<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    I believe the text based WHOIS service is still quite valuable and
    necessary.<br>
    <br>
    <font size="5">It was the biggest mistake to allow ICANN to let
      domain owners obfuscate their contact information.</font> <br>
    <br>
    The domain WHOIS system was immensely useful in helping to fight
    spam, phishing, malware and other forms of Internet abuse and
    crime!  But when ICANN let anyone and everyone HIDE THEIR CONTACT
    INFO, the system became useless!!  Europe does not control us and
    the rest of the world.  Why are we letting their privacy laws change
    the way the rest of the world does WHOIS???<br>
    <br>
    <font size="5">Since ICANN allows domain owner's to hide their
      contact information, why have a domain WHOIS system at all?!?!?</font><br>
    <br>
    Even ARIN isn't very strict on enforcing accurate and up to date
    information in their WHOIS record.  Amazon lists 206-555-0000 (an
    obviously invalid number) as their phone number in their WHOIS
    record(s).  I've reported this to ARIN several times, but the
    intentional error remains.<br>
    <br>
    Don't tell me that the text based WHOIS service creates a greater
    "threat landscape" or "attack vector".  Text based WHOIS has been
    around for decades - by now, I'm sure it's quite hardened!  And
    really, tell me, how hard is it to continue to maintain something
    simple that domain registrars have already been doing since day 0? 
    It's stupid to take away something that works and costs almost
    nothing to maintain.  I'm sure integrating text based WHOIS into the
    new RDAP infrastructure can't be too big a deal?!?<br>
    <br>
    As for RDAP, adding this new much more complicated (relatively
    speaking) technology poses a much greater risk of unforeseen attack
    vectors.  <br>
    <br>
    Lastly, what good is RDAP if ICANN's WHOIS accuracy requirements are
    still being ignored??  I still can't look up actual contact
    information for domains whose server might have been compromised by
    scammers or phishers, so what am I getting from RDAP?!?!?  Let's
    just hope that ARIN doesn't follow suite in that regard?!?<br>
    <br>
    <u><b>Bottom line:  Sure, let's adopt RDAP, but there's no reason to
        get rid of text based WHOIS!</b></u><br>
    <br>
    Patrick Klos<br>
    Klos Technologies, Inc.<br>
    <br>
    <div class="moz-cite-prefix">On 8/14/2026 11:16 AM, ARIN wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:B2B1F04F-4BFD-4AAE-92B6-F224CB2D80CE@arin.net">
      <pre class="moz-quote-pre" wrap="">ARIN is seeking feedback from the community on a proposed road map to streamline and consolidate its directory services.

ARIN currently maintains four directory information protocols: Whois-RWS, RWhois, Whois (Port 43), and RDAP. Supporting multiple redundant services that provide the same information creates additional administrative and operational overhead to the organization. To reduce ARIN’s attack surface, streamline operations and lower future operational overhead, ARIN proposes retiring use of older protocols in favor of RDAP as our single, standardized directory service.

This transition is an important step toward improving alignment with established IETF standards.

We have already seen this transition in the domain industry with ICANN mandating the use of RDAP for directory services and dropping the requirement to support Whois. We also expect RDAP clients to become increasingly common in OS distributions in the coming years.

------
Benefits of Transition to RDAP 

- Enhanced Directory Services: Future enhancements, such as geolocation, will only be implemented in RDAP. 
- Standardization and Automation: RDAP’s standardized data structure will improve automation for clients and provide greater flexibility in managing future data changes. 
- Reduced Technical Overhead: Removing old and redundant services will provide time and cost savings for ARIN. 

------
Timeline and Retirement Planning

This consultation seeks community input for the proposed retirement timelines below. We are keenly interested in receiving specific input on any barriers and/or obstacles these changes may create for customers, as well as steps ARIN can take to ensure a smooth transition. Note that the retirement plans for each impacted directory service will be completed independently, though in some cases work may be conducted concurrently.

***
Whois-RWS Retirement Plan and Timeline

ARIN currently offers Whois-RWS in two formats: an API and a web interface (located at <a class="moz-txt-link-freetext" href="https://whois.arin.net/ui/">https://whois.arin.net/ui/</a>). Because the API has the same functionality between Whois-RWS and RDAP, ARIN proposes sunsetting the Whois-RWS API following a 180-day customer outreach program. This will include updating the Whois-RWS payloads to include a notification to users, as well as a robust communication strategy that includes announcements, social promotion, and other outreach.

