Every network record the registries publish.
The address blocks registered with the five regional registries and the national ones, one row per record at every level of nesting, with the holder, status, dates, contacts and the block each sits inside, and the AS announcing it.
Schema at a glance.
See documentation →The database's schema and metadata are documented carefully. It is published as CSVGZ and MMDB.
| start_ip | end_ip | id | name | country | status | source | abuse_email |
|---|---|---|---|---|---|---|---|
| 1.1.1.0 | 1.1.1.255 | APNIC-LABS | APNIC Research and Development | AU | ASSIGNED PORTABLE | apnic | helpdesk@apnic.net |
| 8.8.8.0 | 8.8.8.255 | GOGL | Google LLC | allocation | arin | network-abuse@google.com | |
| 88.198.0.0 | 88.198.15.255 | HETZNER-RZ-NBG-NET | Hetzner Online AG | DE | ASSIGNED PA | ripe | |
| 196.216.2.0 | 196.216.3.255 | AFRINIC | African Network Information Center - (AfriNIC) Ltd | ZA | ASSIGNED PI | afrinic | abuse@afrinic.net |
| 2a01:4f8:: | 2a01:4ff:ffff:ffff:ffff:ffff:ffff:ffff | DE-HETZNER-20071010 | Hetzner Online GmbH | DE | ALLOCATED-BY-RIR | ripe | abuse@hetzner.com |
Downloading it from code.
Database API reference →One call gets you the current IP Whois build. Every official client wraps it three ways: straight to disk, a time-limited link you hand to your own runner, or bytes in memory. A file written to disk lands only once the whole transfer has arrived, and checksums() returns the published digests to verify it against.
download()downloadUrl()downloadBytes()metadata()checksums()import osfrom internetdata import InternetDataclient = InternetData(os.environ["INTERNETDATA_API_KEY"])# what is in today's build, without moving the filemeta = client.database.metadata("ip_whois_v1")client.database.download("ip_whois_v1", "mmdb", "./ip_whois_v1.mmdb")sums = client.database.checksums("ip_whois_v1", "mmdb")print(meta.updated, meta.entries, sums["sha256"])
Getting your hands on it.
The file is the product. Teams join IP Whois against traffic they already log, inside their own infrastructure, and never send an address anywhere to get an answer.
Ownership
Name the organization a block is registered to, and the larger block it was carved from.
Contacts
Reach the abuse, admin or technical contact on record without a whois query per address.
An official client for every major language.
All SDKs on GitHub →Twelve official clients for the languages you ship in, each wrapping the database endpoints — list what you are licensed for, poll a build, follow the download redirect, verify what landed. Install commands are in the docs.
No loose ends.
How often does this database rebuild?
Daily, except IP RDNS and IP RWHOIS, which change weekly. The metadata call answers when the current build landed and how many rows it holds, before you fetch it.
Where does the data come from?
The five regional internet registries and the national ones, network operators' own RWHOIS servers, the global routing table, and our own scans of the address space. The documentation names the sources of each database.
Why is a contact field empty?
Because the registry does not publish it. Bulk registry data leaves out what privacy rules withhold, most often a personal contact's email, and a record carries only what its holder filed.
Which formats does a build ship in?
Gzipped CSV for all of them, and MMDB for IP ASN, IP Whois, IP RWHOIS and IP Abuse Contact. The schema section above names this one's.
Test the real build first.
An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.