ARIN Lookup
ARIN Lookup helps you lookup ip block ownership and registration, for routing analysis, ownership checks, and faster network troubleshooting.
Advertisement · Anuncio
Advertisement · Anuncio
Technical Analysis & Guide
What It Does
ARIN Lookup takes an IPv4 or IPv6 address and returns the registration record of the network block that contains it: the address range and CIDR, the organization holding it, the allocation type, registration and last-update dates, and the abuse and technical points of contact. ARIN is authoritative only for its own service region (the United States, Canada and parts of the Caribbean and North Atlantic), so addresses managed by RIPE NCC, APNIC, LACNIC or AFRINIC come back as a referral to that registry instead of ARIN data.

Why It Matters
- →Abuse reporting: The OrgAbuse contact on the record is where ARIN expects complaints to go, which is faster than guessing at the upstream carrier or emailing a generic support inbox.
- →Registrant versus announcer: The company that registered a block is not always the network that routes it, and comparing both exposes leased space and forgotten reassignments.
- →IPv4 transfer due diligence: Before buying or leasing addresses, confirm the current registrant, the registration date and whether the block is covered by a registration services agreement.
- →Vendor allowlists: When a SaaS provider asks you to permit a range, the record shows whether the block is theirs or belongs to the cloud platform they rent from.
- →Geolocation complaints: Commercial geolocation databases use registered addresses as one input, so stale organization data often shows up as users being placed in the wrong country.
How to Read Results
- NetRange and CIDR: First and last address of the registered block; a range that does not fall on a bit boundary is listed as several CIDR prefixes.
- NetType: Direct Allocation (held by an ISP and sub-delegable), Direct Assignment (end-user organization), Reallocated or Reassigned (handed down by an upstream provider, with the provider block shown as Parent).
- OrgName and OrgId: The legal holder of the most specific record; on a reassignment this is the customer, while the Parent handle leads to the ISP.
- RegDate and Updated: An old registration date combined with a very recent update usually signals a transfer, a merger or a change of contacts.
- OrgAbuseEmail and OrgTechEmail: Points of contact; ARIN asks holders to validate them every year and flags the ones that were not confirmed.
- Referral to another RIR: The address is not ARIN space; repeat the query against the registry named in the referral (for most of Latin America that is LACNIC).
Technical Background
IANA hands large address blocks to five Regional Internet Registries, and each one registers sub-blocks for its own territory: ARIN for the United States, Canada and parts of the Caribbean and North Atlantic; RIPE NCC for Europe, the Middle East and Central Asia; APNIC for Asia-Pacific; LACNIC for Latin America and much of the Caribbean; and AFRINIC for Africa. ARIN ran out of free IPv4 on 24 September 2015. Since then new IPv4 space comes either from the ARIN waiting list or from transfers under section 8 of the Number Resource Policy Manual, which is why the registration date and the transfer history of a block now carry commercial weight.
For decades registration data was published through WHOIS (RFC 3912), a plain-text protocol on TCP port 43 with no defined schema. Each registry formats answers differently, nothing is authenticated, character sets are not standardized and referrals between registries are improvised. RDAP replaces it with HTTPS and JSON. RFC 9082 defines the query paths, such as /ip/8.8.8.8, /autnum/15169 or /entity/HANDLE, and RFC 9083 defines the response: an objectClassName, startAddress and endAddress, nested entities carrying jCard contacts with roles like abuse or technical, and events such as registration and last changed. RFC 9224 describes the IANA bootstrap files that tell a client which registry serves a given block. ARIN's RDAP service lives under https://rdap.arin.net/registry/.
ARIN models delegation as a tree. A Direct Allocation goes to a provider, which can reallocate part of it to a downstream ISP that may sub-delegate again, or reassign part of it to an end customer. Those records are submitted through SWIP or the Reg-RWS API. A Direct Assignment goes straight to an end-user organization. Querying one address returns the most specific registered network, so a /29 reassigned to a small office will hide the /16 above it; the Parent field, or a query on the parent handle, walks back up the chain. Blocks issued before ARIN was founded in December 1997 are legacy space and may have no registration services agreement at all; their holders can sign a Legacy RSA to get full services.
