IP WHOIS Database


Overview

Our IP WHOIS Database delivers clean, consistently parsed ownership data for any IPv4/IPv6 range, so you can verify who controls an address block, identify the right contacts, and act with confidence. Use it to harden security, speed up network troubleshooting, validate IP ownership during onboarding or investigations, and enrich tooling with reliable WHOIS insights across the global internet.

Raw WHOIS text is preserved for auditability. Available as CSV and MMDB, with JSON, Parquet, or any custom format on request at no extra cost, backed by stable schemas and changelogs. Below, you'll find full documentation of the archive contents, schema definitions, file specifications, and integration notes to help you get up and running quickly.


Available Database Formats

MMDB
MMDBMMDB
  • File Size: 22.00 MB
  • Entries: 11.2M
  • Fields: 55
  • Last Updated: Yesterday

CSV Database Documentation


1. Overview

The CSV version is a set of Gzip-compressed CSV files containing IP ranges and detailed IP WHOIS information. These files are designed for bulk imports and integration into relational databases.


2. Archive Content

After downloading and extracting the IP WHOIS CSV database archive, you'll find the following files (with their types noted):


Schema

This section describes the schema of each file included in the IP WHOIS Database archive. For every file, you'll find its purpose, field definitions, and examples to help with integration.


1. db-ip-whois.csv.gz

This file contains detailed WHOIS information for IP address ranges. It maps each IP block to the name, country, domain, and RIR, as well as various contact handle IDs and the full raw_whois record.


2. db-handles-details.csv.gz

This file contains detailed information on various network handles. It links a unique ID to a specific handle, name, country, address, and contact details such as email, phone, and fax.


3. db-org-details.csv.gz

This file provides detailed organization information. It links a unique ID to an organization's handle, name, type, address, country, and various contact details including email, phone, and fax.


4. File Relationship Diagram

The diagram below illustrates the relationships between the various files included in the CSV database package. It shows how the main CSV file connects to reference tables for person and organization handle files, ensuring consistent and accurate data across for all the records.

Image

File Format & Encoding

All IP WHOIS CSV datasets are provided in UTF-8 encoding, comma-separated, and compressed with Gzip (.csv.gz). Each file includes a header row listing the field names for clarity and consistency.

Field values are unquoted by default, with quotes applied only in the following cases:

  • Line breaks within text fields.
  • Commas inside a value (e.g., addresses).
  • Lists of values (e.g., languages).
  • Spaces that may be auto-quoted by export tools.

MMDB Database Documentation


1. Overview

MMDB version of the database consists of two files: one MMDB file containing all the data (organization and contact handle details), a README file, and a checksum file, and one checksum file, all compressed together in a ZIP file for easy delivery.


2. Archive Content

After downloading and extracting the IP WHOIS MMDB database archive, you'll find the following files (with their types noted):

db-ip-whois.mmdb
db-ip-whois.mmdbdb-ip-whois.mmdb

Full WHOIS details for IP addresses: name, country, domain, RIR, contact IDs, and raw WHOIS record.

  • File Size: 22.00 MB
  • Entries: 11.2M
README.md
README.mdREADME.md

Documentation for dataset contents, schema, usage, and support.

  • File Size: 7.97 KB
db-ip-whois.md5
db-ip-whois.md5db-ip-whois.md5
  • File Size: 95 Bytes

Response Schema

This section describes the structure of the data returned from the IP WHOIS MMDB file. Each field is detailed with its type, meaning, and example values to help you interpret responses and integrate them into your applications.


1. db-ip-whois.mmdb

This file contains detailed WHOIS mappings for both IPv4 and IPv6 address ranges. Below is an example of the structure you'll find in the response.


2. Field Reference

The following reference lists all fields available in the MMDB response. Each entry includes the field path, its description, data type, and example value to help you understand how to parse and integrate the data.

