resources background

Tutorial

How to Find All Domains Registered by a Company

Written By Qasim, WhoisFreaks Team Published: September 28, 2026, Last Updated: September 28, 2026

A normal WHOIS lookup goes one way: you give it a domain, and it tells you who registered it. Reverse WHOIS goes the other way; you give it an identity, and it returns every domain in the WHOIS database that matches. This tutorial shows you how to run that search against the WhoisFreaks Reverse WHOIS API, how to pick the right one of the four search modes, how to page through the results, and; the part most guides skip; how to tell how much of the real portfolio you are actually seeing.

You'll need an API key. If you don't have one yet, sign up and grab your key first; new accounts include 500 free credits, no card required.

Read This Before You Start: What Reverse WHOIS Can and Cannot Find

Reverse WHOIS searches an index built from WHOIS records. It can only match a value that a WHOIS record actually publishes. That single sentence explains almost every disappointing result set.

Since GDPR, most registrars redact registrant name, organisation, street, phone and email on gTLD records by default, and privacy-proxy services replace them with the proxy's own details. You can see this in a live record for a privacy-protected domain: the registrant contact comes back as "name": "Redacted for Privacy" with a company of "Privacy service provided by Withheld for Privacy ehf" and a rotating alias address such as [email protected]. A company= search will never match that domain to its real owner, because the real owner's name is not in the record.

So treat every result set as a floor, not a census. It tells you, "At least these domains match", never "these are all the domains this company owns". Corporate registrars used by large brands; the ones that keep the organization field populated deliberately; tend to return good results. Domains registered through consumer registrars with privacy enabled tend to return nothing at all. That limitation is also why four search modes exist: different identities survive redaction differently, and picking the right one is the whole skill.

Step 1: Choose Your Search Mode

The API accepts exactly one search parameter per request. You cannot combine them; a query carries keyword, email, owner, or company, and never two at once. Choose deliberately:

Parameter Matches against Use it when
company The registrant's organisation field You know the legal or trading entity name and expect corporate registration. The most direct answer to "what does this company own".
owner The registrant's full name You are tracing an individual; a founder, a domainer, a repeat registrant seen in another record.
email The registrant's public email address You have one confirmed contact address. The highest-precision mode, because an email is unique in a way a company name is not.
keyword The domain name string itself Registrant fields are redacted, or you want every domain containing a brand token regardless of who registered it. The only mode that still works under privacy protection, because it never touches registrant data.

For a company investigation: try company first, fall back to keyword when it returns little, and use email or owner to pivot once a lookup on a known domain hands you a real, unredacted contact.

Every reverse search is a single GET against the WHOIS endpoint with whois=reverse:

curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube"

Replace API_KEY with your key from the dashboard and youtube with the organisation you're researching. There are no headers and no request body.

The other three modes are the same call with a different parameter:

curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&owner=google"curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&[email protected]"curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&keyword=youtube"

A few rules govern what you can put in those parameters:

  • Searches are case-insensitive, so Youtube and youtube behave identically.
  • A keyword must be at least 3 and at most 63 characters.
  • company, owner and keyword are substring searches by default. Searching company=meta returns domains whose registrant organization merely contains "meta"; which will include a lot of companies that are not Meta.
  • email is different: it matches exactly, or you can use a pattern such as g***@outlook.com or q*.l*@gmail.com to match a family of addresses.

[IMAGE: 01-reverse-whois-company-request.png] * alt: Terminal running a reverse WHOIS cURL request with the company parameter and the start of the JSON response * caption: One GET request with whois=reverse&company= returns the first page of matching domains. * shows: A terminal with the cURL command and pretty-printed JSON output for a public brand. The key must read API_KEY, never a real value. Roughly 1000px wide, cropped to the command plus the first ten lines of response. No browser chrome. * placement: Immediately after the four cURL examples in Step 2.

Step 3: Tighten a Noisy Result Set with exact

Because substring matching casts a wide net, an exact parameter is available for keyword, owner and company. Set it to true and only records matching the term precisely come back:

curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube&exact=true"

It defaults to false, which is the substring behaviour described above. Two things to keep in mind: exact does not apply to email searches, and turning it on will drop legitimate matches whenever the registrant field carries a suffix your search term doesn't; "YouTube LLC" is not an exact match for "youtube". Start broad, then tighten.

