# IP WHOIS

GET /lookup/ip-whois: Returns the current registration details of an IP address from the regional internet registries (RDAP/WHOIS): the owning network and its…

Source: https://docs.deepinfo.com/reference/lookup/ip-whois/

Last updated: 2026-09-27

---
`GET https://api.deepinfo.com/v1/lookup/ip-whois`

Returns the **current** registration details of an IP address from the regional internet registries (RDAP/WHOIS): the owning network and its range, the ASN, the registry, and contact entities.

## Authentication

Send your API key in the `apikey` request header.

## Query Parameters

| Parameter | Required | Description | Example |
|---|---|---|---|
| `ip` | Required | IPv4 or IPv6 address. | `8.8.8.8` |

## Response Fields

| Field | Description |
|---|---|
| `ip` | The queried IP address |
| `ipwhois.asn` | Number of the autonomous system (AS) that announces the IP |
| `ipwhois.asn_cidr` | The announced IP range that contains the IP |
| `ipwhois.asn_description` | Name of the AS |
| `ipwhois.asn_country_code` | Country code of the AS |
| `ipwhois.asn_registry` | Regional internet registry of the AS |
| `ipwhois.asn_date` | Allocation date of the AS |
| `ipwhois.network` | The registered network that contains the IP, with the `ipwhois.network.*` fields below |
| `ipwhois.network.cidr` | Network range in CIDR notation |
| `ipwhois.network.name` | Network name |
| `ipwhois.network.country` | Country of the network |
| `ipwhois.network.start_address` | First address of the range |
| `ipwhois.network.end_address` | Last address of the range |
| `ipwhois.network.ip_version` | IP version, e.g. `v4` |
| `ipwhois.network.handle` | Registry handle of the network |
| `ipwhois.network.parent_handle` | Handle of the parent network |
| `ipwhois.network.type` | Allocation type |
| `ipwhois.network.status` | Registration status |
| `ipwhois.network.events[]` | Registration events of the network |
| `ipwhois.network.events[].action` | What happened, e.g. `registration` |
| `ipwhois.network.events[].actor` | Who did it, when the registry says |
| `ipwhois.network.events[].timestamp` | When it happened (UTC) |
| `ipwhois.network.notices[]` | Registry notices |
| `ipwhois.network.notices[].title` | Notice title |
| `ipwhois.network.notices[].description` | Notice text |
| `ipwhois.network.notices[].links` | Links given with the notice |
| `ipwhois.network.remarks[]` | Registry remarks |
| `ipwhois.network.remarks[].title` | Remark title |
| `ipwhois.network.remarks[].description` | Remark text |
| `ipwhois.network.remarks[].links` | Links given with the remark |
| `ipwhois.network.links` | RDAP and WHOIS links for the network |
| `ipwhois.network.raw` | Raw registry answer for the network, when available |
| `ipwhois.entities` | Handles of related entities (organizations, contacts) |
| `ipwhois.objects` | Details for each entity handle, keyed by the handle: contact details, roles and registration events |
| `ipwhois.nir` | National Internet Registry data, where applicable |
| `check_date` | When the lookup was performed (UTC) |

## Response Schema

_Inferred from examples._ Built from the saved 2xx example response: the fields it contains, with the types seen there. It is not a contract.

