{"id":15573,"date":"2026-09-05T14:58:34","date_gmt":"2026-09-05T12:58:34","guid":{"rendered":"https:\/\/www.lukaswojcik.com\/blog\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/"},"modified":"2026-09-05T14:58:34","modified_gmt":"2026-09-05T12:58:34","slug":"domain-rdap-certificate-transparency-subdomain-lookup","status":"publish","type":"page","link":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/","title":{"rendered":"Domain RDAP &#038; Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains"},"content":{"rendered":"<div class=\"gtm-analyser-container\" style=\"background: var(--bg-panel, #1e1e24); padding: 25px; border-radius: 8px; border: 1px solid var(--border, #2a2a35);\">\n<p style=\"color: var(--text-secondary, #a0a0b0); margin-bottom: 20px;\">Two public registers describe a domain without touching its servers. RDAP, the successor of WHOIS, is what the registry knows: registrar, registration and expiry dates, status codes such as a transfer lock, nameservers, DNSSEC delegation. Certificate Transparency is what every certificate authority had to log since 2018: every host name that ever received a certificate. Read together they answer questions a site owner rarely asks until it is late: when does the domain expire, is it locked against transfer, and which subdomains still exist somewhere because a certificate was once issued for them.<\/p>\n<div style=\"margin-bottom: 14px;\">\n        <label for=\"rc-domain\" style=\"color: var(--text-secondary, #a0a0b0); display: block; font-size: 0.85rem; margin-bottom: 5px;\">Domain (without www)<\/label><br \/>\n        <input id=\"rc-domain\" type=\"text\" value=\"wikipedia.org\" class=\"form-control\" style=\"width: 100%; padding: 10px; background: var(--bg-body, #14141a); border: 1px solid var(--border, #2a2a35); color: var(--text-primary, #e8e8ee); border-radius: 6px; box-sizing: border-box; font-family: monospace;\">\n    <\/div>\n<p style=\"color: var(--text-secondary, #a0a0b0); font-size: 0.82rem; margin-bottom: 16px;\">From this server: one RDAP query via rdap.org, which redirects to the responsible registry, for registries without RDAP a whois query, and one query to crt.sh for the certificate logs. Nothing on the domain itself is contacted. The query is protected by reCAPTCHA v3; the calling IP address and the domain are stored for one hour to limit the rate.<\/p>\n<p>    <button id=\"rc-btn\" class=\"button\" style=\"background: var(--accent, #7ee787); color: var(--on-accent, #0b1114); border: none; padding: 12px 24px; border-radius: 6px; font-weight: 700; cursor: pointer;\">Look up the domain<\/button><\/p>\n<div id=\"rc-ausgabe\" style=\"margin-top: 22px;\"><\/div>\n<p style=\"color: var(--text-secondary, #a0a0b0); font-size: 0.8rem; margin: 24px 0 0;\">Limits worth knowing: RDAP data depends on the registry, and some (such as .de) publish no RDAP, so whois text is parsed instead, with fewer fields; crt.sh answers are cut at 3 MB, which for very large domains leaves out old certificates; a name in the logs proves a certificate was issued, not that the host still answers; and registrant details are not shown, because registries no longer publish them.<\/p>\n<\/div>\n<p><script>\n(function () {\n    'use strict';<\/p>\n<p>    const T = {\"einleitung\":\"Two public registers describe a domain without touching its servers. RDAP, the successor of WHOIS, is what the registry knows: registrar, registration and expiry dates, status codes such as a transfer lock, nameservers, DNSSEC delegation. Certificate Transparency is what every certificate authority had to log since 2018: every host name that ever received a certificate. Read together they answer questions a site owner rarely asks until it is late: when does the domain expire, is it locked against transfer, and which subdomains still exist somewhere because a certificate was once issued for them.