Showing 7 of 53
Select a field to view details

I. Example Records

Example
{
  "whois": {
    "abuse_handles": [
      {
        "address": "TOT Public Company Limited, 89/2 Moo 3 Chaengwattana Rd, Laksi, Bangkok 10210 THAILAND, ZZ",
        "country": "ZZ",
        "date_updated": "2026-08-13T06:48:44",
        "email": "abuse@totisp.net",
        "fax": "",
        "handle": "at950-ap",
        "name": "ABUSE TOTTH",
        "phone": "+000000000",
        "source": "APNIC"
      }
    ],
    "admin_handles": [
      {
        "address": "TOT Public Company Limited, 89/2 Moo 3 Chaengwattana Rd, Laksi, Bangkok 10210 THAILAND, Thailand",
        "country": "TH",
        "date_updated": "2022-08-29T04:23:40",
        "email": "abuse@totidc.net",
        "fax": "",
        "handle": "ag100-ap",
        "name": "Apipol Gunabhibal",
        "phone": "+66-2574-9178",
        "source": "APNIC"
      }
    ],
    "country": "TH",
    "date_created": "null",
    "date_updated": "2021-01-27T13:27:58",
    "domain": "totisp.net",
    "irt_handles": [
      {
        "address": "TOT Public Company Limited, 89/2 Moo 3 Chaengwattana Rd, Laksi, Bangkok 10210 THAILAND",
        "country": "",
        "date_updated": "2026-08-13T06:48:30",
        "email": "abuse@totisp.net",
        "fax": "",
        "handle": "IRT-ENTITY",
        "name": "IRT-TOT-TH",
        "phone": "",
        "source": "APNIC"
      }
    ],
    "name": "pinnedunderwater_Subdistrict_Administrative_Organization",
    "organization": {},
    "raw_whois": "% [whois.apnic.net]\n% Whois data copyright terms    http://www.apnic.net/db/dbcopyright.html\n\n% Information related to '1.179.139.81 - 1.179.139.82'\n\n% Abuse contact for '1.179.139.81 - 1.179.139.82' is 'abuse@totisp.net'\n\ninetnum:        1.179.139.81 - 1.179.139.82\nnetname:        pinnedunderwater_Subdistrict_Administrative_Organization\ndescr:          pinnedunderwater_Subdistrict_Administrative_Organization , Phetchaburi\ncountry:        TH\nadmin-c:        ag100-ap\ntech-c:         ws431-ap\nabuse-c:        AT950-AP\nstatus:         ASSIGNED NON-PORTABLE\nnotify:         abuse@totisp.net\nmnt-by:         MAINT-TH-TOT\nmnt-irt:        IRT-TOT-TH\nlast-modified:  2021-01-27T13:27:58Z\nsource:         APNIC\n\nirt:            IRT-TOT-TH\naddress:        TOT Public Company Limited\naddress:        89/2 Moo 3 Chaengwattana Rd, Laksi,Bangkok 10210 THAILAND\ne-mail:         apipolg@ntplc.co.th\nabuse-mailbox:  abuse@totisp.net\nadmin-c:        ira3-ap\ntech-c:         ira3-ap\nauth:           # Filtered\nremarks:        apipolg@ntplc.co.th was validated on 2026-07-07\nremarks:        abuse@totisp.net was validated on 2026-08-13\nmnt-by:         MAINT-TH-TOT\nlast-modified:  2026-08-13T06:48:30Z\nsource:         APNIC\n\nrole:           ABUSE TOTTH\ncountry:        ZZ\naddress:        TOT Public Company Limited\naddress:        89/2 Moo 3 Chaengwattana Rd, Laksi,Bangkok 10210 THAILAND\nphone:          +000000000\ne-mail:         apipolg@ntplc.co.th\nadmin-c:        ira3-ap\ntech-c:         ira3-ap\nnic-hdl:        AT950-AP\nremarks:        Generated from irt object IRT-TOT-TH\nremarks:        apipolg@ntplc.co.th was validated on 2026-07-07\nremarks:        abuse@totisp.net was validated on 2026-08-13\nabuse-mailbox:  abuse@totisp.net\nmnt-by:         APNIC-ABUSE\nlast-modified:  2026-08-13T06:48:44Z\nsource:         APNIC\n\nperson:         Apipol Gunabhibal\nnic-hdl:        AG100-AP\ne-mail:         abuse@totidc.net\naddress:        TOT Public Company Limited\naddress:        89/2 Moo 3 Chaengwattana Rd, Laksi, Bangkok 10210 THAILAND\nphone:          +66-2574-9178\ncountry:        TH\nmnt-by:         MAINT-TH-TOT\nlast-modified:  2022-08-29T04:23:40Z\nsource:         APNIC\n\nperson:         Worawat Songwiwat\nnic-hdl:        WS431-AP\ne-mail:         boy@totbb.net\naddress:        TOT Public Company Limited\naddress:        89/2 Moo 3, Chaengwattana Rd, Tungsonghong, Laksi, Bangkok 10210\nphone:          +66-81-876-8917\ncountry:        TH\nmnt-by:         MAINT-TH-TOT\nlast-modified:  2018-08-07T06:07:42Z\nsource:         APNIC\n\n% Information related to '1.179.139.0/24AS131293'\n\nroute:          1.179.139.0/24\norigin:         AS131293\ndescr:          TOT Public Company Limited\n                National Telecom Public Company Limited\n                Chaengwattana Office\n                89/2 Chaengwatthana Road\n                Thoongsonghong\nmnt-by:         MAINT-TH-TOT\nlast-modified:  2025-12-09T07:21:40Z\nsource:         APNIC\n\n% This query was served by the APNIC Whois Service version 1.88.48 (WHOIS-UK2)",
    "rir": "apnic",
    "tech_handles": [
      {
        "address": "TOT Public Company Limited, 89/2 Moo 3, Chaengwattana Rd, Tungsonghong, Laksi, Bangkok 10210, Thailand",
        "country": "TH",
        "date_updated": "2018-08-07T06:07:42",
        "email": "boy@totbb.net",
        "fax": "",
        "handle": "ws431-ap",
        "name": "Worawat Songwiwat",
        "phone": "+66-81-876-8917",
        "source": "APNIC"
      }
    ]
  }
}

