IP and ASN registration lookup

Find the regional registry record for a public IP address or autonomous system number. Compare the published registration with separate routing context when available, without treating either as a person's identity or a location.

Start with the address in the evidence

Use one public IPv4 or IPv6 address from the connection or log you are investigating, or an ASN with or without the AS prefix. Hostnames, CIDR ranges, private addresses, and reserved values are outside this lookup's scope.

A registry's not-registered response differs from a blocked request, rate limit, timeout, or unavailable service. Retry a temporary failure before drawing a conclusion about the address. A missing routing result does not prove that an address is unrouted, and it does not invalidate a registration record that was retrieved successfully.

Before acting, open the linked registry record and check its scope. Use the raw RDAP response when you need fields beyond the summary, but handle downloaded contact information with care.

What the registered record means

An IP record describes a registered address range; an ASN record describes an autonomous system number or range. The holder, handle, status, and event dates belong to that registry record. They do not necessarily describe the device using an address today. A missing field means the source did not publish it, not that its value is zero or that no organization exists. ARIN's RDAP guide explains the registration service.

The country field is registration data, not device geolocation. This lookup does not identify a subscriber or person, test reachability, list open ports, or assess reputation.

How the lookup chooses a registry

IANA's bootstrap data directs the query to a regional Internet registry's RDAP service. RDAP provides structured registration records for IP networks and ASNs. An unavailable service stays unknown; the tool does not fill the gap with a guessed holder. See the RDAP bootstrap standard and query standard.

Your query is sent to the site's lookup service and upstream registration services. Optional IP routing context also involves a routing provider. This is not a browser-local lookup or a promise of anonymous processing.

Registration and routing answer different questions

Registration records describe allocated resources. The separate Team Cymru routing lookup can describe an observed BGP origin and announced prefix. A route origin and registered holder can differ without either record being wrong. Keep that distinction when tracing an incident: neither record alone establishes who generated the traffic.

Use an abuse contact with evidence

A published abuse contact gives you a reporting destination, not proof that the contact or registered holder caused an incident.

  1. Record the address, timestamp and time zone, observed protocol or URL, and relevant logs.
  2. Check that the registry publishes the destination for abuse reports and follow any reporting instructions it provides.
  3. Send the relevant evidence, removing unrelated personal data and secrets.

The lookup cannot promise a response or identify the subscriber behind the event.