| Field | Type |
|---|---|
| `ip` | string |
| `ipwhois` | object |
| `ipwhois.asn` | string |
| `ipwhois.asn_cidr` | string |
| `ipwhois.asn_description` | string |
| `ipwhois.asn_country_code` | string |
| `ipwhois.asn_registry` | string |
| `ipwhois.entities` | array<string> |
| `ipwhois.asn_date` | string |
| `ipwhois.nir` | null |
| `ipwhois.query` | string |
| `ipwhois.raw` | null |
| `ipwhois.network` | object |
| `ipwhois.network.cidr` | string |
| `ipwhois.network.name` | string |
| `ipwhois.network.country` | null |
| `ipwhois.network.start_address` | string |
| `ipwhois.network.end_address` | string |
| `ipwhois.network.handle` | string |
| `ipwhois.network.ip_version` | string |
| `ipwhois.network.links` | array<string> |
| `ipwhois.network.parent_handle` | string |
| `ipwhois.network.raw` | null |
| `ipwhois.network.status` | array<string> |
| `ipwhois.network.type` | string |
| `ipwhois.network.notices` | array<object> |
| `ipwhois.network.notices[].title` | string |
| `ipwhois.network.notices[].description` | string |
| `ipwhois.network.notices[].links` | array<string> |
| `ipwhois.network.remarks` | null |
| `ipwhois.network.events` | array<object> |
| `ipwhois.network.events[].action` | string |
| `ipwhois.network.events[].actor` | null |
| `ipwhois.network.events[].timestamp` | string |
| `ipwhois.objects` | object |
| `ipwhois.objects.GOGL` | object |
| `ipwhois.objects.GOGL.contact` | object |
| `ipwhois.objects.GOGL.contact.email` | null |
| `ipwhois.objects.GOGL.contact.address` | array<object> |
| `ipwhois.objects.GOGL.contact.address[].type` | null |
| `ipwhois.objects.GOGL.contact.address[].value` | string |
| `ipwhois.objects.GOGL.contact.phone` | null |
| `ipwhois.objects.GOGL.contact.kind` | string |
| `ipwhois.objects.GOGL.contact.name` | string |
| `ipwhois.objects.GOGL.contact.role` | null |
| `ipwhois.objects.GOGL.contact.title` | null |
| `ipwhois.objects.GOGL.entities` | array<string> |
| `ipwhois.objects.GOGL.events` | array<object> |
| `ipwhois.objects.GOGL.events[].action` | string |
| `ipwhois.objects.GOGL.events[].actor` | null |
| `ipwhois.objects.GOGL.events[].timestamp` | string |
| `ipwhois.objects.GOGL.events_actor` | null |
| `ipwhois.objects.GOGL.handle` | string |
| `ipwhois.objects.GOGL.links` | array<string> |
| `ipwhois.objects.GOGL.notices` | null |
| `ipwhois.objects.GOGL.raw` | null |
| `ipwhois.objects.GOGL.remarks` | array<object> |
| `ipwhois.objects.GOGL.remarks[].title` | string |
| `ipwhois.objects.GOGL.remarks[].description` | string |
| `ipwhois.objects.GOGL.remarks[].links` | null |
| `ipwhois.objects.GOGL.roles` | array<string> |
| `ipwhois.objects.GOGL.status` | null |
| `ipwhois.objects.ABUSE5250-ARIN` | object |
| `ipwhois.objects.ABUSE5250-ARIN.contact` | object |
| `ipwhois.objects.ABUSE5250-ARIN.contact.email` | array<object> |
| `ipwhois.objects.ABUSE5250-ARIN.contact.email[].type` | null |
| `ipwhois.objects.ABUSE5250-ARIN.contact.email[].value` | string |
| `ipwhois.objects.ABUSE5250-ARIN.contact.address` | array<object> |
| `ipwhois.objects.ABUSE5250-ARIN.contact.address[].type` | null |
| `ipwhois.objects.ABUSE5250-ARIN.contact.address[].value` | string |
| `ipwhois.objects.ABUSE5250-ARIN.contact.phone` | array<object> |