\",\"label_domain\":\"Domain (without www)\",\"datenschutz\":\"From this server: one RDAP query via rdap.org, which redirects to the responsible registry, for registries without RDAP a whois query, and one query to crt.sh for the certificate logs. Nothing on the domain itself is contacted. The query is protected by reCAPTCHA v3; the calling IP address and the domain are stored for one hour to limit the rate.\",\"knopf\":\"Look up the domain\",\"laeuft\":\"Asking the registry and the certificate logs...\",\"grenze\":\"Limits worth knowing: RDAP data depends on the registry, and some (such as .de) publish no RDAP, so whois text is parsed instead, with fewer fields; crt.sh answers are cut at 3 MB, which for very large domains leaves out old certificates; a name in the logs proves a certificate was issued, not that the host still answers; and registrant details are not shown, because registries no longer publish them.\",\"h_registrierung\":\"Registration\",\"quelle_whois\":\"from whois, no RDAP for this registry\",\"zeile_domain\":\"Domain\",\"zeile_registrar\":\"Registrar\",\"zeile_registriert\":\"Registered\",\"zeile_ablauf\":\"Expires\",\"zeile_geaendert\":\"Last changed\",\"zeile_status\":\"Status\",\"zeile_nameserver\":\"Nameservers\",\"zeile_dnssec\":\"DNSSEC delegation\",\"zeile_dauer\":\"Took\",\"zeile_limit\":\"Lookups left this hour\",\"wert_unbekannt\":\"unknown\",\"wert_keine_daten\":\"no registration data readable\",\"ja\":\"yes\",\"nein\":\"no\",\"h_ct\":\"Certificate Transparency\",\"zeile_zertifikate\":\"Certificates logged\",\"zeile_namen\":\"Distinct host names\",\"zeile_aussteller\":\"Issuers\",\"ct_kurz\":\"{zertifikate}, of which {aktiv} still valid, {neu} issued in the last 30 days\",\"spalte_name\":\"Host name\",\"spalte_erste\":\"First seen\",\"spalte_letzte\":\"Last valid until\",\"spalte_n\":\"Certs\",\"spalte_zustand\":\"State\",\"name_aktiv\":\"valid certificate\",\"name_abgelaufen\":\"no valid certificate\",\"name_wildcard\":\"wildcard\",\"h_befunde\":\"Findings\",\"stufe_hoch\":\"High\",\"stufe_mittel\":\"Medium\",\"stufe_niedrig\":\"Low\",\"stufe_info\":\"Information\",\"stufe_gut\":\"In order\",\"keine_befunde\":\"Nothing to report.\",\"urteil_gut\":\"Registration and certificate history show nothing that needs action.\",\"urteil_warnung\":\"Something needs attention within the next weeks.\",\"urteil_kritisch\":\"The domain is about to expire, expired, or on hold.\",\"fehler_kein_token\":\"The check could not be started because reCAPTCHA did not load.\",\"fehler_captcha\":\"reCAPTCHA classified the request as automated. Reloading the page normally helps.\",\"fehler_zu_viele\":\"The limit of {limit} lookups per hour for this address has been reached.\",\"fehler_adresse\":\"That domain cannot be used.\",\"fehler_zaehler\":\"The rate counter is unavailable, so nothing was checked.\",\"fehler_pruefdienst\":\"The reCAPTCHA service could not be reached.\",\"fehler_aufbau\":\"The service is not configured correctly. The fault is on this side.\",\"fehler_eingabe\":\"The request could not be read.\",\"fehler_methode\":\"Wrong request method.\",\"fehler_netz\":\"The service could not be reached.\",\"fehler_antwort\":\"The answer could not be read.\",\"fehler_unbekannt\":\"Something went wrong that has no message of its own.\",\"grund_leer\":\"Nothing was entered.\",\"grund_zu_lang\":\"The input is too long.\",\"grund_kein_punkt\":\"The domain needs at least one dot.\",\"grund_hostform\":\"Enter a domain name, not an IP address.\",\"befund_rdap_fehlt\":\"No registration data ({status} {fehler}) || Neither RDAP nor whois returned anything readable for this domain. Either it is not registered, or the registry answers in a format this check does not parse.