WhoAPI launched in 2011, when the Internet had just over 225 million registered domain names. By the end of the second quarter of 2026, that number had reached 401.6 million.
The bigger story is not how many more domains exist today, but how dramatically the data behind them — and the way we access it — has changed.
Fifteen years ago, most people interacted with a domain primarily as a website address. Today, domains are also brand assets, security signals, and data points used by applications at scale.
Back then, checking a domain usually meant running a WHOIS lookup. The output was not always pretty, and formats varied between registries, but WHOIS often provided creation and expiration dates, registrar information, nameservers, and personal registrant details such as a name, address, email, and phone number.
Many of the questions we ask about domains today are still the same. The way we get the answers is not.
When WHOIS Revealed More
There is a good example on the WhoAPI blog from 2017.
While investigating fake Adidas and Ray-Ban stores promoted through social media, we used a WHOIS lookup as one of the signals to understand what was behind those websites.
The WHOIS record for adidas2017.com showed that the domain had been registered only a month earlier. WHOIS records for other domains in the investigation also showed registrant locations, although some of those details were clearly unreliable.
WHOIS did not prove that a website was fraudulent. It provided context.
The same principle still applies. Domain age alone does not make a website suspicious, but when combined with other signals it can help identify something worth investigating. We recently returned to this idea while looking at why phishing remains so effective.
What changed most dramatically was the amount of registrant information available to the public.
GDPR Changed Public WHOIS
In early 2018, we published The future of WHOIS on WhoAPI, as the domain industry was preparing for GDPR.
At the time, the final outcome was still uncertain. We expected creation dates, expiration dates, registrar information, and nameservers to remain available, while names, email addresses, phone numbers, and postal addresses could disappear from public results.
On May 25, 2018, ICANN’s Temporary Specification for gTLD Registration Data took effect. Registration data continued to be collected, but public access to much of the registrant’s personal information was restricted.
Eight years later, the prediction from that old WhoAPI article looks fairly accurate.
Domain registration data did not disappear. What changed was what remained public.
From Text-Based WHOIS to RDAP
Privacy was not the only challenge.
Traditional WHOIS returns text, and that text is not always formatted consistently across registries and registrars. That is manageable for a single lookup, but it becomes a real problem when software needs to process thousands or millions of domains.

WhoAPI had been turning WHOIS records into structured data for years. In 2017, we even added XML output after a customer told us they had chosen another provider because XML was not available. Three days later, it was. And then, fast forward almost 10 years; again, nobody is using XML, so we discontinued it.
It is a small example, but it shows where domain data was heading. Retrieving information was no longer enough. Applications needed data that could be processed reliably and automatically.
RDAP, or the Registration Data Access Protocol, addressed that problem at the protocol level. ICANN-accredited registrars and gTLD registries have offered RDAP services since 2019.
On January 28, 2025, RDAP became the definitive source for gTLD registration data, while WHOIS services were sunset for most gTLDs.
For someone checking the creation date of a single domain, the difference may not seem dramatic. For software, it is significant.
RDAP provides structured, standardized responses and is better suited to modern applications, including internationalized data and controlled access.
By December 2024, RDAP servers were already processing more than 10 billion queries per month.
The Domain Space Changed Too
The systems used to access domain data were changing at the same time as the namespace itself was becoming much larger and more diverse.
ICANN’s 2012 New gTLD Program eventually introduced more than 1,200 new generic top-level domains. Alongside .com, .net, .org, and country-code domains, we now have hundreds of generic, geographic, and brand TLDs.
We have followed many of those extensions individually on the WhoAPI blog and looked at the broader development in our article about the future of international domain names.
In April 2026, ICANN opened a new gTLD application round, the first in more than a decade. The previous round resulted in extensions such as .microsoft, .africa, .berlin, .bank, and .eco, while the new round supports applications in 27 different scripts.
For domain data providers, that means more registries, more policies, and more data sources to support.
Domain Data Today
WHOIS is no longer synonymous with domain data. Today, registration data is increasingly combined with DNS, SSL, domain availability, and other technical signals.
At scale, reliable domain data depends not only on access, but also on speed, consistency, and automation.
Since August 21, 2025, ICANN’s Registration Data Policy has provided a more permanent framework for handling gTLD registration data.
Conclusion
Fifteen years later, the basic need has not changed. We still want reliable information about a domain. What changed is how we get it and how we use it.
Public WHOIS exposes far less personal registrant information than it did before GDPR, while RDAP now provides the primary framework for accessing gTLD registration data.
In 2011, much of domain research started and ended with a WHOIS lookup.
Today, WHOIS is only one part of a much larger domain data ecosystem.
