Status codes are the part most people scroll past, and they are usually the answer. Any code prefixed with client was set by the registrar; anything prefixed with server was set by the registry, and only the registry can lift it. clientTransferProhibited is normal and healthy: it is the transfer lock most registrars enable by default, not a warning. The ones that matter are clientHold and serverHold: a held domain is pulled out of the TLD zone entirely, so it stops resolving while the registration itself is still valid. If a site went dark and the apex returns NXDOMAIN, look for a hold before you touch DNS. redemptionPeriod means it already expired and was deleted; pendingDelete means the name drops in about five days. A bare ok, with no locks at all, is arguably worse on a production domain than clientTransferProhibited.
Creation Date is the original registration, not the last renewal: a 2003 creation date on a domain that changed hands last year tells you nothing about who runs it now. Registry Expiry Date is the one that counts, because it is the registry's own record; the desktop build highlights it in amber under sixty days. Your registrar's control panel often shows a later date, since registrars renew ahead of the registry. After expiry a gTLD normally gets around thirty days of auto-renew grace, then a thirty-day redemption period with a punitive restore fee, then five days of pendingDelete.
Name servers are shown as the registry holds the delegation, which is what the TLD zone actually hands out. Compare that list against the NS records from a
DNS lookup: a mismatch means either a delegation change that has not propagated, or a lame delegation where the parent points at servers that are no longer authoritative, a classic cause of intermittent resolution failures.
Redaction is the default, not evasion. Since GDPR, gTLD whois strips registrant name, address, phone and email, so REDACTED FOR PRIVACY tells you nothing about a domain's reputation. What survives is what ICANN still mandates: registrar, dates, name servers, status codes and Registrar Abuse Contact Email. That last field is the one you actually want for a takedown. ccTLDs vary sharply: AFNIC still publishes legal entities for .fr while hiding individuals, and DENIC returns little beyond technical fields for .de.