Points of contact are standalone objects with handles such as ABUSE1234-ARIN. ARIN runs an annual POC validation and marks contacts that were never confirmed, which is a strong hint that complaints sent there will go unanswered. ARIN itself does not investigate spam, scanning or attacks; it only maintains the registry.
Remember that registration is not routing. A block registered to one company can be originated in BGP by its provider, by a lessee, or by nobody. For a complete picture, pair this record with an origin-AS lookup and an RPKI ROA check for the same prefix.
Common Errors and How to Fix Them
- ProblemSending spam or attack complaints to the OrgTech address, or to ARIN itself.
- FixUse the OrgAbuse email of the most specific record (the reassigned customer if present, otherwise the parent ISP). ARIN does not act on abuse reports; it only maintains registration data.
- ProblemAssuming the record you see describes the whole network, when it is only a small reassignment.
- FixRead the Parent field and query that handle (for example whois -h whois.arin.net "n NET-...") to find the allocation holder and the provider that can actually act on the block.
- ProblemExpecting ARIN data for a 200.x, 177.x or 186.x address and getting a referral or nothing useful.
- FixThose blocks are LACNIC space. Query rdap.lacnic.net or follow the RDAP referral; the IANA bootstrap file maps every block to its registry.
- ProblemAn ISP keeps a stale SWIP reassignment after a customer leaves, so abuse mail for the new user reaches the old company.
- FixProviders should delete or update reassignments in ARIN Online or through Reg-RWS when service ends, and re-SWIP the block to the new customer when required.
- ProblemIgnoring ARIN's annual POC validation email.
- FixConfirm every POC once a year from ARIN Online; unvalidated contacts are flagged publicly and can block some registry transactions until they are fixed.
Frequently Asked Questions
What is the difference between WHOIS and RDAP?
WHOIS is a 1980s-era text protocol on port 43 where every registry formats replies its own way and nothing is authenticated. RDAP, defined in RFC 9082 and RFC 9083, serves the same registration data over HTTPS as structured JSON, supports standardized referrals between registries, and can apply access control. All five RIRs run RDAP, and it is the format automated tools should parse.
Why does ARIN show a different company than the provider I pay?
Most likely your provider holds the allocation and reassigned a portion to you, or it rents the block from another ISP. The most specific record shows whoever was last registered for that slice, and the Parent field shows the block above it. If you are the customer and your name is missing, the provider simply did not file a reassignment for you.
Can I still get IPv4 addresses from ARIN?
ARIN's free pool was exhausted in September 2015. Organizations can join the waiting list for small returned blocks, which can take a long time, or acquire space through a transfer from another holder, which requires ARIN approval under the transfer policy. IPv6, by contrast, is readily available, and most organizations can qualify for a /48 or larger with little justification.
Does an ARIN record tell me where an IP is physically located?
No. It shows the registered address of the organization that holds the block, which may be a headquarters thousands of kilometers from where the address is actually used. Cloud providers, VPN services and national ISPs routinely use one registration for addresses spread across many cities. Use latency measurements or the provider's own geofeed for location instead.
How do I look up an IP outside North America?
Query the registry that manages it: LACNIC for most of Latin America and the Caribbean, RIPE NCC for Europe and the Middle East, APNIC for Asia-Pacific and AFRINIC for Africa. Each runs its own RDAP and WHOIS servers. RDAP clients that read the IANA bootstrap file pick the right registry automatically, so you do not need to know it in advance.
Academic Documentation
Protocol context and primary references
REST API Documentation
v1.0GET /api/tools/arin
curl -X POST https://epcybertools.com/api/tools/arin \
-H "Content-Type: application/json" \
-d '{"ip":"8.8.8.8"}'
{
"success": true,
"results": [
{ "test": "Sample Check", "status": "pass", "message": "All clear" }
]
}
Usage Examples
# Network query against ARIN WHOIS (n = network, + = full detail)
whois -h whois.arin.net "n + 8.8.8.8"
# Same data as structured RDAP JSON
curl -s https://rdap.arin.net/registry/ip/8.8.8.8 | python3 -m json.tool | head -40