RDAP in Iris Investigate search
When searching by registration data fields, you can specify whether to search RDAP data, WHOIS data, or let the system automatically select the best available record.
Auto mode (default)
Section titled “Auto mode (default)”
By default, searches use registration data in “auto” mode. This means the system searches on the registration data for the given field, automatically selecting between RDAP and WHOIS:
Registration data is populated from a single source — WHOIS or RDAP — selected per domain in this order:
- If only one source is present, that record is used.
- If both are present and were collected more than three days apart, the newer record is used (field count is not considered).
- If both were collected within three days of each other, the record with more populated fields is used.
- On a tie — including when neither record has populated fields — RDAP is used.
To work with source-specific data, use the parsed_whois and parsed_domain_rdap records.
Search specific protocols
Section titled “Search specific protocols”To search specifically against RDAP or WHOIS:
- Open the Advanced Search panel.
- Add a filter for a registration data field (Email, Registrant, or WHOIS Record).
- Locate the protocol selector (shows “auto” by default).
- Change “auto” to either:
- RDAP: Search only RDAP records.
- WHOIS: Search only WHOIS records.
- Run your search.
Supported fields
Section titled “Supported fields”The following fields support RDAP/WHOIS protocol selection:
- Email: Email addresses from registration records.
- Registrant: Registrant name information.
- WHOIS Record: Full text search of registration records.
Other registration-related fields (Registrar, Registrant Organization, etc.) use registration data automatically without protocol selection.
Use specific protocols
Section titled “Use specific protocols”Use auto mode when:
Section titled “Use auto mode when:”- You want the most complete results.
- You don’t care about the source protocol.
- You’re searching for current registration data.
Use RDAP specifically when:
Section titled “Use RDAP specifically when:”- You need structured JSON data.
- You’re investigating domains with RDAP records.
- You want to exclude WHOIS-only results.
Use WHOIS specifically when:
Section titled “Use WHOIS specifically when:”- You’re investigating older domains.
- You need historical consistency.
- You’re comparing with legacy data.
How protocol selection affects results
Section titled “How protocol selection affects results”Auto mode:
- Searches both RDAP and WHOIS records.
- Returns domains matching either protocol.
- Provides the most comprehensive results.
RDAP mode:
- Searches only RDAP records.
- Excludes domains with WHOIS-only data.
- May return fewer results.
WHOIS mode:
- Searches only WHOIS records.
- Excludes domains with RDAP-only data.
- Useful for historical consistency.
Best practices
Section titled “Best practices”Default to auto mode
Section titled “Default to auto mode”For most searches, auto mode provides the best results by searching both protocols and returning the most complete data.
Use specific protocols for:
Section titled “Use specific protocols for:”- Data format requirements: When you need specific JSON (RDAP) or text (WHOIS) format.
- Protocol comparison: When comparing RDAP vs WHOIS coverage.
- Troubleshooting: When investigating protocol-specific issues.
- Historical analysis: When maintaining consistency with older searches.
Combine with historical search
Section titled “Combine with historical search”Remember that Email, Registrant, and WHOIS Record fields support historical search. You can combine protocol selection with historical search to:
- Search historical RDAP records.
- Search historical WHOIS records.
- Compare protocol coverage over time.
For more information, see Historical Search.
See also
Section titled “See also”- RDAP Overview: Understanding RDAP support.
- RDAP in Pivots: Pivot with RDAP data.
- Advanced Search: Using filters and operators.
- Historical Search: Search historical data.