Authentication
This endpoint is public. It takes no credential and no organisation — it is what our own marketing site and AI answer engines read.
This endpoint takes no organisation id. Your key already identifies the organisation it belongs to, and the response is scoped to it.
Try it
Replace anything in angle brackets with your own values, and the key placeholder with a key from your dashboard.
curl -X GET https://api.zinndigital.com/v1/public/domains/whois?domain=<domain>Signed in? The API console in your dashboard fills in your real organisation id and your own key, and runs the request against the live API so you can see the actual response. Open this endpoint in the API console
Details
What the public registry says about a domain — registrar, registration and expiry dates, status codes, nameservers and DNSSEC — for **any** name, whether it is with us or not. No account, one domain per request. Read from RDAP (RFC 7482/7483), which the registries serve themselves and which needs no credential. **`state` is three-valued and that is load-bearing.** `registered` means the registry returned a record. `not_registered` means it answered `404` — there is no such registration. `unknown` means we could not find out: the extension publishes no RDAP service, the registry timed out, rate-limited us, or answered with something we could not read. ⛔ A client must never render `unknown` as `not_registered`: they send a visitor to opposite actions, and collapsing them is the defect that once offered `google.com` for sale with a valid checkout token. `registry` is `null` for both non-`registered` states. Inside it every field is nullable, and `null` means *the registry did not publish it* — never that the domain lacks it. A client rendering `transfer_locked: null` as "unlocked" would tell somebody to go and protect a domain that is already protected. No registrant, admin or technical contact is ever carried: post-GDPR most registries redact them, and republishing the ones that do not would be exporting personal data for no product reason. **Rate limited per caller and globally**, and answers are cached for 24 hours per domain. There is deliberately no bulk or CSV input — the bulk surface is the authenticated one, where the caller has an organisation.
Parameters
| Name | Type | Required | What it is |
|---|---|---|---|
domain (query) | string | Yes | The domain to look up, including its extension. A trailing dot is ignored, case is ignored, and an internationalised name must already be punycoded. |
Response
| Name | Type | Required | What it is |
|---|---|---|---|
fqdn | string | Yes | The normalised name that was looked up (lower-cased, no trailing dot). |
state | string<registered, not_registered, unknown> | Yes | `registered` — the registry returned a record. `not_registered` — the registry answered `404`. `unknown` — we could not find out (no RDAP service for the extension, a timeout, a… |
registry | RegistryProfile | Yes | The registry record, or `null` for any state other than `registered`. |
Errors this endpoint can return
422 · 429 · 503