How to find out who owns a website

Most registration records now hide the owner. The pivots that still work, what each one is evidence of, and how to tell today's operator from a domain's earlier owners.

Domain InvestigationWHOISOSINTTrust & SafetyFraud InvestigationsIdentity Resolution
How to find out who owns a website

To find out who owns a website, look up its registration record through RDAP, which replaced WHOIS as the source of registration data for generic domains in January 2025. Then follow the pivots that survive redaction: the site's DNS and hosting, the certificates issued for it, its archived history, the identifiers on its pages and the business it claims to be. The registrant's name is usually hidden, so ownership has to be pieced together from several of these, each with a date attached, and the person running the site today may not be the one behind its oldest traces.

What you can find out about who owns a website

A website has several owners. The registrant holds the domain, bought from a registrar. A hosting company runs the servers. And an operator, who may be none of these, decides what the pages say and where the money goes. In a scam storefront or a phishing site you want the operator, and you can contact the registrar and the host.

Few pivots name the operator directly. They show which other sites the same operator runs, and an operator careful on one site may be careless on another. In a 2018 study of analytics IDs on malicious websites, researchers identified 59 operators of malicious sites by finding public registration records for other domains that shared the same analytics IDs.

Domains also lapse and change hands. So, as with a phone number, every finding needs a date, and every link to a person needs a second source.

Question one: what does the registration record say?

Since 28 January 2025, ICANN has treated RDAP, the Registration Data Access Protocol, as the definitive source of registration data for generic top-level domains such as .com, in place of WHOIS. ICANN's Lookup tool queries it.

Under ICANN's Registration Data Policy, every generic-domain record publishes the creation and expiry dates, the registrar and its abuse email address and phone number, the status codes and the name servers. It may also show the last transfer, meaning a change of registrar, not necessarily of owner. Of the status codes, clientTransferProhibited is a lock that helps prevent hijacking, clientHold and serverHold mean the domain will not resolve, and redemptionPeriod and pendingDelete mean it is being deleted.

The registrant is another matter. In May 2018 ICANN adopted a temporary specification that restricted most personal data to "layered/tiered access", and registrars began replacing registrants' details with text such as "REDACTED FOR PRIVACY". Where redaction applies, the policy that replaced it on 21 August 2025 withholds the registrant's name, street, postal code and phone numbers, optionally the city, and swaps the email address for a relay address or a web form. It still publishes the registrant's country, the state or province where one was collected, and the organisation name if the registrant agreed. A privacy or proxy service shows its own details instead of its customer's. Country-code domains such as .uk follow rules set within each country, so use that registry's own service.

To ask for the redacted data on a generic domain, use ICANN's free Registration Data Request Service, which needs an ICANN account and is meant for requesters such as consumer protection advocates and cybersecurity specialists. Registrars take part voluntarily, country-code domains are not covered, and the registrar decides whether to disclose anything. ICANN says the service does not guarantee access. Otherwise, use the registrar's own disclosure process. Expect delay or refusal, and keep working the other pivots.

Question two: how old is the site, and has it changed hands?

A registration date marks the start of the current registration, which is not always the start of the site's history.

When a lapsed domain is deleted, the registry holds it for 30 days, and five days after that, ICANN's guide says, it is purged and "becomes available for registration". The next registrant gets a new creation date, and the authors of a 2017 study of re-registration detected re-registrations exactly that way. Every day, they wrote, hundreds of thousands of domains are abandoned, and about 10 percent of deleted .com domains were registered again the same day. The new holder inherits the domain's reputation, which researchers call residual trust, and adversaries do exploit it. A domain that is sold keeps its original creation date instead, and the 2017 study found that expired domains sold before deletion show "only very limited cues as to the new ownership".

So read the creation date against the site's history. A recent date on a domain with years of history means it lapsed and was registered again. An old date with an abrupt change in what the site does may mean a sale.

Two public records supply that history. The Internet Archive's Wayback Machine shows the site on each date it was captured, including old contact and about pages. Its help centre explains how to list everything archived for a domain. Gaps prove little, because the Archive misses sites its crawlers did not know about, sites that blocked them, and sites whose owners asked to be excluded.

Certificate transparency logs, first specified in RFC 6962, are public and append-only, and anyone can query them "to see what certificates have been included and when". In versions of Chrome that enforce certificate transparency, a publicly trusted certificate that has not been logged fails to validate, so an ordinary HTTPS site leaves a trail. A free search such as crt.sh lists each certificate's dates and names, which often reveals subdomains and shows when the site took its current form. A certificate can date a site without naming its owner: Let's Encrypt offers only domain-validated certificates, which under the CA/Browser Forum's rules carry no organisation name.

Question three: where is it hosted?

