Tutorial
Written By Qasim, WhoisFreaks Team Published: September 28, 2026, Last Updated: September 28, 2026
A normal WHOIS lookup goes one way: you give it a domain, and it tells you who registered it. Reverse WHOIS goes the other way; you give it an identity, and it returns every domain in the WHOIS database that matches. This tutorial shows you how to run that search against the WhoisFreaks Reverse WHOIS API, how to pick the right one of the four search modes, how to page through the results, and; the part most guides skip; how to tell how much of the real portfolio you are actually seeing.
You'll need an API key. If you don't have one yet, sign up and grab your key first; new accounts include 500 free credits, no card required.
Reverse WHOIS searches an index built from WHOIS records. It can only match a value that a WHOIS record actually publishes. That single sentence explains almost every disappointing result set.
Since GDPR, most registrars redact registrant name, organisation, street, phone and email on gTLD records by default, and privacy-proxy services replace them with the proxy's own details. You can see this in a live record for a privacy-protected domain: the registrant contact comes back as "name": "Redacted for Privacy" with a company of "Privacy service provided by Withheld for Privacy ehf" and a rotating alias address such as [email protected]. A company= search will never match that domain to its real owner, because the real owner's name is not in the record.
So treat every result set as a floor, not a census. It tells you, "At least these domains match", never "these are all the domains this company owns". Corporate registrars used by large brands; the ones that keep the organization field populated deliberately; tend to return good results. Domains registered through consumer registrars with privacy enabled tend to return nothing at all. That limitation is also why four search modes exist: different identities survive redaction differently, and picking the right one is the whole skill.
The API accepts exactly one search parameter per request. You cannot combine them; a query carries keyword, email, owner, or company, and never two at once. Choose deliberately:
| Parameter | Matches against | Use it when |
| company | The registrant's organisation field | You know the legal or trading entity name and expect corporate registration. The most direct answer to "what does this company own". |
| owner | The registrant's full name | You are tracing an individual; a founder, a domainer, a repeat registrant seen in another record. |
| The registrant's public email address | You have one confirmed contact address. The highest-precision mode, because an email is unique in a way a company name is not. | |
| keyword | The domain name string itself | Registrant fields are redacted, or you want every domain containing a brand token regardless of who registered it. The only mode that still works under privacy protection, because it never touches registrant data. |
For a company investigation: try company first, fall back to keyword when it returns little, and use email or owner to pivot once a lookup on a known domain hands you a real, unredacted contact.
Every reverse search is a single GET against the WHOIS endpoint with whois=reverse:
curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube"
Replace API_KEY with your key from the dashboard and youtube with the organisation you're researching. There are no headers and no request body.
The other three modes are the same call with a different parameter:
curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&owner=google"curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&[email protected]"curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&keyword=youtube"
A few rules govern what you can put in those parameters:
[IMAGE: 01-reverse-whois-company-request.png] * alt: Terminal running a reverse WHOIS cURL request with the company parameter and the start of the JSON response * caption: One GET request with whois=reverse&company= returns the first page of matching domains. * shows: A terminal with the cURL command and pretty-printed JSON output for a public brand. The key must read API_KEY, never a real value. Roughly 1000px wide, cropped to the command plus the first ten lines of response. No browser chrome. * placement: Immediately after the four cURL examples in Step 2.
Because substring matching casts a wide net, an exact parameter is available for keyword, owner and company. Set it to true and only records matching the term precisely come back:
curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube&exact=true"
It defaults to false, which is the substring behaviour described above. Two things to keep in mind: exact does not apply to email searches, and turning it on will drop legitimate matches whenever the registrant field carries a suffix your search term doesn't; "YouTube LLC" is not an exact match for "youtube". Start broad, then tighten.
The response is a JSON envelope: a small pagination header followed by a full WHOIS record for every matching domain.
{ "total_Result": 6, "total_Pages": 1, "current_Page": 1, "whois_domains_historical": [ { "num": 1, "status": true, "domain_name": "whoisfreaks.com", "query_time": "2026-07-29 15:39:24", "whois_server": "whois.verisign-grs.com", "create_date": "2019-03-19", "update_date": "2026-02-17", "expiry_date": "2027-03-19", "domain_registrar": { "iana_id": "1068", "registrar_name": "NAMECHEAP INC", "whois_server": "whois.namecheap.com", "website_url": "http://www.namecheap.com" }, "registrant_contact": { "name": "Redacted for Privacy", "company": "Privacy service provided by Withheld for Privacy ehf", "country_name": "Iceland", "email_address": "[email protected]" }, "name_servers": ["albert.ns.cloudflare.com", "sue.ns.cloudflare.com"], "domain_status": ["clienttransferprohibited"] } ]}
| Field | What to do with it |
| total_Result | How many domains matched in total, across all pages. Your headline number. |
| total_Pages | How many requests it will take to collect everything. Read this before you start looping. |
| current_Page | Which page you're holding. Echoes your page parameter. |
| num | The record's index within the result set. |
| status | true when that individual record resolved cleanly. |
| create_date | Registration date. Cluster these and registration waves jump out; a batch registered on one day is almost always one campaign. |
| domain_registrar | The registrar. A portfolio concentrated at one corporate registrar is a strong signal of genuine common ownership. |
| registrant_contact | The identity fields. Check whether they are real or redacted before you trust them. |
| name_servers | Often the best correlation signal when registrant data is redacted - shared nameservers link domains that WHOIS text cannot. |
| domain_status | EPP status codes, lowercased and without the usual camelCase; clienttransferprohibited, not clientTransferProhibited. Compare case-insensitively. |
Two more quirks worth coding around, because they run through the WHOIS payloads generally: domain_registered is the string "yes" or "no", not a boolean, and the raw registry blob is spelled whois_raw_registery; a typo in the API itself. Reproduce both in your parser rather than assuming they'll be fixed.
