@herenickname/whoz
v0.1.1
Published
A fast, pretty WHOIS & RDAP CLI for domains and IPs — registrar, ASN, network, geolocation, decoded statuses and availability.
Maintainers
Readme
whoz
A fast, pretty WHOIS & RDAP CLI for the terminal — human-readable domain and IP intelligence with a smooth animated reveal.
whoz is a modern whois client and RDAP client that prints clean,
colorized domain information in your terminal: registrar, registration and
expiry dates, decoded EPP status codes (in plain English, not cryptic
clientTransferProhibited strings), nameservers, DNSSEC, and domain
availability. It queries RDAP first for structured, consistent data and
falls back to WHOIS automatically for TLDs that have no RDAP server (most
ccTLDs like .gg, .sh, .ai).
Pass an IPv4 or IPv6 address and whoz switches to a dedicated network view:
allocation range and CIDRs, netname, RIR, organization, route, origin ASN,
abuse contact, reverse DNS, location and anycast status. IPs are discovered
through the official IANA RDAP bootstrap too, with IP WHOIS as a fallback.
It also resolves the domain live — following the CNAME chain to the final A/AAAA records — and shows the hosting country flag + ISO2 code, plus the registrant/owner when it isn't redacted.
No ads. No API key. Just npx @herenickname/whoz example.com.
╭─ example.com ────────────────────────────────────────────────────╮
│ ● registered — via rdap │
│ │
│ registrar RESERVED-Internet Assigned Numbers Authority │
│ owner redacted (privacy / GDPR) │
│ created 1995-08-14 (30.8y ago) │
│ expires 2026-08-13 (in 76d) │
│ dnssec signed │
│ │
│ nameservers │
│ › a.iana-servers.net │
│ › b.iana-servers.net │
│ │
│ dns │
│ A 93.184.215.14 🇺🇸 US │
│ │
│ status │
│ ● Transfer Locked (registrar) │
│ Registrar blocks transfers — the common anti-hijack lock. │
╰───────────────────────────────────────────────────────────────────╯Features
- 🎨 Pretty, colorized output in a clean rounded box — readable at a glance.
- 🧠 Decoded EPP status codes —
clientTransferProhibitedbecomes "Registrar blocks transfers — the common anti-hijack lock." - 🌐 RDAP first, WHOIS fallback — structured data where it exists, full coverage everywhere else. One consistent output regardless of source.
- ✅ Domain availability — clearly tells you registered vs. available, without false positives on RDAP-less TLDs.
- 🌍 Live DNS resolution — follows the CNAME chain to the final A/AAAA records and shows the hosting country flag + ISO2 for the primary IP.
- 📡 Full IPv4/IPv6 intelligence — allocation range, CIDRs, RIR, network type, route, ASN/provider, abuse contact, reverse DNS and geolocation.
- 👤 Owner / registrant — shows organization, name, country and email when the registry exposes them (and says so plainly when it's redacted).
- ⚡ Smooth animated reveal — spinner while looking up, staggered reveal of results (auto-disabled when piped or in CI).
- 🧩
--jsonmode — normalized, machine-readable output for scripts. - 📦 Tiny & dependency-light — two small deps, zero build step, no API key.
- 🔌 Programmatic API —
import { lookup } from '@herenickname/whoz'.
Install
Run it instantly with npx:
npx @herenickname/whoz example.comOr install globally:
npm install -g @herenickname/whoz
whoz example.comUsage
whoz <domain-or-ip> [domain-or-ip...] [options]Examples
whoz example.com # pretty WHOIS/RDAP for one domain
whoz 178.234.19.55 # network, ASN, RIR, abuse and location for an IP
whoz 2606:4700:4700::1111 # IPv6 works too
whoz cleave.dev cleavekit.io # several domains in one go
whoz openai.gg --whois # force WHOIS (ccTLD with no RDAP)
whoz example.com --json # normalized JSON for scripts
whoz example.com | cat # auto-plain output when pipedOptions
| Option | Description |
| --- | --- |
| --json | Print the normalized result as JSON (disables animation) |
| --rdap | Force RDAP only (skip the WHOIS fallback) |
| --whois | Force WHOIS only (skip RDAP) |
| --no-dns | Skip live DNS resolution (CNAME → A/AAAA or IP reverse DNS) |
| --no-geo | Skip IP geolocation lookups |
| --no-animation | Disable the spinner |
| --no-color | Disable colors (also honors the NO_COLOR env var) |
| --timeout <ms> | Per-lookup timeout in milliseconds (default 12000) |
| -h, --help | Show help |
| -v, --version | Show version |
Programmatic API
whoz is also a library. The normalizer functions are pure and network-free,
so they are easy to test and reuse.