Step 4: Read the Response

The response is a JSON envelope: a small pagination header followed by a full WHOIS record for every matching domain.

{ "total_Result": 6, "total_Pages": 1, "current_Page": 1, "whois_domains_historical": [ { "num": 1, "status": true, "domain_name": "whoisfreaks.com", "query_time": "2026-07-29 15:39:24", "whois_server": "whois.verisign-grs.com", "create_date": "2019-03-19", "update_date": "2026-02-17", "expiry_date": "2027-03-19", "domain_registrar": { "iana_id": "1068", "registrar_name": "NAMECHEAP INC", "whois_server": "whois.namecheap.com", "website_url": "http://www.namecheap.com" }, "registrant_contact": { "name": "Redacted for Privacy", "company": "Privacy service provided by Withheld for Privacy ehf", "country_name": "Iceland", "email_address": "[email protected]" }, "name_servers": ["albert.ns.cloudflare.com", "sue.ns.cloudflare.com"], "domain_status": ["clienttransferprohibited"] } ]}

The fields that matter when you're mapping a portfolio:

Field What to do with it
total_Result How many domains matched in total, across all pages. Your headline number.
total_Pages How many requests it will take to collect everything. Read this before you start looping.
current_Page Which page you're holding. Echoes your page parameter.
num The record's index within the result set.
status true when that individual record resolved cleanly.
create_date Registration date. Cluster these and registration waves jump out; a batch registered on one day is almost always one campaign.
domain_registrar The registrar. A portfolio concentrated at one corporate registrar is a strong signal of genuine common ownership.
registrant_contact The identity fields. Check whether they are real or redacted before you trust them.
name_servers Often the best correlation signal when registrant data is redacted - shared nameservers link domains that WHOIS text cannot.
domain_status EPP status codes, lowercased and without the usual camelCase; clienttransferprohibited, not clientTransferProhibited. Compare case-insensitively.

Two more quirks worth coding around, because they run through the WHOIS payloads generally: domain_registered is the string "yes" or "no", not a boolean, and the raw registry blob is spelled whois_raw_registery; a typo in the API itself. Reproduce both in your parser rather than assuming they'll be fixed.

Step 5: Page Through the Full Result Set

The default mode returns 50 records per page. Read total_Pages, then walk it with the page parameter:

curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube&page=2"

If you only need the domain list and its dates rather than the full contact blocks, mini mode returns 100 records per page and carries just the domain name, create/update/expiry dates, owner name, company and email. Half the requests, a much smaller payload:

curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube&mode=mini&page=1"

For portfolio mapping, mini mode is almost always right on the first pass; enumerate cheaply, then run full lookups on the handful of domains you actually care about. Strategy for very large result sets is covered in How to Paginate Through Large Reverse WHOIS Results.

Step 6: Budget Your Credits and Respect the Rate Limit

This is where reverse WHOIS differs most from an ordinary lookup, and getting it wrong is the most common reason a sweep dies halfway.

A standard WHOIS lookup costs 1 credit. Reverse WHOIS does not: like Historical, IP WHOIS, ASN WHOIS and Bulk WHOIS, it consumes varying credits per page or per successful query, as documented in credit usage. A 40-page sweep is therefore priced as 40 units of work, not one. Plan for that before you loop over total_Pages.

Reverse endpoints also sit in the tightest rate-limit category. On the free tier that is 1 request per minute for reverse and historical calls, against 10 rpm for live lookups and 5 rpm for bulk. Limits are enforced per endpoint category, not globally, so a generous live-endpoint allowance tells you nothing about your reverse allowance.

Every response carries your current position in three headers:

Header Meaning
x-ratelimit-allowed-requests Your ceiling for the window
x-ratelimit-remaining-requests How many you have left
x-ratelimit-remaining-time Time until the window resets, in nanoseconds

Exceed it and you get a 429 with the message "Please slow down. Your maximum request limit per minute is reached." Read the headers and sleep rather than retrying blindly. One piece of good news: 4xx responses do not consume credits, so a throttled or malformed request costs you time but not balance.

