Your domain name is the thing your website and your business email both hang from. A registration lapse or unauthorized change can disrupt those services. Recovery may become harder if important account-reset messages depend on the affected domain. The precise impact depends on what changed and how your services are configured.

It deserves a regular review and another check when responsibilities change. Our training video walks through the lookup itself; this article is the reference to keep beside it, because the hard part is not running the search. The hard part is reading the result honestly.

Question one: who holds the registration

Public registration data for generic top-level domains is now published through RDAP, the Registration Data Access Protocol, which ICANN designated as the definitive service for gTLD registration data at the start of 2025. Some legacy contracts still carry WHOIS obligations alongside it, notably for .com, .name and .post, and country-code domains set their own policies entirely. So do not assume one lookup method covers everything you own.

Run the lookup and look for the sponsoring registrar — the company the domain is registered through. That single field is the most useful thing on the page, because it tells you which account to go looking for.

What you will very often not see is a person. Registrant name, email and address are commonly redacted from public output. That is a privacy outcome, not a sign that something is wrong with your domain, and it means the public record cannot answer "who owns this" in the way people expect. Account control and company records help establish who can manage the registration, but a public lookup and a working login do not settle a disputed legal ownership question.

If the record is redacted and you do not recognize the registrar, your next move is not another lookup. It is your accounting system: search supplier payments for registrar names, then search your mail archive for renewal notices. Those records can provide a starting point for finding the account or identifying the person who managed it.

Question two: when does it expire

Where available, the lookup may show a registry expiration date. Treat it as a fact about the registry, not as your renewal invoice date.

Consider a hypothetical firm whose domain shows an expiry in March. Their registrar bills annually in February, auto-renew is switched on, and the card on file expired in January. Nothing in the public record reflects any of that. The registry date looked reassuring right up until the renewal attempt failed silently, because the notice went to a former office manager's mailbox.

So check the registry date, then check the three things it does not cover: whether auto-renew is enabled, whether the payment method on file is current, and which address renewal notices are sent to. Registrars also differ in what happens after an expiry — grace periods, redemption windows and restoration fees vary by registrar and by top-level domain, so ask yours rather than relying on a number you read somewhere.

Question three: is it locked against transfer

Registration records carry status codes, and the one most worth knowing is clientTransferProhibited. It means the registrar has applied a transfer lock, which is the normal, healthy state for a domain that you are not currently moving. A domain sitting unlocked for no reason is worth a question.

Be precise about what the lock does. It blocks a transfer request to another registrar. It does not protect the account itself. Depending on permissions and the registrar’s safeguards, someone with account access may be able to remove the lock or request a transfer code. Protect the account as well as checking the domain status, including enabling multi-factor authentication where available. CISA recommends multi-factor authentication as an additional account-protection layer. It reduces dependence on a password alone; it does not remove every account risk.

Your annual domain check

  • Run a lookup for every domain you own, including the ones that only redirect to your main site.
  • Note the sponsoring registrar for each, and confirm you can actually sign in to that account today.
  • Confirm multi-factor authentication is enabled on the registrar account.
  • Check auto-renew status, the payment method, and the notice address for each domain.
  • Confirm the transfer lock is on for domains you are not moving.
  • Record who inside the business is responsible, and who the second person is when they are unavailable.
  • Set a calendar reminder for the same check next year, owned by a role rather than a named individual.

What a lookup cannot tell you

Public registration data is a directory, not a title deed. It does not establish legal ownership, it does not tell you who inside your company has the password, and it does not tell you whether your DNS records — the settings that actually point traffic at your website and mail — are configured correctly. A domain can be perfectly registered, locked, and paid for, and still be pointing at a server that was decommissioned two years ago.

It also cannot tell you about the arrangement behind the account. Domains registered by a former web designer, a marketing agency, or a departed employee show up in a lookup as entirely ordinary. The risk is in the relationship, not the record.

Your next step

Pick your primary domain and answer the three questions today. If any answer is "I am not sure", that uncertainty is the finding, and it is a better outcome than a confident guess.

Watch the walkthrough, then work through your own list. If your domains sit across several registrars and nobody is quite sure who set them up, ALCO USA Inc can help you work through the records and define the next step alongside your hosting, development and IT support needs. The available recovery options depend on the registrar and the evidence you can provide.

Sources and further reading

ALCO training on domain ownership: https://alcohq.com/training/domain-ownership
Video walkthrough: https://youtu.be/vPLz6TuYsuE
ICANN on the move from WHOIS to RDAP: https://www.icann.org/en/announcements/details/icann-update-launching-rdap-sunsetting-whois-27-01-2025-en
ICANN information for RDAP users: https://www.icann.org/en/contracted-parties/registry-operators/registration-data-access-protocol/information-for-rdap-users-31-08-2018-en
ICANN Lookup FAQ on redacted data: https://lookup.icann.org/en/faq
CISA on requiring multi-factor authentication: https://www.cisa.gov/audiences/small-and-medium-businesses/secure-your-business/require-multifactor-authentication

ICANN domain status codes: https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en