IP and AS whois
Examples:
Transparency
Your browser asks the internet registries directly, over RDAP, the successor of whois that answers in JSON over HTTPS. The server of r-no.fr is not involved: it never sees what you look up.
- Who sees your lookup
- Each lookup goes first to the RIPE NCC, the European registry (
rdap.db.ripe.net). If the address or AS belongs to another registry, the RIPE NCC redirects your browser to it: ARIN, APNIC, LACNIC, AFRINIC, or a national registry such as NIC.br or KRNIC. These registries receive what you look up and your IP address, and learn that the request comes from r-no.fr (theOriginheader, which browsers send and pages cannot remove). No cookie is sent. - Enforced by your browser
- This page's Content Security Policy only allows these registries' RDAP services, and this site itself for the “My address” button, which asks ip/my-ip. A redirection to any other destination is blocked by your browser, and the page says so. No form submission (
form-action 'none'). One more destination is allowed, as on every page of the site:https://stats.r-no.fr, the audience measurement (see below). You can read the policy at the top of the page source. - Audience measurement
- Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (
stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
SHA-256225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716 - https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
- Personal data shown
- Registry records are public, and some name people: contacts of a network, with their phone number or address. This page shows the organisations and contacts of the record, but leaves out the individual members of a team (the full answer, below the result, still holds them). Nothing is kept once you leave the page.
- What is never sent
- Private, local, documentation and other reserved addresses, and private or documentation AS numbers, are recognised in your browser and never sent: no registry allocates them.
- Guardrail
- This page makes at most 20 lookups per minute. The requests leave from your address, not from the server, but they carry the r-no.fr origin: the limit keeps r-no.fr welcome at the registries.
- What is stored
- No cookie, and nothing in the address of this page: a lookup cannot be found in the server's logs. What you type is not kept. Your language is given by the address itself (
/en/or/fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name), and the “My address” button's request in the same way. - Code that runs here
-
- app.js: checks what you typed, asks the registries, and reads their answer. Written for R-no Toolbox, not minified, no third-party library. 28.7 kB
SHA-2569172abf4285e1d300f73e37f2007738809ed28403476304ff96497693c838d0f - textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 9.1 kB
SHA-256f1630a4288923394a4ab6076db8d63772fcb12a7390c0755ef26cb60f0cd0928 - /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
SHA-25680f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
- app.js: checks what you typed, asks the registries, and reads their answer. Written for R-no Toolbox, not minified, no third-party library. 28.7 kB
- Tested
- Checking what you type and reading the registries' answers are covered by automated tests, run on every deployment, on answers recorded from each regional registry.
- Check it yourself
- Download the script and compare its fingerprint with the one above:
curl -s https://r-no.fr/ip/whois/app.js | shasum -a 256 - Limits
- Domain names have their own tool: domains/whois. A registry may limit the number of lookups per address, and asks you to follow its terms of use. What is shown is what the registry holds, which is sometimes out of date.