Skip to main content
Back to blog

Reading an IP WHOIS Record: A Practical Guide

IP Lookup

Reading an IP WHOIS Record: A Practical Guide article illustration

An IP WHOIS record looks like a wall of abbreviations, and the useful part is usually four lines of it.

It is also routinely misread, in two specific ways. People expect it to name a person, and it almost never does. And they assume it is the same WHOIS they have used to look up a domain, which it is not.

Two different systems wearing one name

There are two separate registries here, run by different organisations under different rules.

Domain WHOIS covers names like example.com. It is coordinated by ICANN through registrars, and it has been formally retired. ICANN’s own announcement is unambiguous: as of 28 January 2025, the Registration Data Access Protocol “will be the definitive source for delivering generic top-level domain name (gTLD) registration information in place of sunsetted WHOIS services”. If you are looking up a domain, the old protocol is gone.

IP WHOIS covers addresses and the networks they sit in. It is run by the five Regional Internet Registries, not by ICANN’s registrar system, and it was not part of that sunset. The registries still answer WHOIS queries today, alongside RDAP.

This matters practically, because advice written about one gets applied to the other constantly. A guide telling you WHOIS is dead is talking about domains. A guide telling you WHOIS will name the owner is talking about domains too, and even there it usually will not any more.

What an IP record actually contains

Field names differ between registries, which is itself a common source of confusion. ARIN uses one style, RIPE another. The concepts line up.

The range. NetRange at ARIN, inetnum at RIPE, usually shown alongside its CIDR notation. This is the block the address belongs to, and it is the first thing worth reading, because the size tells you a great deal. A small block often means an end organisation. A very large one means you are looking at a provider’s pool and the record describes the provider, not whoever is using the address today.

The name. NetName or netname. A short label for the block, frequently an abbreviation of the holder.

The organisation. OrgName at ARIN, or the org and descr fields at RIPE. This is the entity the block is allocated to. It is a company, not a customer.

The country. The registered country of the allocation. Worth treating carefully: it is where the block is registered, which need not be where the address is being used.

Dates. Registration and last-updated. A block updated recently has changed hands or had its details revised, which is useful context when a record does not match what you expected.

Contacts. Administrative, technical and abuse. The abuse contact is the one that does real work, covered below.

The autonomous system. Often shown alongside as an ASN, the identifier of the network announcing the route. This tells you who is actually carrying the traffic, which can differ from who the block is allocated to. What an ASN is covers where that number comes from and what it can honestly tell you.

The order to read them in. Range first, to see whether you are looking at one organisation or a provider’s pool. Then organisation, to see who holds it. Then the ASN, to see who is actually carrying the traffic, because a block allocated to one company is often announced by another. Everything else is detail. Four fields answer most questions, and the rest of the record is there for the times they do not.

What it cannot tell you

It does not name a person. For consumer addresses the record describes the ISP. Your neighbour’s broadband and yours resolve to the same organisation, the same block and the same abuse contact. There is no field that has ever contained a subscriber’s identity, and any service claiming to provide one from WHOIS is selling something else.

It is not a location service. The country field is registration data. Geolocation is a separate commercial industry built on inference, and the two disagree often, which is exactly why an address can resolve to the wrong town or occasionally the wrong country. Why your IP location is wrong covers how that gap opens up.

It does not tell you what the address is doing. Reputation, whether an address is flagged as a proxy, and whether it appears on a mail blocklist are all separate systems with separate data. A clean WHOIS record says nothing about any of them.

Five registries, and how referrals work

Address space is administered regionally. ARIN covers North America, RIPE NCC covers Europe and the Middle East, APNIC the Asia-Pacific, LACNIC Latin America and the Caribbean, and AFRINIC the African region.

Query the wrong one and you get a referral rather than an answer. This is a genuine improvement in the newer protocol: ARIN notes that RDAP offers “direct referrals to other RIRs, whereas Whois defines no queries or responses” for that. In practice a good lookup tool handles the routing for you and you never see it.

RDAP, which is already the answer

Even on the IP side, RDAP is where things are heading, and the reasons are practical rather than ceremonial.

WHOIS is a plain-text protocol whose output was designed to be read by people and has no consistent structure between registries, which makes parsing it reliably a nuisance. RDAP is, in ARIN’s description, “an HTTP-based REST-style protocol with standardized responses specified in JSON”, where WHOIS “is a text-based protocol”. It also handles non-English data properly, where WHOIS response objects “may not be” translatable.

For reading one record by eye, the difference is invisible. For anything automated, it is the difference between parsing prose and reading a structured document.

The abuse contact, and using it well

The abuse contact is the field with the most practical value, and the one most often used badly.

It is a real address, monitored by real people at the network holder, for reporting traffic originating from that network. If something is genuinely attacking you and you can show it, that is the correct place to send it.

Send something useful or do not send anything. A report that includes the address, timestamps with the time zone stated, and the relevant log lines can be acted on. A report saying you are being hacked, with no evidence attached, cannot. Bear in mind the recipient may be running a network of millions of addresses, and that a single failed login attempt is background noise on the internet rather than an incident.

If the traffic is coming from a consumer connection, the likely cause is a compromised machine whose owner has no idea. The provider is the only party who can reach them, which is precisely why the contact exists.

Looking one up

The IP checker resolves any address to its organisation, network and registered details, which is the practical version of everything above and the quickest way to see a real record rather than a description of one. To see what your own connection presents first, your IP address page shows the address and the provider it is attributed to.

Two things are worth reading alongside a record rather than from it. If the address you are investigating showed up on a mail blocklist, why an IP gets blacklisted explains why the most common listing is not an accusation. And if you are chasing a location that looks wrong, the WHOIS country field is not the place to resolve it.