## Look up domain and IP registration details

# Who owns a domain
whois example.com

# Who owns an IP address
whois 93.184.216.34

# Look up an IPv6 address
whois 2606:2800:220:1:248:1893:25c8:1946

# Look up an AS number
whois AS15169

# Query a specific whois server
whois -h whois.verisign-grs.com example.com

# Query on a non-standard port
whois -h whois.example.net -p 4321 example.com

# Force the registry answer rather than the registrar's
whois -H example.com

# Hide the legal disclaimers, which are most of the output
whois -H example.com | grep -v '^%'

# Just the expiry date
whois example.com | grep -i 'expir'

# Just the creation date
whois example.com | grep -i 'creation'

# The registrar
whois example.com | grep -i 'registrar:'

# The name servers
whois example.com | grep -i 'name server'

# The status codes, which show locks and pending deletions
whois example.com | grep -i 'status:'

# Abuse contact for a domain
whois example.com | grep -i 'abuse'

# Abuse contact for an IP, for reporting an attack
whois 198.51.100.7 | grep -i 'abuse'

# Which organisation owns an IP range
whois 198.51.100.7 | grep -iE 'orgname|org-name|descr'

# The network range an address belongs to
whois 198.51.100.7 | grep -iE 'netrange|inetnum|cidr'

# The country
whois 198.51.100.7 | grep -i country

# Which AS announces this address
whois -h whois.cymru.com ' -v 8.8.8.8'

# Bulk AS lookup for several addresses
printf 'begin\nverbose\n8.8.8.8\n1.1.1.1\nend\n' | whois -h whois.cymru.com

# Check whether a domain is available
whois example-unlikely-name-12345.com | grep -iE 'no match|not found'

# Check availability in a script
whois example.com 2>/dev/null | grep -qiE 'no match|not found' && echo available || echo taken

# Days until a domain expires
whois example.com | awk -F': *' '/Registry Expiry Date/ {print $2}'

# Check the expiry of several domains
for d in example.com example.net; do echo -n "$d: "; whois "$d" | awk -F': *' '/Expiry Date/ {print $2; exit}'; done

# Look up a country-code domain, which may need its own server
whois -h whois.nic.ge example.ge

# The ge registry directly
whois example.ge

# Look up the abuse contact of the busiest IPs in a log
cut -d' ' -f1 access.log | sort -u | head -n 5 | while read -r ip; do echo "$ip: $(whois "$ip" | grep -im1 abuse)"; done

# Rate limits are common, so slow a bulk lookup down
for ip in $(cat ips.txt); do whois "$ip" | grep -im1 orgname; sleep 2; done

# Modern registries answer RDAP over HTTPS instead
curl -s https://rdap.verisign.com/com/v1/domain/example.com | jq '.events'

# RDAP for an IP address
curl -s https://rdap.arin.net/registry/ip/8.8.8.8 | jq '.name, .country'

# DNS records, which is a different question from registration
dig example.com ANY +noall +answer

# The name servers actually in use, rather than those registered
dig +short NS example.com

# Certificate details, another way to see who runs a site
openssl s_client -connect example.com:443 -servername example.com < /dev/null 2>/dev/null | openssl x509 -noout -subject -issuer