| `ipwhois.objects.ABUSE5250-ARIN.contact.phone[].type` | array<string> |
| `ipwhois.objects.ABUSE5250-ARIN.contact.phone[].value` | string |
| `ipwhois.objects.ABUSE5250-ARIN.contact.kind` | string |
| `ipwhois.objects.ABUSE5250-ARIN.contact.name` | string |
| `ipwhois.objects.ABUSE5250-ARIN.contact.role` | null |
| `ipwhois.objects.ABUSE5250-ARIN.contact.title` | null |
| `ipwhois.objects.ABUSE5250-ARIN.entities` | null |
| `ipwhois.objects.ABUSE5250-ARIN.events` | array<object> |
| `ipwhois.objects.ABUSE5250-ARIN.events[].action` | string |
| `ipwhois.objects.ABUSE5250-ARIN.events[].actor` | null |
| `ipwhois.objects.ABUSE5250-ARIN.events[].timestamp` | string |
| `ipwhois.objects.ABUSE5250-ARIN.events_actor` | null |
| `ipwhois.objects.ABUSE5250-ARIN.handle` | string |
| `ipwhois.objects.ABUSE5250-ARIN.links` | array<string> |
| `ipwhois.objects.ABUSE5250-ARIN.notices` | array<object> |
| `ipwhois.objects.ABUSE5250-ARIN.notices[].title` | string |
| `ipwhois.objects.ABUSE5250-ARIN.notices[].description` | string |
| `ipwhois.objects.ABUSE5250-ARIN.notices[].links` | array<string> |
| `ipwhois.objects.ABUSE5250-ARIN.raw` | null |
| `ipwhois.objects.ABUSE5250-ARIN.remarks` | array<object> |
| `ipwhois.objects.ABUSE5250-ARIN.remarks[].title` | string |
| `ipwhois.objects.ABUSE5250-ARIN.remarks[].description` | string |
| `ipwhois.objects.ABUSE5250-ARIN.remarks[].links` | null |
| `ipwhois.objects.ABUSE5250-ARIN.roles` | array<string> |
| `ipwhois.objects.ABUSE5250-ARIN.status` | array<string> |
| `ipwhois.objects.ZG39-ARIN` | object |
| `ipwhois.objects.ZG39-ARIN.contact` | object |
| `ipwhois.objects.ZG39-ARIN.contact.email` | array<object> |
| `ipwhois.objects.ZG39-ARIN.contact.email[].type` | null |
| `ipwhois.objects.ZG39-ARIN.contact.email[].value` | string |
| `ipwhois.objects.ZG39-ARIN.contact.address` | array<object> |
| `ipwhois.objects.ZG39-ARIN.contact.address[].type` | null |
| `ipwhois.objects.ZG39-ARIN.contact.address[].value` | string |
| `ipwhois.objects.ZG39-ARIN.contact.phone` | array<object> |
| `ipwhois.objects.ZG39-ARIN.contact.phone[].type` | array<string> |
| `ipwhois.objects.ZG39-ARIN.contact.phone[].value` | string |
| `ipwhois.objects.ZG39-ARIN.contact.kind` | string |
| `ipwhois.objects.ZG39-ARIN.contact.name` | string |
| `ipwhois.objects.ZG39-ARIN.contact.role` | null |
| `ipwhois.objects.ZG39-ARIN.contact.title` | null |
| `ipwhois.objects.ZG39-ARIN.entities` | null |
| `ipwhois.objects.ZG39-ARIN.events` | array<object> |
| `ipwhois.objects.ZG39-ARIN.events[].action` | string |
| `ipwhois.objects.ZG39-ARIN.events[].actor` | null |
| `ipwhois.objects.ZG39-ARIN.events[].timestamp` | string |
| `ipwhois.objects.ZG39-ARIN.events_actor` | null |
| `ipwhois.objects.ZG39-ARIN.handle` | string |
| `ipwhois.objects.ZG39-ARIN.links` | array<string> |
| `ipwhois.objects.ZG39-ARIN.notices` | array<object> |
| `ipwhois.objects.ZG39-ARIN.notices[].title` | string |
| `ipwhois.objects.ZG39-ARIN.notices[].description` | string |
| `ipwhois.objects.ZG39-ARIN.notices[].links` | array<string> |
| `ipwhois.objects.ZG39-ARIN.raw` | null |
| `ipwhois.objects.ZG39-ARIN.remarks` | null |
| `ipwhois.objects.ZG39-ARIN.roles` | array<string> |
| `ipwhois.objects.ZG39-ARIN.status` | array<string> |
| `check_date` | string |

