A minimal HTTP service that resolves domain registration data via the WHOIS
protocol (port 43) and returns it as JSON. It exists because browsers and React
Native clients can't open raw TCP sockets, so WHOIS-only TLDs (e.g. .me,
.im) that don't publish RDAP need an HTTP intermediary.
Built on likexian/whois for server
discovery and likexian/whois-parser
for parsing.
.me, .im) are
WHOIS-only.domain-vault browser extension and mobile app fetch domain data
client-side, which cannot reach WHOIS port 43 directly.go build -o whois-bridge .
./whois-bridge
GET /api/domain/{domain}Returns a JSON document shaped like domain-vault's ParsedRDAPData:
{
"registrar": "GoDaddy.com, LLC",
"expirationDate": "2027-04-29T17:53:06Z",
"creationDate": "2008-04-29T17:53:06Z",
"nameservers": ["pdns07.domaincontrol.com", "pdns08.domaincontrol.com"],
"status": ["clientDeleteProhibited", "clientTransferProhibited"]
}
Fields that a registry doesn't publish are returned as empty strings / empty
arrays, never null, and never cause the request to fail. For example .im
often has no registrar or dates.
| Status | Meaning |
|---|---|
200 | Lookup succeeded (fields may be empty) |
400 | Invalid domain (IP, no TLD, invalid characters) |
502 | WHOIS lookup failed (timeout / network) |
curl http://localhost:8080/api/domain/example.me
GET /healthz returns 200 {"status":"ok"}.
| Variable Name | Default | Description |
|---|---|---|
PORT | 8080 | HTTP listen port |
WHOIS_TIMEOUT | 5s | Per-lookup timeout (Go duration, e.g. 8s) |
CACHE_TTL | 24h | How long successful lookups are cached |
RATE_LIMIT | 60 | Max requests per IP per window |
RATE_LIMIT_WINDOW | 1m | Rate-limit window (Go duration) |
Requests are tracked per client IP (read from the last X-Forwarded-For hop, as
set by Cloudflare). Exceeding the limit within a window returns 429 with a
Retry-After header. /healthz is exempt.
A prebuilt multi-arch image is published to Docker Hub as
gera2ld/whois-bridge
(linux/amd64, linux/arm64), built from a multi-stage Dockerfile (static
binary, ~14 MB, runs as a non-root user).
docker run --rm -p 8080:8080 -e WHOIS_TIMEOUT=8s -e CACHE_TTL=12h gera2ld/whois-bridge:latest
Successful lookups are cached in memory with a per-process TTL (default
24h). Lookup/network failures are not cached, so transient errors retry on
the next request. The cache is lost on restart and not shared across instances.
Content type
Image
Digest
sha256:d6787ee4d…
Size
6.8 MB
Last updated
20 days ago
docker pull gera2ld/whois-bridge