The reassignments registries never see.
Network operators publish the blocks they hand to their own customers on RWHOIS servers of their own. Every reassignment those servers return is here, with the customer, its contacts and address, and the block it was carved from.
Schema at a glance.
See documentation →The database's schema and metadata are documented carefully. It is published as CSVGZ and MMDB.
| start_ip | end_ip | id | name | city | country | abuse | host |
|---|---|---|---|---|---|---|---|
| 23.227.192.192 | 23.227.192.223 | NET-126051.23.227.192.192/27 | HIVELOCITY, LLC | Chicago | US | abuse@hivelocity.net | rwhois.hivelocity.net |
| 38.32.15.128 | 38.32.15.135 | NET4-26200F801D | Allata LLC | DALLAS | US | rwhois.cogentco.com | |
| 38.87.81.32 | 38.87.81.47 | NET4-265751201C | Soletanche Freyssinet | ASHBURN | US | rwhois.cogentco.com | |
| 38.88.216.116 | 38.88.216.117 | NET4-2658D8741F | Manatt, Phelps, & Phillips, LLP. | COSTA MESA | US | rwhois.cogentco.com | |
| 216.231.141.0 | 216.231.141.127 | NET-437.216.231.141.0/25 | Nexeon Technologies, Inc | Stafford | US | abuse@sbaedge.com | my.603.sbaedge.net |
Downloading it from code.
Database API reference →One call gets you the current IP RWHOIS build. Every official client wraps it three ways: straight to disk, a time-limited link you hand to your own runner, or bytes in memory. A file written to disk lands only once the whole transfer has arrived, and checksums() returns the published digests to verify it against.
download()downloadUrl()downloadBytes()metadata()checksums()import osfrom internetdata import InternetDataclient = InternetData(os.environ["INTERNETDATA_API_KEY"])# what is in today's build, without moving the filemeta = client.database.metadata("ip_rwhois_v1")client.database.download("ip_rwhois_v1", "mmdb", "./ip_rwhois_v1.mmdb")sums = client.database.checksums("ip_rwhois_v1", "mmdb")print(meta.updated, meta.entries, sums["sha256"])
Getting your hands on it.
The file is the product. Teams join IP RWHOIS against traffic they already log, inside their own infrastructure, and never send an address anywhere to get an answer.
Customer attribution
See which of an operator's customers holds a block, where the registries name only the operator.
An official client for every major language.
All SDKs on GitHub →Twelve official clients for the languages you ship in, each wrapping the database endpoints — list what you are licensed for, poll a build, follow the download redirect, verify what landed. Install commands are in the docs.
No loose ends.
How often does this database rebuild?
Daily, except IP RDNS and IP RWHOIS, which change weekly. The metadata call answers when the current build landed and how many rows it holds, before you fetch it.
Where does the data come from?
The five regional internet registries and the national ones, network operators' own RWHOIS servers, the global routing table, and our own scans of the address space. The documentation names the sources of each database.
Why is a contact field empty?
Because the registry does not publish it. Bulk registry data leaves out what privacy rules withhold, most often a personal contact's email, and a record carries only what its holder filed.
Which formats does a build ship in?
Gzipped CSV for all of them, and MMDB for IP ASN, IP Whois, IP RWHOIS and IP Abuse Contact. The schema section above names this one's.
Test the real build first.
An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.