Blog & How To Guides | WhoisXML API

WhoisXML API Blog

What is Withheld for Privacy ehf (and How to See WHOIS Data Beyond It)

When you run a WHOIS lookup for a domain name you’re interested in, you may find that some details are redacted for privacy. You can’t see who owns that domain because “Privacy service provided by Withheld for Privacy ehf” is on the registrant organization field. What, exactly, does this mean? And is there a way to find out the actual domain owner’s email address and contact them? 

We’ll talk about registration data redaction in general and Withheld for Privacy ehf in particular in this post, as well as cover how it works, and some of the other most common domain privacy protection companies. We will also demonstrate how you can possibly still uncover domain ownership data despite redaction.

WhoisXML API Joins Industry Leaders at the ICANN82 Community Forum

WhoisXML API Joins Industry Leaders at the ICANN82 Community Forum

WhoisXML API representatives recently attended the ICANN82 Community Forum held in Seattle on 8–13 March 2025, where they participated in cross-community conversations and plenary sessions.

The event brought together prominent figures in the industry—Curtis Lindquist, ICANN President and CEO; Nayala Saras, Vice President of Global Stakeholder Engagement, North America; and Tripti Sinha, Chairman of the ICANN Board of Directors; and many other leaders. 

As a regular participant in ICANN forums, we want to share some of the important highlights from ICANN82 in this post.

WhoisXML API Participates in SecurityScorecard Odyssey 2025

WhoisXML API Participates in SecurityScorecard Odyssey 2025

Ed Gibbs, Vice President of Research at WhoisXML API, joined thousands of cybersecurity leaders and innovators at the SecurityScorecard Odyssey.conf, held in Miami, Florida, on 25–27 February 2025.

The event, known for its focus on supply chain cyber risk management, provided a valuable opportunity to consider the role of domain and IP intelligence in strengthening defenses against cyber threats, aligning with this year’s theme, “Charting the Course for Cyber Resilience.”

While the event dove into several important areas of cybersecurity, we highlight three key takeaways in this post. 

Python Script for Transforming Domain Names from First Watch Malicious Domains Data Feed into STIX 2.1

WhoisXML API recently created a Python script to help users of First Watch Malicious Domains Data Feed, also known as “First Watch,” transform predictive domain intelligence into a machine-readable format—STIX 2.1—for automated data processing.

The script reads domain names from First Watch files, converts them to STIX 2.1 Indicator objects with domain-name observable types, and generates a TAXII 2.1-compatible STIX bundle. The output is downloadable as a JSON file in TAXII format.

FQDN to IP, IP to FQDN: The Queries that Power Domain Infrastructure Discovery

Identifying malicious infrastructure, implementing blocklists, analyzing IP or domain reputation — all of these (and many other) tasks rely on mapping fully qualified domain names (FQDNs, or so called "complete domains") to IPs and IPs to FQDNs. These mappings are crucial not only for network security analysis but also for troubleshooting and even basic website administration. 

There are lookup tools that can let you obtain the IP address that resolves to the FQDN (i.e., FQDN to IP or forward lookup tools) or retrieve a list of domains resolving to an IP address (i.e., IP to FQDN also known as reverse lookup tools). If you want to dig deeper—go back in time, if you will—there are also tools that let you perform historical FQDN to IP and IP to FQDN lookups based on passive DNS data. From there, you can create a timeline of the resource's resolutions. 

In this post, we'll show you how to do all of these. If you want to follow along and do the queries yourself, make sure to sign up for a free account to start using the tools we will be demonstrating.

February 2025: Domain Activity Highlights

The WhoisXML API research team analyzed 7.5+ million domains registered between 1 and 28 February 2025 to identify the most popular registrars, top-level domain (TLD) extensions, and other global domain registration trends.

We also determined the top TLD extensions used by 62.1+ billion domains from our DNS database’s A record full file dated 6 February 2025.

Next, we studied the top TLDs of 1.0+ million domains detected as indicators of compromise (IoCs) this February.

Finally, we summed up our findings and provided links to the threat reports produced using DNS, IP, and domain intelligence sources during the period.

What Is RDAP (and Why It’s More Important Now Than Ever)

Conversations around replacing WHOIS – the main protocol for retrieving information about domain registrants – have been around for decades. Now, WHOIS is being phased out and replaced by the Registration Data Access Protocol (RDAP). 

Why is that happening?

Enhance Response Speed for Historical Domain Records with the skipLiveWhois API Parameter

We are thrilled to announce that WHOIS History API has been upgraded to include a feature called “skipLiveWhois,” an optional parameter that enables users to skip WHOIS API requests when the latest indexed record is not fresh (i.e., there is no current WHOIS record from the past 24 hours). 

This enhancement is designed to improve the speed of historical WHOIS lookup requests by close to 90%—from 3.5 seconds to an average of 370 milliseconds.

Try our WhoisXML API for free
Get started