Connector: RDAP domain registration (rdap)
Purpose: registration facts of an organization's domain (RFC 9083, the JSON successor of WHOIS) — registrar
(and IANA id), EPP status codes (clientTransferProhibited, serverHold = suspended, pendingDelete),
nameservers, DNSSEC delegation, registration / expiration / last-changed / transfer dates. Detects registrar
transfers, suspensions, nameserver moves, DNSSEC toggles and imminent expiry (extra.daysToExpiry, expiring
< 30 days, held).
Sensor URL: https://rdap.org/domain/example.com (display form) or a registry RDAP URL. Type: JSON, tier D.
Config: domain?, direct?: true (force rdap.org).
Retrieval: the TLD's authoritative RDAP server is resolved from the IANA bootstrap file
(https://data.iana.org/rdap/dns.json, cached 24 h) — rdap.org is a redirector rate-limited at roughly ten requests
per minute and returned 429 on bulk validation. Overrides for TLDs missing from the bootstrap but served by a
registry (.io, .ac, .sh → Identity Digital). ccTLDs without RDAP (.co, many others) fail with 404 and must not
be added.
Normalization: JSON summary with the volatile parts removed — the last update of RDAP database event,
notices, links, rdapConformance; status codes and nameservers sorted and lower-cased.
Known quirks: registrar name comes from the registrar entity's vCard fn (falls back to its handle); some
registries omit secureDNS (→ dnssec: null); thin registries (e.g. .com) do not include registrant contacts.
Tests: connectors2.test.ts (summarizeRdap). Verified: 2026-09-08 (.com, .ca, .gov, .ai, .dev, .io).