WHOIS Lookup
Look up the registration record for a domain or an IP block, RDAP first, with port 43 WHOIS as the fallback.
Structured RDAP from rdap.arin.net.
Allocation
- AS number
- AS14618
- Netname
- AMAZON-AES
- Holder
- Amazon.com, Inc.
- Country
- Not published
- Registry
- ARIN — American Registry for Internet Numbers
- Block
- Not published
- Registered
- 2005-11-04T14:16:14-05:00
- Last changed
- 2012-03-02T08:03:18-05:00
- Abuse contact
- trustandsafety@support.aws.com
- Status
- active
- Registry server
- rdap.arin.net
Raw RDAP JSON
{
"endAutnum": 14618,
"entities": [
{
"entities": [
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2025-11-05T17:39:37-05:00"
},
{
"eventAction": "registration",
"eventDate": "2021-07-22T10:42:42-04:00"
}
],
"handle": "ARMP-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/ARMP-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/ARMP-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"roles": [
"routing"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "13200 Woodland Park Dr\nHerndon\nHerndon\nVA\n20171\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"AWS RPKI Management POC"
],
[
"org",
{},
"text",
"Amazon Web Services"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"aws-rpki-routing-poc@amazon.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-206-555-0000"
]
]
]
},
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2025-11-13T21:35:59-05:00"
},
{
"eventAction": "registration",
"eventDate": "2019-07-24T13:17:11-04:00"
}
],
"handle": "IPROU3-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/IPROU3-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/IPROU3-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"remarks": [
{
"description": [
"Report abuse incidents to our Abuse POC AEA8-ARIN. ",
"",
"Thank you for your cooperation."
],
"title": "Registration Comments"
}
],
"roles": [
"routing"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "1918 8th Ave\nSeattle\nWA\n98109\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"IP Routing"
],
[
"org",
{},
"text",
"Amazon"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"aws-routing-poc@amazon.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-206-555-0000"
]
]
]
},
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2025-08-28T17:03:29-04:00"
},
{
"eventAction": "registration",
"eventDate": "2008-03-24T14:12:07-04:00"
}
],
"handle": "AEA8-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/AEA8-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/AEA8-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"remarks": [
{
"description": [
" Abuse of Amazon Web Services - The activity you have detected originates from a dynamic hosting environment.",
" For fastest response, please submit abuse reports via the AWS webform: https://repost.aws/knowledge-center/report-aws-abuse",
" If your company system is configured to automatically send abuse reports, please send them to abuse@amazonaws.com including:",
" * src IP",
" * dest IP (your IP)",
" * dest port",
" * Accurate date/timestamp and timezone of activity",
" * Intensity/frequency (short log extracts)",
" * Your contact details (phone and email)"
],
"title": "Registration Comments"
}
],
"roles": [
"abuse"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "Amazon Web Services Elastic Compute Cloud, EC2\n410 Terry Avenue North\nSeattle\nWA\n98109-5210\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"Amazon EC2 Abuse"
],
[
"org",
{},
"text",
"Amazon Web Services, LLC"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"trustandsafety@support.aws.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-206-555-0000"
]
]
]
},
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2025-08-28T17:03:21-04:00"
},
{
"eventAction": "registration",
"eventDate": "2010-03-04T18:38:30-05:00"
}
],
"handle": "AANO1-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/AANO1-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/AANO1-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"roles": [
"noc"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "410 Terry Ave N\nSeattle\nWA\n98109\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"Amazon AWS Network Operations"
],
[
"org",
{},
"text",
"Amazon Web Services, LLC"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"amzn-noc-contact@amazon.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-206-555-0000"
]
]
]
},
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2025-08-28T17:03:33-04:00"
},
{
"eventAction": "registration",
"eventDate": "2005-09-19T06:00:05-04:00"
}
],
"handle": "ANO24-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/ANO24-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/ANO24-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"roles": [
"technical"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "PO BOX 81226\nSeattle\nWA\n98108-1226\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"Amazon EC2 Network Operations"
],
[
"org",
{},
"text",
"Amazon Webservices EC2"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"amzn-noc-contact@amazon.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-206-555-0000"
]
]
]
},
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2026-04-17T14:05:07-04:00"
},
{
"eventAction": "registration",
"eventDate": "2026-04-17T14:05:07-04:00"
}
],
"handle": "DNS1131-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/DNS1131-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/DNS1131-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"roles": [
"dns"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "13200 Woodland Park Rd\nHerndon\nVA\n20171\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"DNS"
],
[
"org",
{},
"text",
"Amazon Web Services"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"ipmanagement+dns@amazon.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-202-555-0000"
]
]
]
},
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2026-03-25T15:54:01-04:00"
},
{
"eventAction": "registration",
"eventDate": "2013-11-12T22:06:06-05:00"
}
],
"handle": "IPMAN40-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/IPMAN40-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/IPMAN40-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"remarks": [
{
"description": [
"Report abuse incidents to our Abuse POC AEA8-ARIN. ",
"",
"Thank you for your cooperation."
