WHOIS, and its structured successor RDAP, is the registration record for a domain. Even where the registrant's identity is redacted, the record still carries the fields that matter operationally: creation date, registrar, nameservers, and status flags.
Creation date is the single most useful signal in a fraud triage. A domain impersonating an established brand that was registered nine days ago is not a coincidence, and age is one of the few attributes an attacker cannot fake without paying for it in advance.
The registrar field decides where the abuse report goes, and the nameservers usually reveal the hosting provider, which is the other party who can act. Shared nameservers across several suspicious domains are also one of the cheapest ways to find the rest of a cluster.
Privacy redaction is now the default rather than the exception in most of the world, so treating a redacted record as suspicious is a mistake. It is a legal norm, not a signal.
How Fraudox handles it
Free domain scan