\",\"befund_whois_rueckfall\":\"Registry without RDAP: whois text parsed instead || Some registries, .de among them, publish no RDAP service. The whois text carries fewer fields and no standard format, so dates and status may be missing.\",\"befund_registrierung\":\"Registrar {registrar} (IANA {iana}), registered {registriert}, last changed {geaendert} || What the registry records about the domain.\",\"befund_alter\":\"Domain age: {jahre} years || Older domains carry weight with spam filters, search engines and certificate authorities alike.\",\"befund_abgelaufen\":\"The domain expired on {datum}, {tage} day(s) ago || After expiry, most registries hold the name in a grace period, then redemption, then release it. Mail and web stop working during that time. Renewal is the only action that matters now.\",\"befund_laeuft_ab\":\"The domain expires in {tage} day(s), on {datum} || Less than a month. If auto-renewal is not set up or the payment method has lapsed, the domain lapses with it. A check with the registrar is due today.\",\"befund_laeuft_bald_ab\":\"The domain expires in {tage} days, on {datum} || Within three months. Time to confirm that renewal is automatic and the contact address at the registrar still works.\",\"befund_ablauf_ok\":\"The domain is registered until {datum} ({tage} days) || Expiry is not a concern right now.\",\"befund_ablauf_unbekannt\":\"No expiry date available || This registry does not publish it, which is common for country-code domains.\",\"befund_status_hold\":\"Domain on hold or pending deletion: {liste} || A hold status takes the domain out of DNS; pending delete means it is about to be released. Either way, the site and mail are down or about to be. The registrar can say why.\",\"befund_transfer_gesperrt\":\"Transfer lock set ({liste}) || A transfer to another registrar needs the lock removed first. This is the default protection against domain hijacking and should stay on.\",\"befund_transfer_offen\":\"No transfer lock (status: {liste}) || Without clientTransferProhibited, a transfer request only needs the auth code. Most registrars offer the lock for free; it should be on for any domain that matters.\",\"befund_status_liste\":\"Status codes: {liste} || The EPP status codes the registry reports.\",\"befund_nameserver\":\"{n} nameserver(s): {liste} || The servers the registry delegates the domain to.\",\"befund_nameserver_einer\":\"Only one nameserver || A single nameserver is a single point of failure for the whole domain. Registries require two; most DNS providers give at least two.\",\"befund_nameserver_ein_anbieter\":\"All nameservers under {anbieter} || Fine for a managed DNS provider with anycast; a risk when it is one small host, because the domain depends on that provider entirely.\",\"befund_nameserver_fehlen\":\"No nameservers listed || The registry has no delegation on record. The domain does not resolve until nameservers are set.\",\"befund_dnssec_ja\":\"DNSSEC delegation signed || The registry holds a DS record for the domain, so resolvers can validate its answers. Prerequisite for DANE.\",\"befund_dnssec_nein\":\"No DNSSEC delegation || Answers for this domain cannot be validated. Optional; most domains do without, and a broken DNSSEC setup takes the domain offline, so it is worth doing carefully or not at all.\",\"befund_ct_fehlt\":\"Certificate logs not available ({status} {fehler}) || crt.sh did not answer in time or returned an error. It is a volunteer service and often slow for large domains; trying again later usually works.\",\"befund_ct\":\"{zertifikate} certificates logged for {namen} host names, {aktiv} still valid, {neu} issued in the last 30 days || Every publicly trusted certificate is logged; this is the complete history the logs hold for the domain.\",\"befund_ct_gekappt\":\"Certificate log answer cut at 3 MB || Very large domains have more history than fits; the oldest entries are missing.