IP WHOIS Lookup
Find which organisation holds an IP block, the range it belongs to, and the registered abuse contact to report misuse to.
Enter a public IP address to see which organisation holds the block and where to report abuse.
Related tools
All Network tools →This tool queries an external service to answer your request. Only the value you enter — such as a domain or IP address — is sent. Your other data stays on your device.
This tool reads public records — DNS, WHOIS and certificate data that registries and servers publish openly. It sends nothing to the host you enter and changes nothing there. Use it on infrastructure you own or are authorised to look into.
About the IP WHOIS Lookup
Find out which organisation holds an IP address, what network block it belongs to, and — the part most people are actually here for — the registered address to report abuse to. The record comes from whichever Regional Internet Registry allocated the block: ARIN for North America, RIPE for Europe and the Middle East, APNIC for Asia-Pacific, LACNIC for Latin America and AFRINIC for Africa.
This is the WHOIS that still works. Domain WHOIS was largely emptied out by GDPR, and looking up who owns a domain now usually returns a set of redacted fields. IP WHOIS was mostly untouched, because the records describe organisations holding infrastructure rather than individuals, and because the abuse contact exists specifically so that strangers can use it. So where a domain lookup often gives you nothing, this generally gives you a named company, a postal address and a monitored inbox.
The practical use is reporting. If an address is brute-forcing your SSH, scraping your site or sending you phishing, the abuse contact here is the party who can actually do something about it — they either operate the machine or they are the provider who rents it to whoever does. A useful report names the address, gives timestamps in UTC, describes what happened and includes a few log lines. Sending that to the abuse address on the record is far more effective than most people expect, particularly with hosting providers, who generally do not want their ranges getting a reputation.
The allocation fields are worth reading too. A direct allocation means the organisation named holds the block from the registry itself, so it is usually a real network operator. A reassignment means the block was sub-allocated by a larger provider to a customer, which tells you that the named organisation rents rather than owns — and that escalating to the parent block's contact is an option if the immediate one does not respond. For location and ASN details rather than registration, use our IP Address Lookup.
How to use the IP WHOIS Lookup
-
Enter the address
Type any public IPv4 or IPv6 address. A port or CIDR suffix pasted from a log or firewall rule is removed automatically.
-
Run the lookup
Complete the verification check and press Look up IP WHOIS. The record is fetched from the responsible registry at that moment.
-
Find the abuse contact
It is shown as its own section. That address is monitored specifically for reports from strangers, which is exactly what you are.
-
Write a useful report
Include the IP address, timestamps in UTC, what happened, and a few relevant log lines. Concrete reports get acted on; vague ones do not.
Frequently asked questions
Why does IP WHOIS still show real details when domain WHOIS does not?
Because they describe different things. Domain WHOIS held the personal details of individual registrants, which GDPR required to be removed from public view. IP WHOIS describes organisations holding network infrastructure — companies, ISPs, universities — which is not personal data in the same way. The abuse contact in particular is published deliberately, because the entire point of it is that strangers who are being attacked can find somewhere to complain.
Is it worth actually sending an abuse report?
More often than people assume, particularly to hosting and cloud providers. They generally do not want their ranges acquiring a reputation that gets them blocked, and a compromised customer server is usually a problem they want to know about. Reports about residential ISP addresses are less likely to produce a visible response, though many ISPs do act on them internally. A specific report with UTC timestamps and log lines gets far better results than a general complaint.
The organisation shown is a big cloud provider, not the actual attacker. Now what?
That is the normal case and it is still the right place to report. The provider rents that address to a customer and has both the records to identify them and the contract terms to act. You will not be told who the customer is — that is their private business relationship — but the machine will often be taken offline. That is the outcome you wanted anyway.
What is the difference between a direct allocation and a reassignment?
A direct allocation means the named organisation holds the block from the registry itself, so it is generally a genuine network operator. A reassignment means a larger provider sub-allocated the block to a customer, so the named organisation is renting it. That distinction matters when you are reporting: if a reassigned block's contact ignores you, the parent block's contact is a legitimate next step.
Can I find out who was using an address at a particular time?
Not from here, and not from any public source. WHOIS shows who holds the block now, not who was assigned a specific address at a specific moment. That mapping exists only in the operator's own logs, and they release it to law enforcement with a valid legal order rather than to members of the public. If your situation genuinely needs it, that is the route.
Do you store the addresses I look up?
No. The address is sent to the lookup service and is not written to our database or our logs. We count that a lookup happened so we know the tool is used, with no record of which address, who asked, or what came back.