Troubleshooting Common Issues

This page covers specific bugs, common user errors, and known limitations.

Can't fetch domain data / TLD Support

Different TLDs expose different levels of registration data, and the structure of that data can vary between registries and registrars. While most modern TLDs support RDAP (the successor to WHOIS), the amount of publicly accessible information depends on registry policies, locale, and access restrictions. As a result, for some domain extensions certain details (such as registrant information) may not be available for automated retrieval. In these cases, the only workaround to this is to enter this info manually when adding a domain.

Firstly, check whether or not your domain extension is supported at deployment.rdap.org

Then, test out which data is returned, by running whois example.com, and the same for RDAP with https://<rdap-server>/domain/<domain-name>


Lookups time out or come back empty

Domain Locker tries several sources in turn: RDAP, then WHOIS on port 43, then the public who-dat API, then the whois command if it's installed. The logs show which source answered, or why each one didn't.

  • Port 43 is blocked or slow on your host: many ccTLDs (such as .de, .ch, .it, .jp and .io) have no RDAP yet, so they depend on it. Skip it with DL_WHOIS_PROVIDERS=rdap,who-dat
  • A registry is rate limiting you: slow the updater down with DL_WHOIS_DELAY_MS and DL_WHOIS_CONCURRENCY
  • You'd rather not rely on the public who-dat instance: run your own with docker run -p 8080:8080 lissy93/who-dat and point DL_WHO_DAT_URL at it. It needs the same network access as the app, so it won't help if port 43 is blocked

All of these are listed in Environmental Variables.


Can't fetch subdomains

DNS, as a system can’t automatically fetch all subdomains for a given domain, since there is no central, public database that lists them.

You can enable automatic discovery for subdomains with either dnsdumpster.com or Shodan (note, Shodan requires pro plan).

  • DNSDumpster: Sign up for an API key here, and then set the the DNS_DUMPSTER_TOKEN env var
  • Shodan: Sign up for an API key here (requires paid plan), and then set the SHODAN_TOKEN env var

You can choose which service is used for subdomain lookups by setting the DL_PREFERRED_SUBDOMAIN_PROVIDER env var to either shod, dnsdump, both or none.

After setting up, you can fetch subdomains for your existing domains by going to http://[domain-locker]/assets/subdomains/[your-domain].

Why no auto-fetching? DNS is designed to answer queries for specific records — not to provide a complete index of every subdomain under a domain. So, unless the domain owner exposes a full zone transfer, discovering subdomains requires external scanning, certificate transparency logs, passive DNS data, or large-scale crawling. This is exactly what third-party services aggregate.


Database errors

The app logs which database it's using, and any migrations it applied, when it starts. For problems specific to SQLite, such as where the file lives, permissions on it, or writes timing out, see SQLite Setup.


Some features not visible

User accounts and sign-in aren't available on self-hosted, since they were built for a Supabase-based architecture. All our Supabase code is open source, and so can be self-hosted if you need them, it is just a significantly more involved setup. See Self-hosting Domain Locker and Supabase for more details.


Hey there! 👋

I hope you're finding Domain Locker useful. If you'd like to support my work, consider becoming a sponsor on GitHub Sponsors. Every contribution however small is greatly appreciated and helps me keep these tools running and open source.
Either way, thanks for being here—you're awesome! 🚀