\",\"befund_ct_wildcard\":\"{n} wildcard certificate name(s): {liste} || A wildcard covers every host name one level below. Convenient, but a leaked key covers all of them at once.\",\"befund_ct_subdomains\":\"{n} subdomain(s) seen in the logs, {aktiv} with a valid certificate: {liste} || Host names beyond the domain and www. Each one is a host that exists or existed and was reachable enough to get a certificate.\",\"befund_ct_vergessen\":\"{n} subdomain(s) with no valid certificate for more than 90 days: {liste} || Names that once had a certificate and have not renewed. Often forgotten hosts: a staging server, an old CMS, a test instance. If the DNS name still exists, the host is still findable, and an unmaintained host is where break-ins start.\",\"befund_ct_aussteller\":\"Issuers: {liste} || Which certificate authorities issued for this domain. A CAA record can restrict this list.\",\"befund_ct_neu\":\"{n} certificate(s) issued in the last 30 days || Recent issuance. Unexpected entries here are worth a look: someone obtained a certificate for a name under this domain.\",\"befund_ct_viele_aussteller\":\"{n} different issuers || Several authorities issued for this domain. Normal for large organisations; for a small site it suggests services were set up in different places without a common rule.\"};<\/p>\n<p>    var ENDPUNKT = '\/lw-rdapct.php';\n    var SITEKEY = '6LcrPkEtAAAAAPo1QCOf-IIM2fCL0UfdJz4y2iSY';\n    var STUFEN = ['hoch', 'mittel', 'niedrig', 'info', 'gut'];<\/p>\n<p>    function liste(w) { return Array.isArray(w) ? w : []; }\n    function zahl(w) { return (typeof w === 'number' && isFinite(w)) ? w : null; }\n    function text(schluessel, daten) {\n        var t = T[schluessel];\n        if (typeof t !== 'string') { return null; }\n        return t.replace(\/\\{([a-z_0-9]+)\\}\/g, function (m, k) {\n            return (daten && daten[k] !== undefined && daten[k] !== null) ? String(daten[k]) : m;\n        });\n    }<\/p>\n<p>    function bewerten(antwort) {\n        var a = antwort || {};\n        if (a.fehler) { return { fehler: String(a.fehler), grund: a.grund || null, limit: zahl(a.limit) }; }\n        var befunde = liste(a.befunde).map(function (f) {\n            return { key: String(f.key || ''), stufe: STUFEN.indexOf(f.stufe) === -1 ? 'info' : f.stufe, daten: (f.daten && typeof f.daten === 'object') ? f.daten : {} };\n        });\n        var gruppen = {};\n        STUFEN.forEach(function (s) { gruppen[s] = befunde.filter(function (f) { return f.stufe === s; }); });\n        var r = (a.rdap && typeof a.rdap === 'object') ? a.rdap : null;\n        var c = (a.ct && typeof a.ct === 'object') ? a.ct : null;\n        var aussteller = [];\n        if (c && c.aussteller && typeof c.aussteller === 'object') { Object.keys(c.aussteller).forEach(function (k) { aussteller.push({ name: k, n: zahl(c.aussteller[k]) || 0 }); }); }\n        return {\n            fehler: null, domain: a.domain ? String(a.domain) : '',\n            urteil: (a.urteil === 'gut' || a.urteil === 'warnung' || a.urteil === 'kritisch') ? a.urteil : 'kritisch',\n            rdap: r ? { quelle: r.quelle === 'whois' ? 'whois' : 'rdap', registrar: r.registrar ? String(r.registrar) : null, registrarIana: r.registrar_iana ? String(r.registrar_iana) : null, registriert: r.registriert ? String(r.registriert) : null, ablauf: r.ablauf ? String(r.ablauf) : null, geaendert: r.geaendert ? String(r.geaendert) : null, status: liste(r.status).map(String), nameserver: liste(r.nameserver).map(String), dnssec: (r.dnssec === true || r.dnssec === false) ? r.dnssec : null } : null,\n            ct: c ? { zertifikate: zahl(c.zertifikate) || 0, namen: zahl(c.namen) || 0, aktiv: zahl(c.aktiv) || 0, neu30: zahl(c.neu_30) || 0, aussteller: aussteller, liste: liste(c.liste).map(function (n) { n = n || {}; return { name: String(n.name || ''), erste: n.erste ? String(n.erste) : null, letzte: n.letzte ? String(n.letzte) : null, n: zahl(n.n) || 0, aktiv: !!n.aktiv, wildcard: !!n.wildcard }; }) } : null,\n            befunde: befunde, gruppen: gruppen, dauer: zahl(a.dauer_ms), limitRest: zahl(a.limit_rest)\n        };\n    }<\/p>\n<p>    function skriptLaden() {\n        return new Promise(function (auf) {\n            if (window.grecaptcha) { auf(true); return; }\n            var s = document.createElement('script');\n            s.src = 'https:\/\/www.google.com\/recaptcha\/api.js?render=' + SITEKEY;\n            s.onload = function () { auf(true); }; s.onerror = function () { auf(false); };\n            document.head.appendChild(s);\n            setTimeout(function () { auf(!!window.grecaptcha); }, 8000);\n        });\n    }\n    function tokenHolen() {\n        return skriptLaden().then(function (da) {\n            if (!da || !window.grecaptcha || !window.grecaptcha.ready) { return null; }\n            return new Promise(function (auf) {\n                var fertig = false;\n                function einmal(w) { if (!fertig) { fertig = true; auf(w); } }\n                setTimeout(function () { einmal(null); }, 12000);\n                try {\n                    window.grecaptcha.ready(function () {\n                        if (fertig) { return; }\n                        if (!window.grecaptcha.execute) { einmal(null); return; }\n                        window.grecaptcha.execute(SITEKEY, { action: 'rdapct' }).then(function (t) { einmal(t || null); }, function () { einmal(null); });\n                    });\n                } catch (e) { einmal(null); }\n            });\n        }, function () { return null; });\n    }\n    function abfragen(domain) {\n        return tokenHolen().then(function (token) {\n            return fetch(ENDPUNKT, { method: 'POST', headers: { 'Content-Type': 'application\/json' }, body: JSON.stringify({ domain: domain, token: token || '' }) })\n                .then(function (r) { return r.json().then(function (j) { return j; }, function () { return { fehler: 'antwort' }; }); }, function () { return { fehler: 'netz' }; });\n        });\n    }<\/p>\n<p>    window.LW_TEST = window.LW_TEST || {};\n    window.LW_TEST.RC = { bewerten: bewerten, darstellen: null, text: text, ENDPUNKT: ENDPUNKT, STUFEN: STUFEN, T: T };<\/p>\n<p>    var btn = document.getElementById('rc-btn');\n    var out = document.getElementById('rc-ausgabe');\n    if (!btn || !out) { return; }<\/p>\n<p>    function el(tag, stil, txt) { var e = document.createElement(tag); if (stil) { e.setAttribute('style', stil); } if (txt !== undefined && txt !== null) { e.textContent = txt; } return e; }\n    function wert(id) { var e = document.getElementById(id); return e ? e.value : ''; }\n    var UEBERSCHRIFT = 'font-family: \"Nunito Sans\", sans-serif; font-weight: 700; color: var(--text-primary, #e8e8ee); font-size: 0.95rem; margin: 22px 0 8px;';\n    var ZELLE = 'padding: 5px 12px 5px 0; color: var(--text-secondary, #a0a0b0); font-size: 0.87rem;';\n    var ZELLE_WERT = 'padding: 5px 12px 5px 0; color: var(--text-primary, #e8e8ee); font-size: 0.87rem; font-family: monospace; word-break: break-all;';\n    var KASTEN = 'background: var(--bg-body, #14141a); border: 1px solid var(--border, #2a2a35); border-radius: 8px; padding: 14px 16px; margin: 0 0 10px;';\n    var GUT = ' color: #7ee787;', WARN = ' color: #ffa94d;', ROT = ' color: #ff7b72;', GRAU = ' color: #8a8a99;';\n    var FARBEN = { hoch: '#ff7b72', mittel: '#ffa94d', niedrig: '#e3b341', info: '#8a8a99', gut: '#7ee787' };\n    var URTEIL = { gut: GUT, warnung: WARN, kritisch: ROT };\n    function gitter(sp) { return el('div', 'display: grid; grid-template-columns: ' + sp + '; gap: 0 18px; align-items: baseline;'); }\n    function paar(g, n, w, stil) { g.appendChild(el('div', ZELLE, n)); g.appendChild(el('div', ZELLE_WERT + (stil || ''), w)); }<\/p>\n<p>    function darstellen(b, ziel) {\n        ziel.innerHTML = '';\n        if (b.fehler) {\n            var txt = T['fehler_' + b.fehler] || T.fehler_unbekannt;\n            if (b.grund && T['grund_' + b.grund]) { txt = txt + ' ' + T['grund_' + b.grund]; }\n            if (b.limit !