Database Integrity & Authenticity Verification

There are two methods of verifying the integrity and authenticity of our Database:


1. Using the Signature File (Recommended)

IPGeolocation.io signs every database release to ensure its authenticity and integrity. This allows customers to verify that a downloaded IP WHOIS database file originates directly from IPGeolocation.io and has not been altered, corrupted, or tampered with during transfer or storage.

Each database update includes a corresponding signature file, generated using our private signing key. Customers can validate the database using the provided public verification key. To verify a database file, you need:

  1. Database file (the downloaded archive)
  2. Signature file (the matching signature for that archive)
  3. Public key (public-key.pem)

These files are available via official IPGeolocation.io download endpoints and are also shared in database update notifications.


2. Using the Checksum File (Legacy)

Each database archive includes a checksum.txt file containing the SHA-256 checksums for the files packaged in the archive. You can use this file to validate that the extracted contents are complete and unchanged.


Data Format & Constraints

  • All fields defined in the schema are always present in the IP WHOIS MMDB response.
  • Fields may contain empty strings (""), but never null, so null checks are not required.
  • Place names such as countries, states, districts, and cities are available in multiple translations.
  • All text values are encoded in UTF-8.
  • Field names and response structure remain stable across updates for backward compatibility.

Database Updates & Delivery

When you subscribe to our IP WHOIS database, we'll send you static download links. These links never change, so you can use them both for your initial download and for all future updates. You will receive:

  1. Database Archive URL : downloads the latest release of your subscribed database (CSV, MMDB or requested formats).
  2. Signature File URL : downloads the matching signature file for the latest release (used for authenticity verification).
  3. Public Key URL : downloads the public verification key (used with the signature file).
  4. Status Endpoint URL : returns the database's most recent update timestamp.

Our databases are updated continuously and shipped on a daily or weekly cycle depending on your plan, ensuring you always have access to the most current data. Each time your subscribed dataset is updated, you'll also receive an email notification so you don't miss a release.

For automated workflows, you can check our status endpoint to see the last update timestamp. When the date changes, simply re-fetch the archive using your static download URL to pull the latest version into your system.

Subscribe to Our Newsletter

Get the latest in geolocation tech, straight to your inbox.