How does the IP address WHOIS tool work?
Most Linux servers can look up the WHOIS information for an IP address with the whois program. We pair this program with PHP, the scripting language that runs our website, to show you the WHOIS information for an IP address.
We ask ARIN, the registry for North America. For addresses it doesn't manage, ARIN's record refers to the right registry (RIPE for Europe, APNIC for Asia-Pacific, LACNIC for Latin America, AFRINIC for Africa), or to the network owner's own WHOIS server, and whois follows that referral. If a referred server doesn't answer within 10 seconds, we show ARIN's part of the record.
To run a WHOIS from a Linux shell, you can do something like this:
whois -h whois.arin.net 216.73.217.153
You can also run the WHOIS from PHP. If done carelessly, this can expose your web server to unfriendly people, so check the address first, pass it to the program as its own argument (never as part of a shell command), and escape the output before showing it, since WHOIS records are written by other people:
/* This code is public domain */
/* Source: https://ipaddr.es */
$ip_address = '216.73.217.153';
// Make sure the IP address is valid
if (filter_var($ip_address, FILTER_VALIDATE_IP)) {
// Run whois without a shell
$process = proc_open(['whois', '-h', 'whois.arin.net', $ip_address], [1 => ['pipe', 'w']], $pipes);
$output = stream_get_contents($pipes[1]);
proc_close($process);
// Display the output, escaped
echo '<pre>' . htmlspecialchars($output) . '</pre>';
}
Last updated: September 29, 2026 (12:40 AM GMT)