Step 7: Deal With the Gaps

When a company search returns fewer domains than you know exist, work the problem in this order:

  1. Switch to keyword. It matches the domain string, not the registrant, so redaction doesn't affect it. For a brand with a distinctive token this often returns far more than company did.
  2. Loosen exact. If you set exact=true, drop it; "Example Ltd" will not exact-match "example".
  3. Pivot on an unredacted record. Run a normal WHOIS lookup on a domain you already know belongs to the target; if any contact field survived, feed that email into an email= search. One unredacted record can unlock a whole cluster.
  4. Correlate on nameservers. Domains sharing an unusual nameserver pair are frequently the same operator even when every WHOIS text field is redacted.
  5. Check history. A domain redacted today may have been public in 2017. WHOIS history is where pre-GDPR registrant data still lives.

Then accept the residual gap honestly. Reporting to a client or a court, say "at least N domains matched on registrant organization" rather than "the company owns N domains"; reverse WHOIS cannot support the second claim.

Summary

Step Action
1 Pick one mode: company, owner, email or keyword; never two
2 GET /v1.0/whois?whois=reverse&company=... with your API key
3 Add exact=true to cut substring noise (not valid for email)
4 Read total_Result / total_Pages, then the record array
5 Walk pages with page=; use mode=mini for 100-per-page enumeration
6 Budget credits per page and stay inside 1 rpm on the free tier
7 Fall back to keyword, nameservers and WHOIS history to close the gaps

Reverse WHOIS turns a single identity into a domain list in one request, which is why it underpins brand protection, M&A due diligence and infrastructure attribution alike. Full parameter reference lives in the Reverse WHOIS API documentation, and the Reverse WHOIS API product page covers plans and coverage. If you'd rather not write code, the same four searches are in the dashboard; see How to Use the WhoisFreaks Reverse WHOIS Tool. To take the output further, How to Use Reverse WHOIS to Map a Domain Portfolio covers structuring results.

Frequently Asked Questions

What is a reverse WHOIS lookup?

It inverts the normal query: instead of supplying a domain and getting its registration details, you supply a detail (company name, registrant name, email, or a keyword in the domain) and get every matching domain. The WhoisFreaks API returns these as paginated JSON from a single GET request.

How do I find every domain a company owns?

GET https://api.whoisfreaks.com/v1.0/whois with whois=reverse and company=, then page through with total_Pages. This only finds domains whose WHOIS still lists the organisation publicly, so run a keyword= search on the brand token to catch what redaction hides.

What's the difference between the keyword, company, owner and email searches?

company, owner and email all match registrant data, so all three are blocked by redaction. keyword matches the domain name text itself, so it keeps working regardless of privacy protection. Only one of the four per request.

Why does my reverse WHOIS search return so few results?

Almost always redaction. Since GDPR, most gTLD registrars hide registrant name, organisation, email and phone by default. Switch to a keyword search, drop exact=true if you set it, and check WHOIS history where pre-redaction data may still be visible.

How many records does each page return?

Default mode returns 50 records per page with the full WHOIS record for each. Mini mode (mode=mini) returns 100 per page but only the domain name, dates, and owner name, company and email. Use total_Pages to size the job.

How many credits does a reverse WHOIS search cost?

More than a standard WHOIS lookup, which is 1 credit; reverse consumes varying credits per page, so multi-page sweeps cost proportionally more. Current figures are in the credit usage documentation. 4xx responses cost nothing.

What happens if I query too fast?

Reverse WHOIS is in the strictest rate-limit category: one request per minute on the free tier, against ten for live lookups. Going over returns a 429. Read x-ratelimit-remaining-time (nanoseconds) and pace your loop rather than retrying on failure.

TIP

Run mode=mini on the first pass of any portfolio sweep. It doubles the records per page and strips the contact blocks you don't need yet, which halves both your page count and your credit spend before you commit to full lookups on the domains that actually matter.

Never report a reverse WHOIS result as a complete portfolio. It is the set of domains whose WHOIS records still publish the value you searched for. Redaction and privacy proxies remove most gTLD registrant data, so the honest phrasing is "at least N domains matched", with the search mode named alongside the number.

When registrant fields come back redacted, correlate on name_servers and create_date instead. Shared nameservers and same-day registration batches survive privacy protection and often identify common ownership more reliably than a company-name match would have.