Live WHOIS Lookup
Current registrar, registrant, creation, expiry dates, nameservers, status codes
N8N Integration
Integrate into existing security pipelines, use pre-built API integrations for your favorite tools, or fit WhoisFreaks data into pre-existing workflows
18 domain and IP intelligence operations inside n8n — live and historical WHOIS, DNS records, SSL certificates, subdomains, typosquat detection, IP reputation and geolocation. Built for security teams, domain investors and anyone automating domain research.
The node is verified, so it installs from the canvas panel on n8n Cloud. Self-host instead and every lookup runs inside your own network.
n8n doesn't meter community node runs. Checking 10,000 domains costs the same in n8n as checking ten. Your only spend is API credits.
Without it you'd wire an HTTP Request node per endpoint and repeat the auth in each. Here you pick from a dropdown and set the key once.
WhoisFreaks is a verified n8n community node, which means it installs on n8n Cloud as well as self-hosted instances. Open the nodes panel, search for WhoisFreaks, and install. No npm, no command line, no restart.
Get your free API key first: whoisfreaks.com/signup
Install the Whoisfreaks community node into your self-hosted n8n instance to get started.
Navigate through your n8n settings to install the required package from community nodes.
Authenticate your installed node using your unique account credentials and API key.
Current registrar, registrant, creation, expiry dates, nameservers, status codes
Every unique historical WHOIS record, ordered with the newest first
Domains matching a specific registrant email address, name, or company
Determines whether a specific domain name is currently available to register
Retrieves current registrar and registration details for multiple domains
Five patterns teams build most often. Orange steps are Whoisfreaks operations, everything else is a native n8n node.
Typosquatted domains are registered before they are used. Catching them at registration buys time to act before a phishing campaign launches.