Without it, anyone can find your home address, phone number, and email by typing your domain name into a search box. People use privacy protection for the same reasons they use unlisted phone numbers: to avoid spam, harassment, or unwanted contact.
Businesses sometimes hide their information for competitive reasons — they do not want competitors to know who is behind a domain. Individuals often hide it for safety. Privacy protection does not make a domain suspicious; it is a normal privacy choice. However, some people use it to hide fraudulent activity, so if you are investigating a suspicious website, hidden WHOIS information is one warning sign among many.
When WHOIS information is outdated or wrong
WHOIS data is only as current as the domain owner keeps it. If someone registered a domain five years ago and moved since then, the address in WHOIS will still be the old one. Registrars are supposed to verify contact information periodically, but enforcement is inconsistent. If you find contact information in WHOIS and it bounces back, the information may simply be old.
Some domain owners intentionally put false information in WHOIS (which violates the registrar's terms of service, though it is rarely enforced). If an email address does not work and there is no other way to contact the owner, you may not be able to reach them. In that case, try the website's own contact page or social media accounts instead.
Frequently Asked Questions
Can I find out who owns a website if they used privacy protection?
Not through WHOIS — you will only see the privacy service's details. However, you can try the "contact owner" feature if the registrar offers one, or look for contact information on the website itself. If you have a legal reason to know the owner's identity (like reporting illegal activity), you can contact law enforcement or the website host, though they are not required to share that information.
Is it illegal to look up someone's domain information?
No. WHOIS is a public database specifically designed for lookups. Anyone can search it for free. The information in WHOIS is public by default — owners have to pay extra to hide it. Looking up a domain is not illegal, but using the information to harass or spam someone is.
Why does the WHOIS result show a company name instead of a person?
The domain owner registered it under a business name or organization rather than their personal name. This is common for company websites, nonprofit sites, and professional projects. The company name is the legal owner of the domain.
Can I change the information in WHOIS?
Yes, if you own the domain. Log into your registrar's account (GoDaddy, Namecheap, etc.), find the domain management section, and look for "WHOIS settings" or "registrant information." You can update your details there, or you can enable privacy protection to hide them. Changes usually take a few hours to appear in the public WHOIS database.
What if the domain is registered to someone else but they are using it to impersonate me?
Contact the registrar directly with proof of the impersonation. Most registrars have an abuse or legal team that can investigate. You can also report the domain to the website host (use a reverse IP lookup to find the hosting company) or to law enforcement if the impersonation is part of a larger fraud.