Observed Signal · Jul 30, 2026 · Technical Release · Source: DEV Community · Impact: 2/5 · Sentiment: Neutral

RDAP Replaces WHOIS; 404 Responses Can Be Misleading

Executive Signal Summary

The legacy WHOIS protocol has been replaced by RDAP (RFC 9083), which returns JSON and is required for gTLD registries. Post-GDPR, RDAP generally omits registrant personal data, leaving operational fields (registrar, dates, status, DNSSEC) as the most useful outputs. The article describes a common tooling trap: rdap.org acts as a router using IANA's RDAP bootstrap, and if a TLD is not listed there rdap.org returns 404 for every name under that TLD, which can be mistaken for availability. The two-part fix is (1) consult IANA's dns.json to know which TLDs have RDAP services and (2) use DNS (NS records) to detect delegation for TLDs without RDAP; when neither proves registration, return an unknown/null rather than a false available result. The author also notes an Apify Actor (Domain Scraper) used for runnable examples and pricing details for domain queries.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Protocol-level change with operational implications for domain tooling and automation; useful for security auditing, sales qualification and toolbuilders, but not a high-impact AdTech industry shift.

SIGNAL RADAR

Track Cloudflare Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • RDAP replaced WHOIS and is standardized as RFC 9083; it returns JSON.
  • gTLD registries are required to run RDAP services.
  • Post-GDPR, RDAP returns no registrant personal data for most TLDs; operational fields remain available (registrar, dates, status, DNSSEC).
  • rdap.org routes queries using IANA's RDAP bootstrap; if a TLD is not in the bootstrap, rdap.org returns 404 for all names under that TLD, causing false 'available' results.
  • Fix recommended: fetch IANA's https://data.iana.org/rdap/dns.json to know which TLDs have RDAP, and use DNS NS records to detect delegation for TLDs lacking RDAP; the author demonstrates tooling using an Apify Actor (Domain Scraper).

Connected Companies & Entities

7 Entities mapped

“linear.app CloudFlare, Inc. 2030-05-09 8.2 google cloudflare reject...”

“Combine that with a DNS lookup and you get the thing people actually want, which is what a company runs on: ... mail provider ... google...”

“domain registrar expires age mail dns dmarc stripe.com SafeNames Ltd. 2027-09-11 30...”

“domain registrar expires age mail dns dmarc linear.app CloudFlare, Inc. 2030-05-09 8...”

“domain registrar expires age mail dns dmarc vercel.com Amazon Registrar, Inc. 2029-10-04 26...”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Jul 30, 2026
Original Coverage Title: “WHOIS is gone, RDAP replaced it, and a 404 does not mean what you think”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Digital Risk Protection (Brand Safety & Fraud)Mar 26, 2026

Rethinking Digital Risk Protection: Detection vs Disruption

This analysis argues that 'Digital Risk Protection' (DRP) is an overused, inconsistently defined category—many vendors label monitoring-only products as DRP while genuine protection requires confirmed removal of external threats. Canonically, DRP covers external brand impersonation across domains, social, mobile apps, phone vishing, credential leaks and scam listings. The market splits between detection (mature, data-driven signal matching) and disruption (coordination-heavy takedowns requiring registrars, platforms and carriers). Vendor capabilities vary widely: some excel at OSINT/dark-web detection but not takedowns, while dedicated DRP vendors differ in operational quality. The author emphasizes evidence-package quality and 'explainable verification' as critical inputs to takedown speed, and notes Australia’s Scams Prevention Framework (SPF) shifts procurement toward disruption outcomes. The piece ends with a practical evaluation checklist for buyers focused on coverage, removal rates, escalation relationships and recurrence detection.

Read assessment
Application Performance Monitoring (APM)Jul 9, 2026

Free ReDoS Checker and API to Detect Catastrophic Regexes

A developer tutorial and announcement for ReDoScan, a REST API and free web checker built by Hudson Enterprises LLC that detects ReDoS (regular expression denial-of-service) vulnerabilities caused by catastrophic backtracking in backtracking-based regex engines. The service offers static analysis (fast, rule-based risk badges) and an optional dynamic timing mode that measures runtime growth and classifies it (safe / polynomial / exponential). Key endpoints include /scan, /scan-batch (up to 200 patterns) and /known-evil (public corpus). The API is available via a RapidAPI listing with a free tier (1,500 scans/month); paid tiers provide higher monthly scan quotas. The article explains how to integrate ReDoScan into CI/CD gates, caveats about coverage (not a full SAST) and recommended usage patterns for batch CI and deeper audits.

Read assessment
Email & NewsletterJul 26, 2026

MCP Spec Imminent; Email Authentication Is Weakening

The author scanned 671,693 domains (Tranco forward-DNS snapshot 2026-07-25) and reports widespread weaknesses in email authentication as the MCP spec is about to land. Key findings: 634,220 domains publish SPF, 468,749 publish DMARC, but DMARC enforcement fell by 0.42 percentage points last month despite 9,173 net new DMARC domains; a large share of those records are non-enforcing `p=none` or inert (no working `rua=`). Enforcement correlates with prominence: top-1k sites are far more protected than the long tail. Self-hosted MX is the single largest inbound category (22.79%), exceeding Google Workspace and Microsoft 365. The author warns agentic email products amplify risk through concentrated volume, unaudited SPF includes, and missing telemetry, and gives concrete diagnostic commands and remediation steps.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.