## Errors

`400` if `ip` is not a valid IP address.

## Examples

### 200 · 8.8.8.8

```bash
curl 'https://api.deepinfo.com/v1/lookup/ip-whois?ip=8.8.8.8' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json'
```

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "ip": "8.8.8.8",
  "ipwhois": {
    "asn": "15169",
    "asn_cidr": "8.8.8.0/24",
    "asn_description": "GOOGLE - Google LLC, US",
    "asn_country_code": "US",
    "asn_registry": "arin",
    "entities": [
      "GOGL"
    ],
    "asn_date": "2023-12-28",
    "nir": null,
    "query": "8.8.8.8",
    "raw": null,
    "network": {
      "cidr": "8.8.8.0/24",
      "name": "GOGL",
      "country": null,
      "start_address": "8.8.8.0",
      "end_address": "8.8.8.255",
      "handle": "NET-8-8-8-0-2",
      "ip_version": "v4",
      "links": [
        "https://rdap.arin.net/registry/ip/8.8.8.0",
        "https://whois.arin.net/rest/net/NET-8-8-8-0-2"
      ],
      "parent_handle": "NET-8-0-0-0-0",
      "raw": null,
      "status": [
        "active"
      ],
      "type": "DIRECT ALLOCATION",
      "notices": [
        {
          "title": "Terms of Service",
          "description": "By using the ARIN RDAP/Whois service, you are agreeing to the RDAP/Whois Terms of Use",
          "links": [
            "https://www.arin.net/resources/registry/whois/tou/"
          ]
        },
        {
          "title": "Whois Inaccuracy Reporting",
          "description": "If you see inaccuracies in the results, please visit: ",
          "links": [
            "https://www.arin.net/resources/registry/whois/inaccuracy_reporting/"
          ]
        }
      ],
      "remarks": null,
      "events": [
        {
          "action": "last changed",
          "actor": null,
          "timestamp": "2023-12-28T22:24:56Z"
        },
        {
          "action": "registration",
          "actor": null,
          "timestamp": "2023-12-28T22:24:33Z"
        }
      ]
    },
    "objects": {
      "GOGL": {
        "contact": {
          "email": null,
          "address": [
            {
              "type": null,
              "value": "1600 Amphitheatre Parkway\nMountain View\nCA\n94043\nUnited States"
            }
          ],
          "phone": null,
          "kind": "org",
          "name": "Google LLC",
          "role": null,
          "title": null
        },
        "entities": [
          "ABUSE5250-ARIN",
          "ZG39-ARIN"
        ],
        "events": [
          {
            "action": "last changed",
            "actor": null,
            "timestamp": "2019-10-31T19:45:45Z"
          },
          {
            "action": "registration",
            "actor": null,
            "timestamp": "2000-03-30T05:00:00Z"
          }
        ],
        "events_actor": null,
        "handle": "GOGL",
        "links": [
          "https://rdap.arin.net/registry/entity/GOGL",
          "https://whois.arin.net/rest/org/GOGL"
        ],
        "notices": null,
        "raw": null,
        "remarks": [
          {
            "title": "Registration Comments",
            "description": "Please note that the recommended way to file abuse complaints are located in the following links. \n\nTo report abuse and illegal activity: https://www.google.com/contact/\n\nFor legal requests: http://support.google.com/legal \n\nRegards, \nThe Google Team",
            "links": null
          }
        ],
        "roles": [
          "registrant"
        ],
        "status": null
      },
      "ABUSE5250-ARIN": {
        "contact": {
          "email": [
            {
              "type": null,
              "value": "network-abuse@google.com"
            }
          ],
          "address": [
            {
              "type": null,
              "value": "1600 Amphitheatre Parkway\nMountain View\nCA\n94043\nUnited States"
            }
          ],
          "phone": [
            {
              "type": [
                "work",
                "voice"
              ],
              "value": "+1-650-253-0000"
            }
          ],
          "kind": "group",
          "name": "Abuse",
          "role": null,
          "title": null
        },
        "entities": null,
        "events": [
          {
            "action": "last changed",
            "actor": null,
            "timestamp": "2026-08-19T18:34:18Z"
          },
          {
            "action": "registration",
            "actor": null,
