---
title: "IP WHOIS Database Documentation | IPGeolocation.io Docs"
slug: "/documentation/ip-whois-database.html"
parent: "IP Geolocation Databases"
description: "Comprehensive IP WHOIS documentation covering ranges, RIR sources, organization blocks, admin/tech/abuse contacts, and raw WHOIS. Updated daily."
---

# IP WHOIS Database

* * *

## Overview

Our IP WHOIS Database delivers clean, consistently parsed ownership data for any IPv4/IPv6 range, so you can verify who controls an address block, identify the right contacts, and act with confidence. Use it to harden security, speed up network troubleshooting, validate IP ownership during onboarding or investigations, and enrich tooling with reliable WHOIS insights across the global internet.

Raw WHOIS text is preserved for auditability. Available as CSV and MMDB, with JSON, Parquet, or any custom format on request at no extra cost, backed by stable schemas and changelogs. Below, you'll find full documentation of the archive contents, schema definitions, file specifications, and integration notes to help you get up and running quickly.

* * *

## Available Database Formats

**MMDB**

*   File Size: 22.00 MB

*   Entries: 11.2M

*   Fields: 55

*   Last Updated: Yesterday

[Documentation](https://ipgeolocation.io/documentation/ip-whois-database.html#mmdb-database-documentation)

> [!IMPORTANT]
> If you require our IP WHOIS Database in a different format, such as Parquet or any custom structure, please feel free to reach out to us via our [Contact form](https://ipgeolocation.io/db-pricing.html#contact-us-for-quote). We are happy to accommodate specific format requests to meet your needs.

* * *

## CSV Database Documentation

* * *

### 1. Overview

The CSV version is a set of Gzip-compressed CSV files containing IP ranges and detailed IP WHOIS information. These files are designed for bulk imports and integration into relational databases.

* * *

### 2. Archive Content

After downloading and extracting the IP WHOIS CSV database archive, you'll find the following files (with their types noted):

* * *

## Schema

This section describes the schema of each file included in the IP WHOIS Database archive. For every file, you'll find its purpose, field definitions, and examples to help with integration.

* * *

### 1. db-ip-whois.csv.gz

This file contains detailed WHOIS information for IP address ranges. It maps each IP block to the name, country, domain, and RIR, as well as various contact handle IDs and the full raw_whois record.

> [!TIP]
> `org_id` joins to `db-org-details.id` to get organization details for IP, and `*handles_id` keys join to `db-handles-details.id` to get contact handles details.

* * *

### 2. db-handles-details.csv.gz

This file contains detailed information on various network handles. It links a unique ID to a specific handle, name, country, address, and contact details such as email, phone, and fax.

> [!TIP]
> `id` in the db-handles-details.csv.gz file joins to the `*_handles_id` fields in db-ip-whois.csv.gz (e.g., admin_handles_id,tech_handles_id,abuse_handles_id,irt_handles_id).

* * *

### 3. db-org-details.csv.gz

This file provides detailed organization information. It links a unique ID to an organization's handle, name, type, address, country, and various contact details including email, phone, and fax.

> [!TIP]
> `id` in the db-org-details.csv.gz file joins to the `org_id` field in db-ip-whois.csv.gz (linking each IP range to its organization details).

* * *

### 4. File Relationship Diagram

The diagram below illustrates the relationships between the various files included in the CSV database package. It shows how the main CSV file connects to reference tables for person and organization handle files, ensuring consistent and accurate data across for all the records.

![Image](https://static.ipgeolocation.io/web-assets/images/database/er-diagrams/ip-whois.svg)

* * *

## File Format & Encoding

All IP WHOIS CSV datasets are provided in UTF-8 encoding, comma-separated, and compressed with Gzip (.csv.gz). Each file includes a header row listing the field names for clarity and consistency.

Field values are unquoted by default, with quotes applied only in the following cases:

*   Line breaks within text fields.
*   Commas inside a value (e.g., addresses).
*   Lists of values (e.g., languages).
*   Spaces that may be auto-quoted by export tools.

* * *

## MMDB Database Documentation

* * *

### 1. Overview

MMDB version of the database consists of two files: one MMDB file containing all the data (organization and contact handle details), a README file, and a checksum file, and one checksum file, all compressed together in a ZIP file for easy delivery.

* * *

### 2. Archive Content

After downloading and extracting the IP WHOIS MMDB database archive, you'll find the following files (with their types noted):

**db-ip-whois.mmdb**

Full WHOIS details for IP addresses: name, country, domain, RIR, contact IDs, and raw WHOIS record.

*   File Size: 22.00 MB

*   Entries: 11.2M

**README.md**

Documentation for dataset contents, schema, usage, and support.

