.to WHOIS Lookup
.to is the country-code extension of the Kingdom of Tonga. Look up a .to address and see which details its record carries.
- 1.494 extensions
- IANA 1601 ICANN accredited
- 2 protocols — RDAP and WHOIS
Your IP address 216.73.216.31
.to WHOIS Lookup: Tonga Domain Name Records
.to is the country-code extension of the Kingdom of Tonga, delegated into the root zone on 18 December 1995; IANA's record names the government of Tonga as the sponsoring organisation. Queries are answered by whois.tonicregistry.to on port 43, and in our measurement on 12 August 2026 the reply carried fifteen fields. The extension also runs an RDAP endpoint at rdap.tonicregistry.to.
The most telling finding of the measurement sits not in the record but in the root: there is no DS record for .to, so the extension is unsigned. The reply itself carries a DNSSEC field, and in the record we measured its value was unsigned. Together the two mean this: even a signed .to address cannot be validated, because a resolver building the chain of trust downward from the root finds the upper link missing. Signing stays a setting at the level of the individual name.
The rest of the record follows a familiar template: creation, updated and expiry dates, the registrar's name and IANA number, an email for abuse reports, the name servers and the status codes. In the record we measured, the expiry date fell exactly ten years after registration. No registrant lines appear in the reply; the notice at the end states in its own words that personal data is not published and that contact runs through the sponsoring registrar. For a signed country extension by way of comparison, see .is WHOIS lookup; for one that carries no dates at all, .ae WHOIS lookup.
About the .to extension
- Extension
- .to
- WHOIS server
- whois.tonicregistry.to
- RDAP endpoint
- https://rdap.tonicregistry.to/rdap
- Registry
- The government of the Kingdom of Tonga, per the IANA record
- Delegated
- 18 December 1995
- DS record in the root
- None — the extension is unsigned (measured 12 August 2026)
- Measured field count
- 15 fields (12 August 2026)
- Measured sample
- tonic.to: registered 30 July 2025, expires 30 July 2035
WHOIS FAQ
Does DNSSEC validation work in the .to extension?
Not end to end. In our measurement on 12 August 2026 there was no DS record for .to in the root zone, so the extension is unsigned. DNSSEC validation starts at the root and moves down, proving the key of each zone in turn, which means a missing link stops the proof for everything beneath it. Nothing prevents you from publishing keys for your own name, but resolvers will treat the zone as unsigned.
What does the DNSSEC line in a .to reply show?
It shows the signing state of the name you queried, not of the extension. In the tonic.to record we measured, that value read unsigned. Even a value of signed would not complete validation while the extension itself carries no DS record in the root, because the two facts belong to different layers. Our result screen reports the state of the individual name, and the state of the zone is stated on this page.
Does a .to WHOIS lookup show the domain owner?
It does not. In the 12 August 2026 measurement the reply held no registrant name, address or email. The notice at the end of the answer gives the reason in its own words: personal information is not displayed for privacy reasons, and anyone with a legitimate need to contact a specific domain holder is asked to approach the sponsoring registrar. The identity you can learn from the record is that of the registrar.
Are creation and expiry dates included for .to domains?
They are. The reply carries the creation date, the last updated date and the registry expiry date as separate fields, and all three arrive populated on the result screen. In the record we measured, registration was dated 30 July 2025 and expiry 30 July 2035. The answer also closes with a stamp saying when the WHOIS database itself was last updated — a note about the freshness of the data rather than about the name.
What do the status codes in a .to record mean?
They state which operations the name is closed to, and they come from ICANN's common EPP vocabulary. In the record we measured, deletion, transfer and updates were all closed, and all three codes carried the server prefix, meaning the registry set them and the registrar cannot lift them. With a client prefix the authority sits with the registrar instead. Checking the prefix is the quickest way to see where an operation is blocked.
Can a .to record run for a ten-year term?
The measurement shows one that does. In the tonic.to record, exactly ten years separated registration from expiry: 30 July 2025 to 30 July 2035. A WHOIS reply reports the calendar of a record and not how that term was arrived at. The result screen shows the expiry date and the time remaining, which is what lets you tell a long-running record from a short one at a glance.
How does an available .to name look in a lookup?
It comes back with no record data. In our measurement a name that was not registered drew no registration data from the server, and the result screen marked it as available. Availability works correctly for this extension: the query is answered on port 43, and a registered name can be told apart from a free one. Results that look available are cached for five minutes and registered ones for six hours.