Last updated: 10 July 2026
DomainCheckr is a free, ad-free domain WHOIS/RDAP lookup and domain-intelligence tool operated by MWBM Partners Ltd (t/a MWservices). There are no user accounts and we keep no database of users. This policy explains, in plain terms, what data is involved when you use the Service, how it is used, and your rights.
1. What This Service Is
The Service lets you look up public WHOIS/RDAP registration data, DNS records, SSL/TLS certificates, email security configuration, and related information for domains and IP addresses that you enter. It is free to use, carries no advertising, and does not require you to create an account.
2. Data You Submit
- Domain names and IP addresses you enter are used to perform the lookup you requested, and are sent to the external data sources described in Section 4 below to fulfil that lookup.
- API keys, if you use the authenticated JSON API, are stored on our server only as a SHA-256 hash — never in plain text.
3. Server-Side Data
- IP address — your IP address is used transiently for abuse prevention and rate limiting. It is stored only as a hashed value in a short-lived server-side file, and is not retained in plain text. Your IP address may also appear in standard web-server logs, retained according to our hosting provider's normal log-rotation policy.
- Session cookie — a single first-party session cookie is used for CSRF (Cross-Site Request Forgery) protection and session-based rate limiting. It is
HttpOnly,SameSite=Lax, andSecure(when served over HTTPS). This cookie is not used for tracking or advertising, contains no personal information, and is deleted when you close your browser. - Lookup cache — results of a lookup are cached on the server for approximately 15 minutes to speed up repeat queries and reduce load on external registries, then automatically expire.
- Usage statistics — only aggregate, non-identifying counts (e.g. total lookups performed) are kept for basic operational monitoring. No personally identifiable information is included.
4. Third-Party Data Sources
To fulfil a lookup, the domain or IP address you enter may be sent to one or more of the following external services. Many of these are only contacted for optional, supplementary checks, and all of them are skipped when your browser sends a Do Not Track signal (see Section 5).
- RDAP and WHOIS — the RDAP aggregation service at
rdap.org, and the relevant registry/registrar WHOIS servers, to retrieve domain registration data. - DNS resolvers — including public DNS resolvers, to retrieve DNS records and check propagation.
- Certificate Transparency logs — via
crt.sh, for SSL/TLS certificate history. - IP geolocation — via
ip-api.com, for server location data. - Reverse-IP lookup — via
hackertarget.com, for co-hosted domain discovery. - Website screenshots — via
thum.io, for preview images. - The target website itself — for HTTP header, technology-stack,
robots.txt, and redirect checks. - Mail servers — for SMTP-related email security checks.
- DNS blocklists — including Spamhaus and other DNS blocklist providers, for reputation checks.
- Optional security-intelligence services — Google Safe Browsing, VirusTotal, Have I Been Pwned, Shodan, AbuseIPDB, PhishTank, and URLhaus, but only where the site operator has configured API keys for these.
In addition, reference data about top-level domains is periodically refreshed from IANA and publicsuffix.org, and front-end assets (Bootstrap, icons) are loaded from the jsDelivr CDN when you load a page. Each third-party service is subject to its own privacy policy; we do not control what data these services retain.
5. Do Not Track (DNT)
The Service honours the Do Not Track signal sent by your browser. When DNT is enabled, all optional third-party enrichment calls listed in Section 4 are skipped, and anonymous usage-statistics tracking is disabled. Core WHOIS/RDAP/DNS lookup functionality is unaffected. For a full breakdown of what is and isn't available with DNT enabled, see Section 7 of our Terms of Service.
6. Data Stored in Your Browser Only
The following data is stored using your browser's localStorage and is never sent to our servers:
- Lookup history — domains you have recently looked up.
- Watch list — domains you choose to monitor for expiry.
- Change-history timeline — snapshots of past lookups, used to show what has changed over time.
- Security-score history — past security-score results for domains you have checked.
- Settings and preferences — such as your theme and language choices.
You can clear this data at any time from your browser's settings, or using the relevant "clear" controls within the application. We have no access to this data.
7. No Advertising, No Third-Party Analytics
The Service carries no advertising and does not use third-party analytics or tracking scripts. We do not sell, rent, or share your data with third parties for marketing purposes.
8. Your Rights (UK GDPR)
We process a minimal amount of personal data — principally your IP address, transiently, for the purpose of preventing abuse and enforcing rate limits. Our lawful basis for this is legitimate interest in keeping the Service secure, available, and fair to all users. Because we hold no accounts and no persistent personal-data store beyond short-lived, hashed rate-limiting records and standard server logs, most data-subject requests will find little or nothing held about you. If you have questions about this policy or wish to raise a data-protection query, please contact us via MWBM Partners Ltd (t/a MWservices).
9. Children
The Service is a general-purpose technical utility and is not directed at children. We do not knowingly collect personal data from children.
10. Changes to This Policy
We may update this policy from time to time to reflect changes to the Service or our data practices. The "Last updated" date at the top of this page will reflect the most recent revision.
11. Contact
For privacy-related enquiries, please contact MWBM Partners Ltd.