import { lookup, explainStatus } from '@herenickname/whoz';
const rec = await lookup('example.com');
console.log(rec.registrar, rec.expires, rec.available);
for (const s of rec.statuses) {
console.log(s.label, '→', s.human);
}
// Decode a single EPP status code yourself:
console.log(explainStatus('clientHold').human);
// → "Registrar pulled it from the DNS zone — it will not resolve."
const ip = await lookup('1.1.1.1');
console.log(ip.network.range, ip.route, ip.asns, ip.abuse?.email);Domain records retain the normalized shape below. IP records have kind: 'ip'
and expose ip, version, registry, network, route, asns, abuse,
geo and reverseDns alongside the original raw response.
{
domain: string,
available: boolean | null,
source: 'rdap' | 'whois',
registrar?: string,
registrarUrl?: string,
registrarId?: string,
created?: string,
updated?: string,
expires?: string,
statuses: Array<{ key, label, human, tone, raw }>,
nameservers: string[],
dnssec: boolean | string | null,
raw: unknown // the original RDAP/WHOIS payload
}How it works
- Official server lists.
whozresolves the authoritative server for each TLD or IP allocation from IANA, not a third-party redirector:- RDAP from the official IANA RDAP bootstrap
(
dns.json,ipv4.jsonandipv6.json), which maps every RDAP-enabled TLD or address range to its authoritative base URL. - WHOIS from
whois.iana.orgper TLD (whoiser ships a static map that goes stale — e.g..costill points at the long-deadwhois.nic.co).
- RDAP from the official IANA RDAP bootstrap
(
- Local cache. The domain and IP RDAP bootstrap files are refreshed every
7 days under
~/.whoz/; WHOIS servers are cached lazily per TLD, so the server lists aren't fetched on every lookup. Override the location withWHOZ_CACHE_DIR. - RDAP first, WHOIS fallback. If the TLD is in the RDAP bootstrap,
whozqueries its authoritative RDAP server directly for structured JSON. If not (many ccTLDs:.gg,.sh,.ai, …) it falls back to WHOIS viawhoiser, pointed at the IANA server, which normalizes field names across registrars. - One normalized shape. Whichever source answered, you get the same record
and the same pretty output. The
sourcefield tells you which was used.
Because availability comes from the authoritative server's 404 (not a
redirector's), whoz doesn't fall into the classic trap of reporting a
registered domain as "available" just because a TLD lacks RDAP.
- IP intelligence. IPv4/IPv6 inputs use IANA's official IP RDAP bootstrap, the responsible RIR's RDAP service, RIPE NCC routing data for the announced prefix/origin ASN, and IP WHOIS as a registration fallback.
- Live DNS + geo. For a registered domain,
whozalso queries the system DNS resolver to follow the CNAME chain and collect the final A/AAAA records, then geolocates the primary IP. Direct IP queries also request reverse DNS. DNS uses your local resolver; geolocation sends only the IP being looked up to ipinfo.io. Disable with--no-geo(geo only) or--no-dns(DNS only).
Why whoz?
Plain whois output is a wall of inconsistent text that differs per registrar,
and raw RDAP is JSON you have to read yourself. whoz gives you:
- consistent, human-readable fields regardless of registry,
- EPP status codes explained instead of memorized,
- correct availability across both gTLDs and ccTLDs,
- useful network and routing context for IPv4/IPv6 addresses,
- and output that looks good enough to screenshot.
Related
whoiser— the WHOIS/RDAP library powering the fallback path.- RDAP — the modern, structured successor to WHOIS.
- ICANN EPP status codes — the reference for the decoded statuses.
License
MIT © herenickname
