FlowRunner
PricingContact
Theme
Start Free

IP2WHOIS

Analytics & Data

Look up complete WHOIS records for any registered domain across 1221 TLDs through IP2WHOIS. Agents check domain age and registrant details before trusting an inbound signup.

2 actions API key available
Platform Documentation ↗ Capability data verified 2026-07-31
An inbound trial request arrives from a company domain nobody has seen before
Look Up Domain WHOIS returns creation date, domain age in days, registrar and the contact blocks
Get Hosted Domains lists the other domains served from the same address
Agent confirms the nameservers match a recognised host and the record is not a "No data found" error
Age, contact redaction and hosting neighbourhood are scored against the trust threshold
Established domains are approved and the registrant organisation is written onto the CRM account
Sales operations rules on the young and redacted domains before any rejection goes out

What This Integration Enables

IP2WHOIS is the odd one out in this group, and deliberately so. Everything else here starts from an IP address. This starts from a domain name, and it answers a question no geolocation lookup can: how old is this thing, who registered it, and what else lives at the same address. It covers 1,221 TLDs and 634 ccTLDs, and returns the domain ID, EPP status, creation, update and expiration dates, the domain age in days already calculated, the responsible WHOIS server, the registrar with its IANA ID and URL, the nameservers, and the registrant, admin, tech and billing contact blocks.

Two honest caveats belong in any workflow built on it. Contact fields are commonly blank or redacted where the domain uses privacy protection or falls under GDPR, so absence of a registrant name is normal and proves very little on its own. And unregistered or unsupported domains return a "No data found" error rather than an empty record, which your flow should handle as a distinct branch. The reverse lookup, Get Hosted Domains, adds the other half of the picture by returning every domain served from an IPv4 or IPv6 address, paginated with a per-page cap that follows your plan. That is how an agent discovers it is looking at shared hosting rather than a dedicated attacker.

FlowRunner agents use all of it for one decision shape: how much trust to extend to something that just showed up. A domain registered six days ago behind privacy protection is not proof of fraud. It is also not nothing. The connector supplies the facts; the flow decides what threshold matters, and the borderline cases go to a person.

Without FlowRunner

Domain treated as a string The signup domain is stored as text and never asked a single question
Company name typed by the prospect Whatever was entered in the company field is what the CRM believes
Renewals and expiries invisible A partner domain lapses and the first anyone hears is a broken integration

With FlowRunner

Domain treated as a record Creation date, age in days, registrar, status and nameservers arrive with the signup
Organisation read from the registry The registrant organisation and country come from the WHOIS record where the domain owner published them
Expiry tracked on a schedule Expiration dates are checked ahead of time and surfaced before anything breaks

Use Case Scenarios

Age and registrant checked before a trial is provisioned

An enterprise trial request arrives. Before any seat is created, the agent calls Look Up Domain WHOIS on the email domain and reads the creation date and domain age in days. Domains older than a year with a named registrant organisation are approved automatically, and the organisation and country are written onto the account in Pipedrive so the rep does not have to research the company. Domains under thirty days old, or with every contact block redacted, are held. The agent is not deciding these are fraudulent. It is deciding they are not obviously fine, which is a different and much more defensible judgment.

Expiry monitoring for partner and brand domains

A scheduled flow walks the list of partner, vendor and defensive brand domains once a week and calls Look Up Domain WHOIS on each. It reads the expiration date and the EPP status codes, and raises anything expiring inside ninety days or carrying an unexpected status such as a pending delete or a transfer prohibition that was not there last week. The findings go to the operations channel in Slack with the registrar name and URL attached, so whoever picks it up already knows where to log in.

Pivoting from an address to its neighbourhood during an investigation

A security investigation starts with one hostile address. The agent calls Get Hosted Domains and pages through the results using the reported total page count, collecting every domain served from that address. It then runs Look Up Domain WHOIS across the returned domains and groups them by registrar and creation date. A cluster of domains registered within days of each other at the same registrar tells a very different story than three hundred unrelated small sites on a shared host, and the grouped output makes which one you are looking at obvious at a glance.

Human-in-Loop Highlight

The gate sits on the rejection, not the approval. When a trial request comes from a domain created six days ago with every contact block redacted, the agent has a pattern that fits a throwaway fraud domain exactly. It also fits a real company that registered its domain last week and took privacy protection, which is now the default at most registrars. Rejecting the second one is silent and permanent: the prospect gets a wall, does not appeal, and nobody ever learns the miss happened. So the agent will not reject. It assembles the evidence and asks in the sales operations channel: "Trial request from northfield.example. Domain created 6 days ago, registrar Namecheap, registrant fully redacted, nameservers Cloudflare, 412 other domains on the same address. Approve, approve with a manual verification step, or decline?" The reversible half, approving domains that are plainly established, runs without anyone. The half with no undo goes to a person.

Agent processes routinely
Detects exception requiring judgment
Clear match Continues automatically
Ambiguous Routes to human via preferred channel
Human decides
Agent resumes with decision

Agent Capabilities

2 actions

Domain WHOIS

1
  • Look Up Domain WHOIS Retrieves the full WHOIS record for a registered domain across 1,221 TLDs and 634 ccTLDs. Returns the domain ID, EPP status, creation, update and expiration dates, domain age in days, the responsible WHOIS server, the registrar with IANA ID, name and URL, the nameservers, and the registrant, admin, tech and billing contact blocks with name, organization, address, phone, fax and email. Contact fields are commonly blank or redacted under privacy protection or GDPR, and unregistered or unsupported domains return a "No data found" error rather than an empty record.

Hosted Domains

1
  • Get Hosted Domains Performs a reverse IP lookup and returns the domain names hosted on a given IPv4 or IPv6 address. Used for shared-hosting discovery, attack-surface mapping and investigating what else is served from the same address. Results are paginated, and the response reports the total hosted domains, the current page, the domains per page and the total page count. Domains per page is capped by plan, so loop the Page parameter up to the reported total to collect the full list.

Frequently Asked Questions

What can FlowRunner do with IP2WHOIS?

FlowRunner agents can run Look Up Domain WHOIS and Get Hosted Domains in IP2WHOIS.

Does connecting IP2WHOIS to FlowRunner require OAuth?

No. IP2WHOIS connects to FlowRunner with an API key, no OAuth flow required.

Can IP2WHOIS trigger a FlowRunner workflow automatically?

IP2WHOIS doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.

Start building with IP2WHOIS

$100 in credits. No card required. Connect in minutes.