Summary
- ARIN is consulting until 14 September 2026 on retiring Whois-RWS, RWhois and Whois over Port 43 in favour of RDAP; the dates remain proposals, not completed shutdown decisions.
- Each service has a different proposed dependency: API and web parity for Whois-RWS, conversion tooling for RWhois, and a two-year sunset window accompanied by outreach for the heavily used Port 43 service.
- The durable control should be three evidence-based exit gates, not one aggregate declaration that RDAP is ready.
A directory migration can look complete from the server side while remaining broken in the path that matters. A replacement endpoint may return the right registration record, yet an incident-response script may never discover it. A local reassignment service may have no tested conversion path. A security appliance may still expect plain text over Port 43 and fail silently when that assumption disappears.
That is why ARIN's consultation on the future of its directory services is best understood as three migrations sharing one destination. ARIN opened the consultation on 14 August and asks for comments by 17:00 ET on 14 September. It proposes consolidating Whois-RWS, RWhois and Whois over Port 43 into RDAP, the standardized Registration Data Access Protocol. At this article's 4 September reporting freeze, the consultation remained open. None of the proposed retirement dates was an adopted or completed shutdown.
One standard, three dependency maps
RDAP offers a stronger common substrate than a collection of registry-specific query habits. The IETF's STD 95 family defines HTTP transport, security services, uniform query formats, structured JSON responses and discovery of the authoritative service. ARIN argues that consolidation can reduce its attack surface and operating overhead while making automation and future data changes easier.
Those benefits do not make the legacy services interchangeable. Whois-RWS exposes an API and a web interface. ARIN proposes a 180-day outreach programme before retiring the API on or after 1 July 2027. The familiar web URL would remain until equivalent RDAP-backed query capabilities are ready, allowing the implementation behind it to change without forcing an end user to learn a new interface.
RWhois sits on the publication side of the system. Some organizations use it to expose reassignment information from their own servers. ARIN says it would recommend an open-source RDAP server and provide a conversion tool for existing RWhois data. Only after that tool becomes available would a proposed 365-day sunset begin, with retirement no earlier than 1 January 2028.
Port 43 presents the broadest discovery problem. It is old, simple and deeply embedded. ARIN says it still carries high query volume and is used by cybersecurity professionals, researchers, law enforcement and other communities beyond ARIN's membership. The proposed retirement date is no earlier than 1 January 2029, after a two-year sunset and outreach beyond the usual registry channels.
A date is not an exit test
The three services should be assessed independently because ARIN has proposed a different dependency and timetable for each. A single readiness percentage would conceal different failure modes.
For Whois-RWS, the test is functional and behavioural parity: common queries, referrals, errors, rate limits and automation should have documented RDAP equivalents. For RWhois, the test is whether operators can move data and authority, not merely whether ARIN can answer a query. The conversion tool needs reproducible results, a rollback path and enough time for organizations to test the server ARIN recommends.
For Port 43, the harder evidence sits outside ARIN's inventory. Unauthenticated clients, shell scripts, security products and research pipelines may leave no registration list. Response notices and outreach help, but readiness also requires observing declining use, publishing migration examples and distinguishing abandoned traffic from essential clients that have not yet moved.
In BTW's analysis, the economic trade-off is asymmetric. Keeping redundant services indefinitely consumes security and maintenance capacity. Retiring one too early can shift much larger costs onto downstream workflows, especially when their owners discover the dependency during an incident rather than a planned test.
The consultation outcome, final retirement dates, any exception policy, usage baselines, parity criteria and rollback triggers remain unknown. The number of scripts, appliances and other clients that cannot adopt RDAP without vendor or operator changes is also unknown.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