            "timestamp": "2015-11-06T20:36:35Z"
          }
        ],
        "events_actor": null,
        "handle": "ABUSE5250-ARIN",
        "links": [
          "https://rdap.arin.net/registry/entity/ABUSE5250-ARIN",
          "https://whois.arin.net/rest/poc/ABUSE5250-ARIN"
        ],
        "notices": [
          {
            "title": "Terms of Service",
            "description": "By using the ARIN RDAP/Whois service, you are agreeing to the RDAP/Whois Terms of Use",
            "links": [
              "https://www.arin.net/resources/registry/whois/tou/"
            ]
          },
          {
            "title": "Whois Inaccuracy Reporting",
            "description": "If you see inaccuracies in the results, please visit: ",
            "links": [
              "https://www.arin.net/resources/registry/whois/inaccuracy_reporting/"
            ]
          }
        ],
        "raw": null,
        "remarks": [
          {
            "title": "Registration Comments",
            "description": "Please note that the recommended way to file abuse complaints are located in the following links.\n\nTo report abuse and illegal activity: https://www.google.com/contact/\n\nFor legal requests: http://support.google.com/legal \n\nRegards,\nThe Google Team",
            "links": null
          }
        ],
        "roles": [
          "abuse"
        ],
        "status": [
          "validated"
        ]
      },
      "ZG39-ARIN": {
        "contact": {
          "email": [
            {
              "type": null,
              "value": "arin-contact@google.com"
            }
          ],
          "address": [
            {
              "type": null,
              "value": "1600 Amphitheatre Parkway\nMountain View\nCA\n94043\nUnited States"
            }
          ],
          "phone": [
            {
              "type": [
                "work",
                "voice"
              ],
              "value": "+1-650-253-0000"
            }
          ],
          "kind": "group",
          "name": "Google LLC",
          "role": null,
          "title": null
        },
        "entities": null,
        "events": [
          {
            "action": "last changed",
            "actor": null,
            "timestamp": "2025-11-10T12:10:31Z"
          },
          {
            "action": "registration",
            "actor": null,
            "timestamp": "2000-11-30T18:54:08Z"
          }
        ],
        "events_actor": null,
        "handle": "ZG39-ARIN",
        "links": [
          "https://rdap.arin.net/registry/entity/ZG39-ARIN",
          "https://whois.arin.net/rest/poc/ZG39-ARIN"
        ],
        "notices": [
          {
            "title": "Terms of Service",
            "description": "By using the ARIN RDAP/Whois service, you are agreeing to the RDAP/Whois Terms of Use",
            "links": [
              "https://www.arin.net/resources/registry/whois/tou/"
            ]
          },
          {
            "title": "Whois Inaccuracy Reporting",
            "description": "If you see inaccuracies in the results, please visit: ",
            "links": [
              "https://www.arin.net/resources/registry/whois/inaccuracy_reporting/"
            ]
          }
        ],
        "raw": null,
        "remarks": null,
        "roles": [
          "administrative",
          "technical"
        ],
        "status": [
          "validated"
        ]
      }
    }
  },
  "check_date": "2026-09-22T12:26:00Z"
}
```

## Worked Examples

Worked examples of this endpoint, each on its own page with the exact request and its response: [IP WHOIS Examples](/reference/lookup/ip-whois/examples/).

- [Google Public DNS (ARIN)](/reference/lookup/ip-whois/examples/arin-google-dns/): IP WHOIS of 8.8.8.8 (ARIN): AS15169 Google, network 8.8.8.0/24, with Google LLC as registrant and its abuse contact.
- [Cloudflare DNS (APNIC)](/reference/lookup/ip-whois/examples/apnic-cloudflare-dns/): IP WHOIS of 1.1.1.1 (APNIC): announced by Cloudflare (AS13335) but registered to APNIC Research and Development.
- [Yandex DNS (RIPE NCC)](/reference/lookup/ip-whois/examples/ripe-yandex-dns/): IP WHOIS of 77.88.8.8 (RIPE NCC): Yandex DNS, two ASNs in one field and no ASN description.
- [A Brazilian DNS Server (LACNIC)](/reference/lookup/ip-whois/examples/lacnic-nic-br/): IP WHOIS of 200.160.0.10 (LACNIC): NIC.br's network 200.160.0.0/20, identified by a Brazilian company number.