],
"title": "Registration Comments"
}
],
"roles": [
"administrative"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "1918 8th Ave\nSeattle\nWA\n98109\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"IP Management"
],
[
"org",
{},
"text",
"Amazon"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"ipmanagement@amazon.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-703-464-1336"
]
]
]
}
],
"events": [
{
"eventAction": "last changed",
"eventDate": "2026-04-17T14:53:11-04:00"
},
{
"eventAction": "registration",
"eventDate": "2005-09-29T15:32:10-04:00"
}
],
"handle": "AMAZO-4",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/AMAZO-4",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/org/AMAZO-4",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"remarks": [
{
"description": [
"For details of this service please see",
"http://ec2.amazonaws.com"
],
"title": "Registration Comments"
}
],
"roles": [
"registrant"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"fn",
{},
"text",
"Amazon.com, Inc."
],
[
"adr",
{
"label": "Amazon Web Services, Inc.\r\nP.O. Box 81226\nSeattle\nWA\n98108-1226\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"kind",
{},
"text",
"org"
]
]
]
},
{
"events": [
{
"eventAction": "last changed",
"eventDate": "2025-08-28T17:03:33-04:00"
},
{
"eventAction": "registration",
"eventDate": "2005-09-19T06:00:05-04:00"
}
],
"handle": "ANO24-ARIN",
"links": [
{
"href": "https://rdap.arin.net/registry/entity/ANO24-ARIN",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/poc/ANO24-ARIN",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"objectClassName": "entity",
"port43": "whois.arin.net",
"roles": [
"technical"
],
"status": [
"validated"
],
"vcardArray": [
"vcard",
[
[
"version",
{},
"text",
"4.0"
],
[
"adr",
{
"label": "PO BOX 81226\nSeattle\nWA\n98108-1226\nUnited States"
},
"text",
[
"",
"",
"",
"",
"",
"",
""
]
],
[
"fn",
{},
"text",
"Amazon EC2 Network Operations"
],
[
"org",
{},
"text",
"Amazon Webservices EC2"
],
[
"kind",
{},
"text",
"group"
],
[
"email",
{},
"text",
"amzn-noc-contact@amazon.com"
],
[
"tel",
{
"type": [
"work",
"voice"
]
},
"text",
"+1-206-555-0000"
]
]
]
}
],
"events": [
{
"eventAction": "last changed",
"eventDate": "2012-03-02T08:03:18-05:00"
},
{
"eventAction": "registration",
"eventDate": "2005-11-04T14:16:14-05:00"
}
],
"handle": "AS14618",
"links": [
{
"href": "https://rdap.arin.net/registry/autnum/14618",
"rel": "self",
"type": "application/rdap+json",
"value": "https://rdap.arin.net/registry/autnum/14618"
},
{
"href": "https://whois.arin.net/rest/asn/AS14618",
"rel": "alternate",
"type": "application/xml",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"name": "AMAZON-AES",
"notices": [
{
"description": [
"By using the ARIN RDAP/Whois service, you are agreeing to the RDAP/Whois Terms of Use"
],
"links": [
{
"href": "https://www.arin.net/resources/registry/whois/tou/",
"rel": "terms-of-service",
"type": "text/html",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"title": "Terms of Service"
},
{
"description": [
"If you see inaccuracies in the results, please visit: "
],
"links": [
{
"href": "https://www.arin.net/resources/registry/whois/inaccuracy_reporting/",
"rel": "inaccuracy-report",
"type": "text/html",
"value": "https://rdap.arin.net/registry/autnum/14618"
}
],
"title": "Whois Inaccuracy Reporting"
},
{
"description": [
"Copyright 1997-2026, American Registry for Internet Numbers, Ltd."