*   File Size: 7.97 KB

**db-ip-whois.md5**

*   File Size: 95 Bytes

* * *

## Response Schema

This section describes the structure of the data returned from the IP WHOIS MMDB file. Each field is detailed with its type, meaning, and example values to help you interpret responses and integrate them into your applications.

* * *

### 1. db-ip-whois.mmdb

This file contains detailed WHOIS mappings for both IPv4 and IPv6 address ranges. Below is an example of the structure you'll find in the response.

* * *

### 2. Field Reference

The following reference lists all fields available in the MMDB response. Each entry includes the field path, its description, data type, and example value to help you understand how to parse and integrate the data.

#### I. Example Records

**Example**

```json
{
  "whois": {
    "abuse_handles": [
      {
        "address": "Avenida Paulista. 1636 Conj 4 Pavmto15 Sala 1504, 01310-200, Sao Paulo, BR",
        "country": "",
        "date_updated": "2026-04-20T20:43:33",
        "email": "report@abuseradar.com",
        "fax": "",
        "handle": "mcl141-ripe",
        "name": "Meteor Cloud LTDA",
        "phone": "",
        "source": "RIPE"
      }
    ],
    "admin_handles": [
      {
        "address": "Avenida Paulista. 1636 Conj 4 Pavmto15 Sala 1504, 01310-200, Sao Paulo, BR",
        "country": "",
        "date_updated": "2026-04-20T20:43:33",
        "email": "report@abuseradar.com",
        "fax": "",
        "handle": "mcl141-ripe",
        "name": "Meteor Cloud LTDA",
        "phone": "",
        "source": "RIPE"
      }
    ],
    "country": "EU",
    "date_created": "2026-03-18T14:42:10",
    "date_updated": "2026-04-20T20:43:33",
    "domain": "abuseradar.com",
    "irt_handles": [],
    "name": "ipxo",
    "organization": {
      "address": "Avenida Paulista. 1636 Conj 4 Pavmto15 Sala 1504, 01310-200, Sao Paulo, Brazil",
      "country": "BR",
      "date_updated": "2026-04-20T20:43:33",
      "email": "",
      "fax": "",
      "handle": "org-mcl148-ripe",
      "name": "Meteor Cloud LTDA",
      "phone": "",
      "source": "ripencc",
      "type": "other"
    },
    "raw_whois": "% This is the RIPE Database query service.\n% The objects are in RPSL format.\n%\n% The RIPE Database is subject to Terms and Conditions.\n% See https://docs.db.ripe.net/terms-conditions.html\n\n% Note: this output has been filtered.\n%       To receive output for a database update, use the -B flag.\n\n% Information related to '2.27.112.0 - 2.27.112.255'\n\n% Abuse contact for '2.27.112.0 - 2.27.112.255' is 'report@abuseradar.com'\n\ninetnum:        2.27.112.0 - 2.27.112.255\nnetname:        ipxo\ncountry:        EU\ngeofeed:        https://geofeed.ipxo.com/geofeed.txt\norg:            ORG-MCL148-RIPE\nadmin-c:        MCL141-RIPE\ntech-c:         MCL141-RIPE\nabuse-c:        MCL141-RIPE\nstatus:         SUB-ALLOCATED PA\nremarks:        End User Organization\nmnt-by:         netutils-mnt\ncreated:        2026-03-18T14:42:10Z\nlast-modified:  2026-04-20T20:43:33Z\nsource:         RIPE\n\norganisation:   ORG-MCL148-RIPE\norg-name:       Meteor Cloud LTDA\norg-type:       OTHER\nremarks:        End User Organization\naddress:        Avenida Paulista. 1636 Conj 4 Pavmto15 Sala 1504\naddress:        01310-200\naddress:        Sao Paulo\ncountry:        BR\nabuse-c:        MCL141-RIPE\nmnt-ref:        netutils-mnt\nmnt-by:         netutils-mnt\ncreated:        2026-04-20T20:43:33Z\nlast-modified:  2026-04-20T20:43:33Z\nsource:         RIPE # Filtered\n\nrole:           Meteor Cloud LTDA\naddress:        Avenida Paulista. 1636 Conj 4 Pavmto15 Sala 1504\naddress:        01310-200\naddress:        Sao Paulo\naddress:        BR\nnic-hdl:        MCL141-RIPE\nremarks:        End User Organization\nabuse-mailbox:  report@abuseradar.com\nmnt-by:         netutils-mnt\ncreated:        2026-04-20T20:43:33Z\nlast-modified:  2026-04-20T20:43:33Z\nsource:         RIPE # Filtered\n\n% Information related to '2.27.112.0/24AS210554'\n\nroute:          2.27.112.0/24\norigin:         AS210554\nmnt-by:         netutils-mnt\ncreated:        2026-04-20T20:43:33Z\nlast-modified:  2026-04-20T20:43:33Z\nsource:         RIPE\n\n% This query was served by the RIPE Database Query Service version 1.123 (SHETLAND)\n\n",
    "rir": "ripencc",
    "tech_handles": [
      {
        "address": "Avenida Paulista. 1636 Conj 4 Pavmto15 Sala 1504, 01310-200, Sao Paulo, BR",
        "country": "",
        "date_updated": "2026-04-20T20:43:33",
        "email": "report@abuseradar.com",
        "fax": "",
        "handle": "mcl141-ripe",
        "name": "Meteor Cloud LTDA",
        "phone": "",
        "source": "RIPE"
      }
    ]
  }
}
```

