Whois (RDAP) lookup API for domains, IPs and AS numbers

POST a domain, an IP address or an AS number to /v1/rdap. It queries the RDAP server named by the IANA bootstrap, the successor of whois, and returns registrar, created, updated and expiry dates, status, nameservers and DNSSEC for a domain.

Request

query is a domain (example.com), an IPv4 or IPv6 address (1.1.1.1) or an AS number (AS13335). For an IP or AS number the answer holds the network, CIDR, country, organisation and abuse email instead.

curl, using the free tier
curl -s -X POST https://tanod.dev/v1/rdap \
  -H 'X-Tanod-Free: 1' -H 'content-type: application/json' \
  -d '{"query":"example.com"}'

Response

Response (the example from the OpenAPI spec, trimmed)
{
  "query": "example.com",
  "type": "domain",
  "found": true,
  "rdap_server": "rdap.verisign.com",
  "name": "example.com",
  "registrar": {"name": "RESERVED-Internet Assigned Numbers Authority", "iana_id": "376"},
  "created": "1995-08-14T04:00:00Z",
  "updated": "2026-08-14T08:01:43Z",
  "expires": "2027-08-13T04:00:00Z",
  "status": ["client delete prohibited", "client transfer prohibited", "client update prohibited"],
  "nameservers": ["elliott.ns.cloudflare.com", "hera.ns.cloudflare.com"],
  "dnssec": true,
  "redacted": [],
  "notes": ["registry data only; registrar-level RDAP was not queried"],
  "cached": false
}

Limits and caveats

Redaction. Many registries hide personal contact data. Redacted fields are returned as null and named in redacted.

Registry data only. For many domains the answer comes from the registry, not the registrar, so some registrar-level fields can be missing. Not every top-level domain offers RDAP.

Values are text from a third-party server and should be treated as untrusted data.

Price and free allowance

USD 0.002 per call, paid in USDC on Base with x402. 5 free per IP per UTC day with the header X-Tanod-Free: 1; the pool is shared with domain inspection, email verification and IP lookup. MCP tool: rdap_lookup at https://tanod.dev/mcp, where the free tier is automatic.

All endpoints →

Related guides: How to check a domain's SPF, DMARC and DKIM with an API, IP address to ASN lookup API (network, org, abuse contact), How to verify an email address with an API (syntax, MX, disposable). Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.