The default mode returns 50 records per page. Read total_Pages, then walk it with the page parameter:
curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube&page=2"
If you only need the domain list and its dates rather than the full contact blocks, mini mode returns 100 records per page and carries just the domain name, create/update/expiry dates, owner name, company and email. Half the requests, a much smaller payload:
curl "https://api.whoisfreaks.com/v1.0/whois?apiKey=API_KEY&whois=reverse&company=youtube&mode=mini&page=1"
For portfolio mapping, mini mode is almost always right on the first pass; enumerate cheaply, then run full lookups on the handful of domains you actually care about. Strategy for very large result sets is covered in How to Paginate Through Large Reverse WHOIS Results.
This is where reverse WHOIS differs most from an ordinary lookup, and getting it wrong is the most common reason a sweep dies halfway.
A standard WHOIS lookup costs 1 credit. Reverse WHOIS does not: like Historical, IP WHOIS, ASN WHOIS and Bulk WHOIS, it consumes varying credits per page or per successful query, as documented in credit usage. A 40-page sweep is therefore priced as 40 units of work, not one. Plan for that before you loop over total_Pages.
Reverse endpoints also sit in the tightest rate-limit category. On the free tier that is 1 request per minute for reverse and historical calls, against 10 rpm for live lookups and 5 rpm for bulk. Limits are enforced per endpoint category, not globally, so a generous live-endpoint allowance tells you nothing about your reverse allowance.
Every response carries your current position in three headers:
| Header | Meaning |
| x-ratelimit-allowed-requests | Your ceiling for the window |
| x-ratelimit-remaining-requests | How many you have left |
| x-ratelimit-remaining-time | Time until the window resets, in nanoseconds |
Exceed it and you get a 429 with the message "Please slow down. Your maximum request limit per minute is reached." Read the headers and sleep rather than retrying blindly. One piece of good news: 4xx responses do not consume credits, so a throttled or malformed request costs you time but not balance.
When a company search returns fewer domains than you know exist, work the problem in this order:
Then accept the residual gap honestly. Reporting to a client or a court, say "at least N domains matched on registrant organization" rather than "the company owns N domains"; reverse WHOIS cannot support the second claim.
| Step | Action |
| 1 | Pick one mode: company, owner, email or keyword; never two |
| 2 | GET /v1.0/whois?whois=reverse&company=... with your API key |
| 3 | Add exact=true to cut substring noise (not valid for email) |
| 4 | Read total_Result / total_Pages, then the record array |
| 5 | Walk pages with page=; use mode=mini for 100-per-page enumeration |
| 6 | Budget credits per page and stay inside 1 rpm on the free tier |
| 7 | Fall back to keyword, nameservers and WHOIS history to close the gaps |
Reverse WHOIS turns a single identity into a domain list in one request, which is why it underpins brand protection, M&A due diligence and infrastructure attribution alike. Full parameter reference lives in the Reverse WHOIS API documentation, and the Reverse WHOIS API product page covers plans and coverage. If you'd rather not write code, the same four searches are in the dashboard; see How to Use the WhoisFreaks Reverse WHOIS Tool. To take the output further, How to Use Reverse WHOIS to Map a Domain Portfolio covers structuring results.
It inverts the normal query: instead of supplying a domain and getting its registration details, you supply a detail (company name, registrant name, email, or a keyword in the domain) and get every matching domain. The WhoisFreaks API returns these as paginated JSON from a single GET request.
GET https://api.whoisfreaks.com/v1.0/whois with whois=reverse and company=, then page through with total_Pages. This only finds domains whose WHOIS still lists the organisation publicly, so run a keyword= search on the brand token to catch what redaction hides.
company, owner and email all match registrant data, so all three are blocked by redaction. keyword matches the domain name text itself, so it keeps working regardless of privacy protection. Only one of the four per request.
Almost always redaction. Since GDPR, most gTLD registrars hide registrant name, organisation, email and phone by default. Switch to a keyword search, drop exact=true if you set it, and check WHOIS history where pre-redaction data may still be visible.
Default mode returns 50 records per page with the full WHOIS record for each. Mini mode (mode=mini) returns 100 per page but only the domain name, dates, and owner name, company and email. Use total_Pages to size the job.
More than a standard WHOIS lookup, which is 1 credit; reverse consumes varying credits per page, so multi-page sweeps cost proportionally more. Current figures are in the credit usage documentation. 4xx responses cost nothing.
Reverse WHOIS is in the strictest rate-limit category: one request per minute on the free tier, against ten for live lookups. Going over returns a 429. Read x-ratelimit-remaining-time (nanoseconds) and pace your loop rather than retrying on failure.
Run mode=mini on the first pass of any portfolio sweep. It doubles the records per page and strips the contact blocks you don't need yet, which halves both your page count and your credit spend before you commit to full lookups on the domains that actually matter.
Never report a reverse WHOIS result as a complete portfolio. It is the set of domains whose WHOIS records still publish the value you searched for. Redaction and privacy proxies remove most gTLD registrant data, so the honest phrasing is "at least N domains matched", with the search mode named alongside the number.
When registrant fields come back redacted, correlate on name_servers and create_date instead. Shared nameservers and same-day registration batches survive privacy protection and often identify common ownership more reliably than a company-name match would have.
Pull WHOIS, live DNS, and subdomains from WhoisFreaks in XSOAR. Score the domain before any block fires. Auto-block high-risk or route to analyst review.
12 min read

ExpiredDomains.net does not offer any API to integrate its services into customer infrastructure. To access expired or deleted domain names via an API, you would need to rely on scraping or third‑party providers.
9 min read