== null) { txt = txt.replace('{limit}', String(b.limit)); }\n            ziel.appendChild(el('p', ZELLE + WARN + ' margin: 0;', txt));\n            return;\n        }\n        ziel.appendChild(el('div', 'font-size: 1.05rem; font-weight: 700; margin: 0 0 12px;' + URTEIL[b.urteil], T['urteil_' + b.urteil]));<\/p>\n<p>        ziel.appendChild(el('div', UEBERSCHRIFT, T.h_registrierung + (b.rdap && b.rdap.quelle === 'whois' ? ' (' + T.quelle_whois + ')' : '')));\n        var g = gitter('auto auto');\n        paar(g, T.zeile_domain, b.domain);\n        if (b.rdap) {\n            paar(g, T.zeile_registrar, (b.rdap.registrar || '-') + (b.rdap.registrarIana ? ' (IANA ' + b.rdap.registrarIana + ')' : ''));\n            paar(g, T.zeile_registriert, b.rdap.registriert || '-', GRAU);\n            paar(g, T.zeile_ablauf, b.rdap.ablauf || T.wert_unbekannt, b.rdap.ablauf ? '' : GRAU);\n            paar(g, T.zeile_geaendert, b.rdap.geaendert || '-', GRAU);\n            paar(g, T.zeile_status, b.rdap.status.length ? b.rdap.status.join(', ') : '-', GRAU);\n            paar(g, T.zeile_nameserver, b.rdap.nameserver.length ? b.rdap.nameserver.join(', ') : '-', GRAU);\n            paar(g, T.zeile_dnssec, b.rdap.dnssec === null ? T.wert_unbekannt : (b.rdap.dnssec ? T.ja : T.nein), b.rdap.dnssec ? GUT : GRAU);\n        } else { paar(g, T.zeile_registrar, T.wert_keine_daten, WARN); }\n        if (b.dauer !== null) { paar(g, T.zeile_dauer, b.dauer + ' ms', GRAU); }\n        if (b.limitRest !== null) { paar(g, T.zeile_limit, String(b.limitRest), GRAU); }\n        ziel.appendChild(g);<\/p>\n<p>        if (b.ct) {\n            ziel.appendChild(el('div', UEBERSCHRIFT, T.h_ct));\n            var gc = gitter('auto auto');\n            paar(gc, T.zeile_zertifikate, text('ct_kurz', { zertifikate: b.ct.zertifikate, aktiv: b.ct.aktiv, neu: b.ct.neu30 }));\n            paar(gc, T.zeile_namen, String(b.ct.namen));\n            if (b.ct.aussteller.length) { paar(gc, T.zeile_aussteller, b.ct.aussteller.map(function (x) { return x.name + ' (' + x.n + ')'; }).join(', '), GRAU); }\n            ziel.appendChild(gc);\n            if (b.ct.liste.length) {\n                var huelle = el('div', 'overflow-x: auto; max-height: 420px; overflow-y: auto;');\n                var gp = gitter('auto auto auto auto auto');\n                [T.spalte_name, T.spalte_erste, T.spalte_letzte, T.spalte_n, T.spalte_zustand].forEach(function (s) { gp.appendChild(el('div', ZELLE + ' font-weight: 700; color: var(--text-primary, #e8e8ee); white-space: nowrap;', s)); });\n                b.ct.liste.forEach(function (n) {\n                    gp.appendChild(el('div', ZELLE_WERT, n.name));\n                    gp.appendChild(el('div', ZELLE_WERT + GRAU, n.erste || '-'));\n                    gp.appendChild(el('div', ZELLE_WERT + GRAU, n.letzte || '-'));\n                    gp.appendChild(el('div', ZELLE_WERT + GRAU, String(n.n)));\n                    gp.appendChild(el('div', ZELLE_WERT + (n.aktiv ? GUT : WARN) + ' white-space: nowrap;', (n.aktiv ? T.name_aktiv : T.name_abgelaufen) + (n.wildcard ? ' \u00b7 ' + T.name_wildcard : '')));\n                });\n                huelle.appendChild(gp);\n                ziel.appendChild(huelle);\n            }\n        }<\/p>\n<p>        ziel.appendChild(el('div', UEBERSCHRIFT, T.h_befunde));\n        var irgendwas = false;\n        