The Whois-RWS web interface will remain available until work is completed to ensure parity, providing equivalent query capabilities to RDAP. The changeover from Whois-RWS to RDAP will be transparent to end users visiting that URL. ARIN will inform the community a minimum of 30 days before the retirement of the Whois-RWS web interface, noting the switch to RDAP will not change the end user experience.

***
RWhois Retirement Plan and Timeline

When RWhois server use is retired, we will provide organizations with a recommendation for an open-source RDAP server implementation. To help ease the transition and migration of data, ARIN plans to provide a conversion tool for populating that recommended RDAP server with existing RWhois data. When the tool is publicly available, ARIN proposes a 365-day sunsetting timeline for RWhois. This will allow for robust communication and direct outreach to organizations who use RWhois and plan to either convert to the RDAP client or discontinue their use of local clients and report their reassignment information directly to ARIN instead.

***
Whois (Port 43) Retirement Plan and Timeline

ARIN understands that Whois (Port 43) carries a high volume of queries and will require the longest timeline to retire. We propose a two-year sunsetting window, during which ARIN will engage in active outreach to users. This will include updates to Whois (Port 43) results during the sunsetting period that will contain information about the retirement deadline.

Because Whois (Port 43) has been the historically preferred method of querying Internet number resource registration data, it remains heavily used by cybersecurity professionals, researchers, law enforcement, and many other types of organizations. ARIN will seek to engage beyond our community to raise awareness of the planned retirement date for Whois (Port 43).

------
After the retirement of the directory service protocols described above and listed below, ARIN will only support RDAP as our single, standardized directory service.

- Whois-RWS: on or after 1 July 2027
- RWhois: dependent on migration tool release date, but no sooner than 1 January 2028
- Whois (Port 43): on or after 1 January 2029

Throughout the sunsetting process for all services, ARIN will engage with our community to ensure customers and users are well-informed about the retirement of the described services and ARIN’s transition to RDAP as its standard directory service.

We look forward to your feedback on the proposed timelines for retirement for Whois-RWS, RWhois, and Whois (Port 43). We ask that you consider each service independently, with the understanding that each of these services may impact your organization differently.

Please provide comments to <a class="moz-txt-link-abbreviated" href="mailto:arin-consult@arin.net">arin-consult@arin.net</a>. You can subscribe to this mailing list at <a class="moz-txt-link-freetext" href="https://lists.arin.net/mailman/listinfo/arin-consult">https://lists.arin.net/mailman/listinfo/arin-consult</a>.

This consultation will remain open until 5:00 PM ET on 14 September 2026. ARIN seeks clear direction through community input, so your feedback is important.

Thank you for your continued support in improving ARIN’s services.

Regards,

John Curran
President and CEO
ARIN

------
Relevant links:
- Presentation from ARIN 56: <a class="moz-txt-link-freetext" href="https://www.arin.net/participate/meetings/ARIN56/materials/arin56_directoryservices.pdf">https://www.arin.net/participate/meetings/ARIN56/materials/arin56_directoryservices.pdf</a>
- IETF Standard for RDAP: <a class="moz-txt-link-freetext" href="https://www.rfc-editor.org/info/std95">https://www.rfc-editor.org/info/std95</a>
- Guide to RDAP Client Implementations: <a class="moz-txt-link-freetext" href="https://rdap.rcode3.com/client_implementations/index.html">https://rdap.rcode3.com/client_implementations/index.html</a>
- ARIN RDAP Documentation: <a class="moz-txt-link-freetext" href="https://www.arin.net/resources/registry/whois/rdap/">https://www.arin.net/resources/registry/whois/rdap/</a>


_______________________________________________
ARIN-Consult
You are receiving this message because you are subscribed to the ARIN Consult Mailing
List (<a class="moz-txt-link-abbreviated" href="mailto:ARIN-consult@arin.net">ARIN-consult@arin.net</a>).
Unsubscribe or manage your mailing list subscription at:
<a class="moz-txt-link-freetext" href="https://lists.arin.net/mailman/listinfo/arin-consult">https://lists.arin.net/mailman/listinfo/arin-consult</a> Please contact the ARIN Member Services
Help Desk at <a class="moz-txt-link-abbreviated" href="mailto:info@arin.net">info@arin.net</a> if you experience any issues.
</pre>
    </blockquote>
    <br>
  </body>
</html>