],
"title": "Copyright Notice"
}
],
"objectClassName": "autnum",
"port43": "whois.arin.net",
"rdapConformance": [
"nro_rdap_profile_0",
"rdap_level_0",
"nro_rdap_profile_asn_flat_0"
],
"startAutnum": 14618,
"status": [
"active"
]
}Cached for six hours. The same record as JSON: /api/v1/rdap. Add &raw=1 for the unmodified registry document.
RDAP first, WHOIS as a fallback
RDAP gives us typed fields, so the normalised view on this page is a mapping rather than a guess. Classic WHOIS output has no schema at all; each registry invented its own labels, and parsing it reliably is a losing game. When a registry publishes no RDAP endpoint, usually an older country-code registry, we fall back to a port 43 query and show the raw text with only light normalisation. The result labels which path was used.
Reading the raw output
The raw response stays collapsed under the normalised view. Open it when a field looks wrong, when the registry publishes something we did not map, or when you need the exact text for a dispute or a transfer request. Registry text is authoritative; our normalisation is a convenience.
Caching
Results cache for six hours. WHOIS and RDAP data changes on the scale of days, registries rate-limit aggressively, and hammering them for a value that did not move helps nobody. If you need a fresh read after a change you just made, wait out the cache rather than retrying in a loop.
About this tool
Enter a domain or an address. We query RDAP first, the structured JSON successor to WHOIS, and fall back to port 43 WHOIS where a registry runs none. A domain returns the registrar, creation and expiry dates, nameservers, and EPP status codes, and an address returns the RIR, netname, organisation, country, and abuse contact. Personal details are usually redacted under privacy law, and results cache for six hours.
How to read the result
- Registrar
- The accredited company through which the domain was registered, which is where it was bought rather than who owns it. A transfer changes this field while the registrant stays the same.
- Creation, updated, and expiry dates
- Registry timestamps in UTC for when the domain was created, last changed, and paid through. The expiry date is the paid-through date, not the deletion date, and after it a domain usually passes through a renewal grace period, then redemption, then pending-delete, roughly 75 days in total.
- Nameservers
- The nameservers recorded at the registry as the delegation for this domain. They can differ from the NS records the zone itself serves, when a zone was changed without updating the delegation, which is a lame delegation.
- EPP status codes
- Registry and registrar locks that say what can be done with the domain right now. clientTransferProhibited is normal and prevents unauthorised transfers, serverHold means the domain is not published in the zone at all, and pendingDelete and redemptionPeriod mean an expired domain is moving toward deletion.
- Registrant details or a redaction notice
- For most generic and European domains the registrant name, address, and email are withheld under GDPR and ICANN Temporary Specification policy, leaving a registrar-operated forwarding address. Some country registries publish more, and business registrations often do.
- For IP addresses, RIR, netname, org, and abuse contact
- The Regional Internet Registry that allocated the block, the registered netname, the holding organisation, and the abuse mailbox to complain to. For a hosting provider the organisation is the provider rather than their customer, and that mailbox is where a complaint about the customer goes.
Questions people ask
- Why is the WHOIS record for a domain redacted?
- The GDPR took effect in 2018 and ICANN issued a Temporary Specification requiring registries and registrars to withhold personal data from public output. Most contact fields for private registrants are now replaced with a redaction notice and a forwarding address. Legitimate access requests go through the registrar or the RDAP tiered-access process.
- What is the difference between WHOIS and RDAP?
- WHOIS is a plain-text protocol from 1982 with no consistent format, no authentication, and no internationalisation. RDAP returns structured JSON over HTTPS, supports differentiated access, and is standardised in RFC 7480 through 7484. ICANN has required RDAP for gTLDs since 2019, and it is the source we prefer.
- Can I find who owns an IP address?
- You can find the organisation the block is registered to, which for a datacenter address is the hosting provider rather than the customer running the machine. Smaller allocations sometimes name the end customer in the netname. There is no public record linking a residential address to a person.
- The domain looks unregistered but I cannot buy it. Why?
- Check the status codes. redemptionPeriod and pendingDelete mean a previous registration expired and is still working through the deletion sequence, which takes about 75 days total. Some registries also reserve names or hold them at premium pricing without showing a registration.
- Is a WHOIS lookup visible to the domain owner?
- Not through the query itself. RDAP and WHOIS queries go to the registry or registrar, not to the domain holder. Registries log queries and rate-limit them, so heavy automated querying gets throttled or blocked.
Related
Last reviewed 2026-09-05.