DNS records show the infrastructure behind the name (RFC 1035, RFC 3596). A and AAAA records give the server's addresses, NS records the name servers, MX records the mail servers and TXT records free text. That text often includes an SPF record (RFC 7208) authorising the hosts that may send the domain's mail, which can name the operator's mail services.

An RDAP lookup on the server's IP address returns the network's registration and its abuse contact, which, as the RIPE NCC warns, "will be an ISP or other network operator - not the abuser". That is where takedown reports go.

A shared IP address is weak evidence. A study published in 2020 found more than 60 percent of websites co-located with at least ten others. Count the domains on an address before reading anything into it, as in linking related accounts: a handful can be a lead, two thousand is background. Behind a security proxy or content delivery network, as one measurement study put it, "the origin's IP address is no longer listed in the DNS records of the domain name", so the address you see is the provider's. Parked domains use a parking service's name servers, and a 2015 study counted more than 8 million of them, so shared parking says nothing about ownership.

Certificates. One certificate can cover several names, as Let's Encrypt's FAQ notes. Two unrelated-looking domains on one certificate were requested together, either by one owner or by a hosting provider that puts domain names from numerous distinct customers on a shared certificate.

Analytics IDs. The 2018 study found that shared analytics IDs cluster sites "managed by the same person/team", even on different servers and behind registration privacy, and that such sharing is "very common across both benign and malicious website owners". In an old Universal Analytics ID such as UA-123456789-1, the centre number identifies the account. Google stopped processing standard Universal Analytics data in July 2023, and Bellingcat calls the replacement IDs "less uniform", but old ones survive in archived copies of a site. Two cautions from the same study: a phishing page cloned from a real site often carries the victim's ID, because the cloning software copies the analytics code, and hosting companies' pages for suspended accounts can share one ID across many domains.

Verification tokens. Services ask site owners to publish a token, in a TXT record or a meta tag, to prove control. Google describes its Search Console tag as "tied to a specific user", and its verification API issues a different token for each site. An IETF draft on domain verification describes tokens that identify either the challenge or the user. The same token on two domains points to one account or to a record copied between them, and either is a link. A cloned page carries its meta tags with it, while a TXT record stays behind.

Contact and payment details. Phone numbers, email addresses, messaging handles and the account buyers pay into. Our guides to an email address and a phone number cover what each can prove. Payment details from victims' reports are among the strongest links, because the money has to reach someone.

Shared valueWhat a match suggestsHow it misleadsStarting weight
Receiving bank account or walletOne operation collects the moneyThe named holder may not be the operatorStrong
Analytics accountOne person or team manages both sitesCloned pages, and agencies with many clientsStrong once cloning is ruled out
Verification tokenOne account, or a copied recordCloned meta tagsMedium to strong
Contact phone or emailOne operator answers both sitesCopied templates, recycled numbersMedium to strong
CertificateNames requested togetherShared hosting certificatesMedium
Name servers or IP addressThe same provider or serverShared hosting, content delivery networks, parkingWeak unless few sites share it

Count only independent links: an analytics account and a token set up in one sitting are nearly one observation.

Question five: who does the site claim to be?

Check any company, address or registration number named in the footer, terms, contact or imprint pages against the registry of the country named. In the UK, Companies House gives free details of any company, including its registered address, date of incorporation, current and resigned officers and previous names. Look for an incorporation date years after the site's claimed founding, or a registration number that belongs to a differently named company. That company's details were probably borrowed, and it belongs in the report as an affected party.

A worked example

The case below is a composite. Its domains use the .example names reserved for documentation, its IP address comes from a range reserved for examples, and its phone number from the 555-0100 to 555-0199 range reserved for fiction.

In late September 2026, a marketplace's trust and safety team receives reports from four buyers. Each saw a well-known outdoor brand's jackets at half price from one of three seller accounts opened that month, was told to order "direct from our outlet" at brindlecote.example, paid by bank transfer and received nothing.

The registration. RDAP shows a registration on 11 September 2026 through a large retail registrar, with a privacy service in place of the registrant. The site's about page says it has served customers since 2011.

The history. The Wayback Machine shows a small homewares shop on the domain from 2012 to 2021, then a for-sale parking page, then the storefront from mid-September 2026. The certificate logs agree: yearly certificates for the shop until 2021, then a new one on 12 September 2026, covering a checkout subdomain too. The domain lapsed and was registered again, so "since 2011" borrows the shop's history, and the domain's earlier holders are filed as previous registrants and nothing more.

The hosting. The site resolves to 203.0.113.42, shared with about 1,900 other domains, so the address is set aside.

The fingerprints. The page carries two analytics tags. One is the brand's own, copied when the storefront was cloned, so it links the scam only to its victim. The other appears on one other site, jacket-clearance.example, a storefront copying a different brand, registered in August 2026. The two domains publish the same verification token in their TXT records, and both contact pages give the same WhatsApp number, +1 312 555 0164.