STUFEN.forEach(function (s) {\n            var gr = b.gruppen[s];\n            if (!gr.length) { return; }\n            irgendwas = true;\n            ziel.appendChild(el('div', 'font-weight: 700; font-size: 0.82rem; text-transform: uppercase; letter-spacing: 0.5px; margin: 14px 0 6px; color: ' + FARBEN[s] + ';', T['stufe_' + s] + ' (' + gr.length + ')'));\n            gr.forEach(function (f) {\n                var k = el('div', KASTEN + ' border-left: 3px solid ' + FARBEN[s] + ';');\n                var t = text('befund_' + f.key, f.daten) || f.key;\n                var teile = t.split(' || ');\n                k.appendChild(el('div', 'color: var(--text-primary, #e8e8ee); font-size: 0.9rem; font-weight: 700;', teile[0]));\n                if (teile[1]) { k.appendChild(el('div', ZELLE + ' padding: 6px 0 0; line-height: 1.55;', teile[1])); }\n                ziel.appendChild(k);\n            });\n        });\n        if (!irgendwas) { ziel.appendChild(el('p', ZELLE + ' margin: 0;', T.keine_befunde)); }\n    }\n    window.LW_TEST.RC.darstellen = darstellen;<\/p>\n<p>    var laeuft = false;\n    btn.addEventListener('click', function () {\n        if (laeuft) { return; }\n        laeuft = true; btn.disabled = true;\n        out.innerHTML = '';\n        out.appendChild(el('p', ZELLE + GRAU + ' margin: 0;', T.laeuft));\n        abfragen(wert('rc-domain')).then(function (a) { darstellen(bewerten(a), out); laeuft = false; btn.disabled = false; },\n            function () { darstellen(bewerten({ fehler: 'netz' }), out); laeuft = false; btn.disabled = false; });\n    });\n})();\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Asks the registry via RDAP who a domain is registered with, when it was created and when it expires, which status locks apply, which nameservers serve it and whether DNSSEC is delegated, then reads Certificate Transparency logs for every host name a certificate was ever issued for, including subdomains nobody remembers.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":38,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-tool-base.php","meta":{"footnotes":""},"tags":[91144,91243,91115],"class_list":["post-15573","page","type-page","status-publish","hentry","tag-devops","tag-networking","tag-web-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Domain RDAP &amp; Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains - Lukas Wojcik - Blog<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Domain RDAP &amp; Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains - Lukas Wojcik - Blog\" \/>\n<meta property=\"og:description\" content=\"Asks the registry via RDAP who a domain is registered with, when it was created and when it expires, which status locks apply, which nameservers serve it and whether DNSSEC is delegated, then reads Certificate Transparency logs for every host name a certificate was ever issued for, including subdomains nobody remembers.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/\" \/>\n<meta property=\"og:site_name\" content=\"Lukas Wojcik - Blog\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/og-default.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/domain-rdap-certificate-transparency-subdomain-lookup\\\/\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/domain-rdap-certificate-transparency-subdomain-lookup\\\/\",\"name\":\"Domain RDAP & Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains - Lukas Wojcik - Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\"},\"datePublished\":\"2026-09-05T12:58:34+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/domain-rdap-certificate-transparency-subdomain-lookup\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/domain-rdap-certificate-transparency-subdomain-lookup\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/domain-rdap-certificate-transparency-subdomain-lookup\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Toolbox\",\"item\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/en\\\/toolbox\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Domain