PublicIPChecker

Guide

How to find out who owns an IP address

5 min read · Updated 2026-09-28

WHOIS and RDAP records show which organisation registered an IP block — not the person behind it. What the records actually contain, where to read them, and how to report abuse.

What you will (and won't) learn

A WHOIS (or its modern successor RDAP) record for an IP address answers one question: which organisation holds the address block? The record shows the registered organisation (usually the ISP, CDN or cloud that was allocated the range), the exact block boundaries, the registry that issued it (ARIN, RIPE NCC, APNIC, LACNIC or AFRINIC), the allocation dates, and — crucially — the organisation's abuse contact.

It does not show the individual using the address at this moment. For subscriber identity, the ISP's own logs are the source, and they are released under legal process, not on request. (WHOIS for domain names has been redacted the same way since 2018 — the same logic applies.)

IPv4 vs IPv6 records

IPv4IPv6
GranularityDetailed — often down to the specific ISP customer rangeCoarser — frequently only the regional registry plus the ISP
Historical dataDecades of transfer recordsShorter, still being built out
Practical read"This address belongs to this carrier's residential pool""This prefix belongs to this ISP"

That coarseness is one reason the ASN is the field worth checking for v6 — the network identity is usually the most specific signal available.

Where to look

  • This site: the home page and the lookup tool show the organisation and ASN for any address, resolved from public registration data — the WHOIS answer in one card.
  • Command line: whois 203.0.113.45 prints the full classic record.
  • RDAP (the modern API): https://rdap.org/ip/203.0.113.45 returns the same data as structured JSON — what tools, search engines and this site's own data pipeline use.
  • Registry sites (whois.ripe.net, arin.net, apnic.net, …) serve the authoritative records per region.

Reporting abuse

Every record lists an abuse contact — an email address or form where the network owner handles complaints. A useful report contains: the exact address, dates and times (with time zone), what happened, and evidence (packets, screenshots, log lines). For a home user whose own address is causing the problem, the faster path is your ISP's support line directly. If the offence was mail-based, the blacklist delisting process runs in parallel with the abuse report.

The honest limits

  • Ownership ≠ identity — you learn the network, not the person.
  • Large blocks — a single registration can cover a city's worth of addresses.
  • Datacentre addresses stop one level earlier: the record names the host, and the tenant behind a VPS is known only to the host's account system.
  • Records lag — recent transfers and new allocations take time to propagate everywhere.

Putting it together: the checker's ISP / organisation + ASN fields and the datacenter verdict are the everyday answer to "whose network is this?"; WHOIS/RDAP is the paper trail when you need the block boundaries, the registry, or the abuse contact.

Frequently asked questions

Can WHOIS tell me who is using an IP address?

It tells you which organisation registered the block — an ISP, a cloud, a CDN. The individual subscriber behind a dynamic address is only in the ISP's logs, behind legal process.

Why does my VPN's IP say 'Hetzner' or 'OVH'?

Because those are datacentre companies that own the address blocks the VPN rents — the registration names the block's owner, not the VPN brand. See the datacenter guide in the guides section for the full picture.

Is RDAP better than classic WHOIS?

For machines, yes — structured JSON, standardised fields, no scraping restrictions. The underlying data is the same registry information.


Keep reading

Check any other IP address

Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.