The money. Two buyers had already reported jacket-clearance.example to the marketplace, and the bank details they were given match the brindlecote.example buyers'.

The business. Companies House shows that the UK company number in the footer belongs to an unrelated dormant company, which is filed as an affected party.

Put together, the storefronts are one operation. The analytics account and the token may come from one set-up session, so they count as one strand, and the contact number and the bank account are independent of it and of each other. The team acts on the three seller accounts, archives the storefronts, reports both domains to their registrars' and hosts' abuse contacts and to Google Safe Browsing, and files a disclosure request with the registrar. Who the operator is stays open: the registrant is behind a privacy service, the request may go unanswered, and the account holder's identity sits with the bank. The report says so.

Investigating without alerting the operator

Most pivots above are read from third parties. Visiting the site is different, because its server can log every request. When you need to see it, use an isolated browser, and do not log in, fill in forms, start a checkout or enter any details. Take payment details from victims' reports, never from a test order. Preserve evidence with screenshots and the Archive's Save Page Now, which saves one page at a time. Report through abuse contacts and Safe Browsing, never to the operator.

Reading the results fairly

Most of what makes a website look suspicious has an ordinary explanation, and a fair report checks for it first.

A hidden registrant is normal. Registrars have redacted personal data since 2018, and before that an ICANN-commissioned study found privacy or proxy services on about 20 percent of domains in the top five generic top-level domains. A later study for ICANN found them more often on domains used for harm, but also on 28 percent of the legitimate banks it examined.

A young domain is normal for a new business, and a domain with someone else's history may have been bought in good faith. Shared hosting, content delivery networks and parking services put strangers on one address. Previous owners in archives and old certificates are earlier holders and nothing more. A cloned page's analytics ID and meta tags point to the brand it copied. Agencies and freelance developers build many clients' sites, so a shared analytics account can mean a shared developer. And a company named on a site may never have heard of it.

Where Sixtyfour fits

Run carefully, the five questions take time, and much of what they produce is a set of identifiers: email addresses, phone numbers, usernames and company names. Sixtyfour's agent starts from identifiers like these, researches where each one appears across public sources, links what it finds to one person or entity, and returns every finding with its source. Anything it could not establish is reported as open, and a person on your team decides what happens next. There is more on how trust and safety teams use it on our trust and safety page.

The short version

Read the registration record, date the site through its archive and certificates, find where it is hosted, and search for the accounts, tokens, contact details and payment details it shares with other sites. Give every finding a date and a weight, count only independent links, and mark what you could not establish as open.

“A registration date marks the start of the current registration, which is not always the start of the site's history.”
Hashim Khawaja Founding Engineer, Sixtyfour
1200 × 630 — ready to share

Frequently asked

Often, though rarely from the registration record alone. Registrars began redacting registrants' personal details in 2018, but the record still shows the registration dates, the registrar, the name servers and the registrant's country. The site's hosting, certificates, archived pages, analytics IDs and contact details can then link it to other sites and to a business, and you can ask the registrar for the redacted data through its disclosure process, which may take time and may be refused.

For generic domains such as .com, ICANN made RDAP the definitive source of registration data on 28 January 2025, in place of WHOIS, and ICANN's Lookup tool uses it. Some registries and registrars still run WHOIS services alongside RDAP, and country-code domains such as .uk follow their own registries' rules.

It means the registrar has withheld the registrant's personal details from the public record, a practice that began for generic domains in 2018. It says nothing about the owner's intentions, because legitimate businesses and individuals are redacted in exactly the same way. The registration and expiry dates, the registrar, the name servers and the registrant's country stay visible.

Check the creation date in an RDAP lookup, then compare it with the earliest captures in the Wayback Machine and the earliest certificates in certificate transparency logs. The creation date only shows when the current registration began. If the domain lapsed and was registered again, the archive and the certificates can show an earlier history that belonged to someone else.

Usually not. Shared hosting puts many unrelated sites on one address, and a study published in 2020 found more than 60 percent of websites co-located with at least ten others. Sites behind a content delivery network show the provider's addresses instead of their own. Treat a shared address as a lead only when very few sites use it.

Report it to the registrar's abuse contact, which appears in the domain's RDAP record, and to the hosting provider's abuse contact, which an RDAP lookup on the site's IP address usually shows. Phishing pages can also be reported to Google Safe Browsing. Do not contact the operator, and do not enter any details into the site.

Get started

See how Sixtyfour turns the contact details behind a suspect website into a sourced investigation.

Request a Demo
  1. What you can find out about who owns a website
  2. Question one: what does the registration record say?
  3. Question two: how old is the site, and has it changed hands?
  4. Question three: where is it hosted?
  5. Question four: what links it to other sites?
  6. Question five: who does the site claim to be?
  7. A worked example
  8. Investigating without alerting the operator
  9. Reading the results fairly
  10. Where Sixtyfour fits
  11. The short version