RDAP &#038; Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/\",\"name\":\"Lukas Wojcik - Blog\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/#\\\/schema\\\/person\\\/895f7604f9b6b71aad9bba33af28d0f9\",\"name\":\"luky\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"url\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"contentUrl\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\",\"width\":424,\"height\":636,\"caption\":\"luky\"},\"logo\":{\"@id\":\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/lw-x2.jpg\"},\"sameAs\":[\"https:\\\/\\\/www.lukaswojcik.com\\\/blog\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Domain RDAP & Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains - Lukas Wojcik - Blog","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/","og_locale":"en_US","og_type":"article","og_title":"Domain RDAP & Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains - Lukas Wojcik - Blog","og_description":"Asks the registry via RDAP who a domain is registered with, when it was created and when it expires, which status locks apply, which nameservers serve it and whether DNSSEC is delegated, then reads Certificate Transparency logs for every host name a certificate was ever issued for, including subdomains nobody remembers.","og_url":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/","og_site_name":"Lukas Wojcik - Blog","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/08\/og-default.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/","url":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/","name":"Domain RDAP & Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains - Lukas Wojcik - Blog","isPartOf":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#website"},"datePublished":"2026-09-05T12:58:34+00:00","breadcrumb":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/domain-rdap-certificate-transparency-subdomain-lookup\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.lukaswojcik.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Toolbox","item":"https:\/\/www.lukaswojcik.com\/blog\/en\/toolbox\/"},{"@type":"ListItem","position":3,"name":"Domain RDAP &#038; Certificate Transparency Lookup: Registrar, Expiry, Forgotten Subdomains"}]},{"@type":"WebSite","@id":"https:\/\/www.lukaswojcik.com\/blog\/#website","url":"https:\/\/www.lukaswojcik.com\/blog\/","name":"Lukas Wojcik - Blog","description":"","publisher":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.lukaswojcik.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/www.lukaswojcik.com\/blog\/#\/schema\/person\/895f7604f9b6b71aad9bba33af28d0f9","name":"luky","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","url":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","contentUrl":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg","width":424,"height":636,"caption":"luky"},"logo":{"@id":"https:\/\/www.lukaswojcik.com\/blog\/wp-content\/uploads\/2026\/07\/lw-x2.jpg"},"sameAs":["https:\/\/www.lukaswojcik.com\/blog"]}]}},"_links":{"self":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/15573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/comments?post=15573"}],"version-history":[{"count":0,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/15573\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/pages\/38"}],"wp:attachment":[{"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/media?parent=15573"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.lukaswojcik.com\/blog\/wp-json\/wp\/v2\/tags?post=15573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}