* * *

## Database Integrity & Authenticity Verification

There are two methods of verifying the integrity and authenticity of our Database:

* * *

### 1. Using the Signature File (Recommended)

IPGeolocation.io signs every database release to ensure its authenticity and integrity. This allows customers to verify that a downloaded IP WHOIS database file originates directly from IPGeolocation.io and has not been altered, corrupted, or tampered with during transfer or storage.

Each database update includes a corresponding signature file, generated using our private signing key. Customers can validate the database using the provided public verification key. To verify a database file, you need:

1.  Database file (the downloaded archive)
2.  Signature file (the matching signature for that archive)
3.  Public key (public-key.pem)

These files are available via official IPGeolocation.io download endpoints and are also shared in database update notifications.

> [!NOTE]
> The public key may be provided as PEM-encoded text. Save it to a file named public-key.pem
>
> Ensure OpenSSL is installed on your system. If not, install it using the following commands
>
> On Linux, if openssl is not installed
>
> ```shell
> sudo apt install openssl
> ```
>
> Verify OpenSSL installation:
>
> ```shell
> openssl version
> ```
>
> To verify the database file, run the following command, replacing the placeholders with your actual file paths:
>
> ```shell
> openssl dgst -sha256 -verify <path-to-public-key.pem> -signature <path-to-signature-file.sig> <path-to-database-file.zip>
> ```
>
> Example output:
>
> ```shell
> Verified OK
> ```
>
> if verification `FAILED` do not use the file, re-download the database and signature from official IPGeolocation endpoints. If the issue persists, please [contact our support team](https://ipgeolocation.io/contact.html).

* * *

### 2. Using the Checksum File (Legacy)

Each database archive includes a checksum.txt file containing the SHA-256 checksums for the files packaged in the archive. You can use this file to validate that the extracted contents are complete and unchanged.

> [!TIP]
> Always verify downloaded files with the provided checksum before importing.
>
> On Linux, if sha256sum is not installed, first run:
>
> ```shell
> sudo apt-get install coreutils
> ```
>
> Then check the archive files against the checksum file with:
>
> ```shell
> sha256sum -c checksum.txt
> ```
>
> Example output:
>
> *your output may differ depending on the specific database archive you downloaded.
>
> If a file's checksum does not match, `FAILED` will be shown instead of `OK` . If verification fails, first confirm that the download completed correctly; if the issue persists, please [contact our support team](https://ipgeolocation.io/contact.html).

> [!IMPORTANT]
> Signature verification confirms both authenticity and integrity. Checksum verification confirms integrity only (it detects corruption/modification, but does not independently prove who produced the file).

* * *

## Data Format & Constraints

*   All fields defined in the schema are always present in the IP WHOIS MMDB response.
*   Fields may contain empty strings (""), but never null, so null checks are not required.
*   Place names such as countries, states, districts, and cities are available in multiple translations.
*   All text values are encoded in UTF-8.
*   Field names and response structure remain stable across updates for backward compatibility.

* * *

## Database Updates & Delivery

When you subscribe to our IP WHOIS database, we'll send you static download links. These links never change, so you can use them both for your initial download and for all future updates. You will receive:

1.  **Database Archive URL :** downloads the latest release of your subscribed database (_CSV, MMDB or requested formats_).
2.  **Signature File URL :** downloads the matching signature file for the latest release (_used for authenticity verification_).
3.  **Public Key URL :** downloads the public verification key (_used with the signature file_).
4.  **Status Endpoint URL :** returns the database's most recent update timestamp.

Our databases are updated continuously and shipped on a daily or weekly cycle depending on your plan, ensuring you always have access to the most current data. Each time your subscribed dataset is updated, you'll also receive an email notification so you don't miss a release.

For automated workflows, you can check our status endpoint to see the last update timestamp. When the date changes, simply re-fetch the archive using your static download URL to pull the latest version into your system.
