Trace abuse contacts with WHOIS to report attacking IPs

Quick answer

When an IP attacks your server — brute-forcing logins, scraping aggressively, or probing for holes — you can report it to whoever is responsible for that network. The path runs through WHOIS and the regional registry records. Here’s how to find the right contact.

Who actually owns an IP address?

Every public IP belongs to a block allocated by a Regional Internet Registry (RIR) — ARIN (North America), RIPE (Europe), APNIC (Asia-Pacific), and others — to an organisation, usually an ISP or hosting provider. That organisation, not the individual attacker, is who you report to. They can act on their own customer; you can’t.

Step 1: Identify the network behind the IP

Start by finding the network owner. Our Bulk IP Audit tool and Reverse DNS tool show the ASN organisation — the company that runs the network — which tells you whether you’re dealing with a hosting provider, an ISP, or a cloud platform. That’s your starting point for the abuse contact.

Step 2: Look up the WHOIS / RIR record

Query the IP in the relevant registry’s WHOIS (for example, RIPE or ARIN’s lookup). The record lists the allocated range, the owning organisation, and crucially an abuse contact — often an abuse@ email or an abuse-c handle. This is the address specifically designated for reporting misuse from that network.

Step 3: Report effectively

Email the abuse contact with specifics: the attacking IP, timestamps in UTC, the type of activity, and a few log lines as evidence. Concise, factual reports get acted on; vague ones get ignored. Most reputable hosts and ISPs will investigate and can suspend an abusive customer or compromised machine.

When will reporting not help?

Some networks — so-called bulletproof hosts — ignore abuse reports by design. If reports go nowhere, the practical defence is to block the offending IP or its whole ASN at your firewall. For large-scale attacks, grouping the source IPs by ASN (see our guide on grouping botnet attacks by ASN) lets you block coordinated infrastructure in one move rather than chasing individual addresses.

Related: Bulk IP Audit tool · Reverse DNS tool

0 IPs logged or stored
2 stacks shown (v4 & v6)
8+ diagnostic tools
lookups, always free