IP WHOIS Lookup

Look up WHOIS information for any IP address using the RDAP protocol. View the owning organization, network range, country, registration dates, and abuse contact.

What Is an IP WHOIS Lookup?

IP addresses on the internet are allocated to organisations through the regional internet registries, and those allocation records are public. An IP WHOIS lookup queries that information to show you the holding organisation, the range of the network, the country and date of registration, and the contact address for reporting abuse. This tool retrieves the data over RDAP, the protocol in current use.

What you learn is strictly «who this address is allocated to» — not where it is actually in use, nor who the individual user is. Bear in mind too that for a range allocated to a cloud provider, what you see is the provider's name, not the operator of whatever service runs on top of it.

How to Run an IP WHOIS Lookup

  1. Enter the IP address Both IPv4 and IPv6 can be looked up. To check the address you are connecting from, use the detect button.
  2. Check the holding organisation and range The network name and the allocated range are shown. The range also tells you which other addresses the same organisation holds.
  3. Check the contact address A destination for abuse reports is sometimes listed. It is what you need when you have to report the source of an attack.

Tips for getting more out of it

  • Spam / intrusion investigation: When a suspicious IP appears in your logs, look up the owning organization and abuse contact to file a report.
  • Network administration: Verify the subnet range and registered owner of an IP block.
  • Confirm CDN / cloud providers: Look up well-known IPs like Google's 8.8.8.8 to verify their owner.
  • RDAP (Registration Data Access Protocol) is the modern replacement for WHOIS, returning structured JSON over HTTPS.

When an IP WHOIS Lookup Comes in Handy

Tracing where suspicious access came from

You can find out which organisation and country an unfamiliar IP in your server log is allocated to — a starting point for deciding whether any response is needed.

Identifying where to report

For the source of an attack or of nuisance traffic, you can find the abuse contact published by whoever holds the allocation.

Deciding the scope of an access restriction

When you want to restrict access from a particular organisation, check the allocated range that the IP belongs to and specify that.

Auditing your own network's registration

You can confirm whether the registration details for addresses allocated to your organisation are current. If the contact is out of date, reports will never reach you.

WHOIS and IP Allocation Terms

WHOIS
The mechanism for querying registration details of domains and IP addresses. Strictly it refers to the long-standing, text-based query method.
RDAP
A query protocol designed as the successor to WHOIS. Its results are structured, which makes them well suited to machine processing.
Registry
The organisation that manages IP address allocation for a given region. The Asia-Pacific region is handled by APNIC.
Handle
An identifier a registry attaches to a registration entry. It gives you a thread to follow to other entries belonging to the same organisation.
Abuse Contact
The point of contact for reporting misuse originating from that network. In some regions registering one is mandatory.
Reverse DNS
The mechanism for finding the host name corresponding to an IP address. It sometimes carries a name the operator deliberately set.

FAQ

No. Private and reserved addresses are not routable on the public internet and have no WHOIS records. Only public IP addresses can be looked up.

Results are cached for 24 hours. Wait a while and try again, or check rdap.org directly for real-time data.

Yes, both IPv4 and IPv6 addresses are supported.

RDAP data varies by registry (ARIN, RIPE, APNIC, etc.). Not all fields are populated for every IP block.
Tool-kun

Side Note — WHOIS history and the GDPR turning point

WHOIS was born in 1982 as RFC 812 during the ARPANET era. Originally a small database to identify who managed each computer, it grew into critical infrastructure as the commercial internet expanded.

The GDPR's enforcement in 2018 fundamentally changed domain WHOIS. Registrant contact details became protected as personal data, and most registrars began redacting them. IP address WHOIS (RDAP) was less affected since it primarily records organizational data, and most IP block registration information remains publicly accessible.

RDAP (Registration Data Access Protocol) is now the standardized successor to WHOIS. Unlike WHOIS which used plain text over port 43, RDAP operates over HTTPS with JSON responses, supporting authentication, access control, and internationalization. This tool uses RDAP.