Whois: Fragile, Unparseable, Obsolete
netmeister.org
netmeister.org
One particularly fun story is how we might have broken a whois server. It was the country TLD server for some West African nation, I think Senegal but I'm not sure. We hit their server with like a hundred queries in rapid succession (to test what rate limiting approach they used) and requests started hanging. We switched IP addresses ... and still requests were hanging. We tried multiple IP addresses in totally different networks, all of them hung or timed out, even for a single request. A day later we retried and all of a sudden it started working again! From that point on we made sure to never do more than a couple requests a second to that particular domain.
Also, any queries to one cc TLD (either Egypt or Ukraine, can't remember which) just returned "we don't provide information in whois requests" or something to that effect.
GoDaddy didn't do traditional rate limiting. If you exceeded whatever their limit was they didn't just return an error message, they would blacklist your IP and for any query say "visit our website for information", and their website gated things behind a captcha.
Many years ago I built a replacement whoisservers.org, and tried contacting a few maintainers, but nobody seemed to really care.
If you want to make use of it, you can run "whois -h com.whoisservers.org exmaple.com" (or substitute -h with the appropriate flag for your client to specify a server)
Mine points your client to the appropriate whois server you need to talk to for a specific TLD. Like I said the same functionality is already built into a few whois clients, they are just using a DNS zone that is no longer updated.
I also hunted (s/whois/rdap/g) around for undocumented RDAP servers and found a few. There are still a lot of TLDs without RDAP though [2].
[1] https://rdap.redirect2.me/ (source at https://github.com/redirect2me/rdap-proxy)
I don't think that's possible. WHOIS, by design, is controlled by the domain registry, which may delegate it to registrars -- the owner of the domain may have some limited control over the contents (like the registrant information), but they don't get to control it fully, and I've certainly never seen a registrar delegate WHOIS to the domain owner.
I can not find any whois clients that support this expired ietf draft [1] so I assume it was abandoned.
[1] - https://datatracker.ietf.org/doc/html/draft-sanz-whois-srv-0...
Someone is hosting copyrighted content? Look up that machine's IP-WHOIS.
Someone is trying to DDOS me? Look up that machine's IP-WHOIS.
Someone is holding a domain I want? If their answer is going to be anything other than a straight "no", they'll happily provide a way to be contacted.
Please tell me how I'm wrong.
Some parameters are reliably there and in a way it is very easy to parse since it is key value separated by a colon (cut -d ':' -f 1,2) but there is no "schema" you can follow and sometimes I saw unique and extra additions by some servers and missing critical fields by others. "Your domain is compromised, bad guys are doing bad stuff with it" how do I reliably find out the right contact for example? That last bit was always a manual excercise.
Don’t modern whois clients all do this? (I.e. not the one available in, say, macOS.)
Email was the great communicator. Removing it from WHOIS made the web more fragile and broken. But whois doesn't have to be that way and the problems are not intrinsic to whois. They are stemming from political interference done with good intentions but bad outcomes.
the ICANN [contact disclosure] requirement now does indeed conflict with modern privacy laws, such as the EU's GDPR, meaning all domains registered by European registries are in violation of either GDPR or ICANN's requirement.
General information to be provided
1. In addition to other information requirements established by Community law, Member States shall ensure that the service provider shall render easily, directly and permanently accessible to the recipients of the service and competent authorities, at least the following information:
(a) the name of the service provider;
(b) the geographic address at which the service provider is established;
(c) the details of the service provider, including his electronic mail address, which allow him to be contacted rapidly and communicated with in a direct and effective manner;
(d) where the service provider is registered in a trade or similar public register, the trade register in which the service provider is entered and his registration number, or equivalent means of identification in that register;
(e) where the activity is subject to an authorisation scheme, the particulars of the relevant supervisory authority;
The EU wants to make cross-border commerce work. So, they want customers to be able to find sellers should there be a problem.
[1] https://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CELEX...
I’m inclined to believe that most people looking up WHOIS details have good intentions, but clearly there are people that use them for their own purposes.
And you're completely wrong about GDPR. It is the primary, if not exclusive, reason most registrars in most regions have removed WHOIS information. ref: https://www.icann.org/resources/pages/gtld-registration-data... https://circleid.com/posts/20210119-whois-record-redaction-a...
I would like to use RDAP instead but RDAP coverage is even spottier than WHOIS.
BTW, if anyone knows of a WHOIS server able to handle the .de TLD, please let me know as all I get right now is "The DENIC whois service on port 43 doesn't disclose any information"
> since 2019, ICANN requires registrars and registries to implement an RDAP service.
At least, as much as one can. It'd be nice if ICANN required registries to implement an RDAP service.