How to read and understand WHOIS results?

Ram4x4

Junior Member
Oct 1, 2017
2
0
1
I've recently become obsessed with filtering SPAM from my email. I receive, on average, 300-400 SPAM emails PER DAY. It's driving me nuts.

I've contacted my ISP (Windstream) as apparently they do diddly-squat to filter SPAM on their end and I was told it's on me to create filters (which I can do, sort of, via a web interface to my mailbox on their end). Their system is cumbersome and I have to create a new filter rule for every single thing I want to filter. I gave up on it.

What I've started doing is creating rules in my Outlook. Yeah, I still get the glorious luxury of downloading all that crap email, but at least it gets dumped to trash before it hits my inbox. Unfortunately, Microsoft doesn't make creating rules much easier. There's no option to filter, say a range of something, only individual items at a time, but at least the filter criteria can be contained within a single rule.

I've also downloaded a complete database of all issued IP's in the world and put them in an Excel spreadsheet and sorted by country of origin. That way, I can look at header info in SPAM emails and check the originating IP (at least on those too dumb to hide it). If it comes from a foreign IP, it's IP (and when possible entire domain or range of IPs) goes into my filter. Still, it's a never ending process as new SPAM is coming in all the time from new sources, but it's getting better.

So, anyway, this all leads me to a question. Sometimes when I look up an IP on a WHOIS site, it's a bit confusing as to where the IP really is coming from, or who owns it, and so forth. I was hoping someone could look at the following WHOIS entry and explain to me what it means.

This entry is for the the IP: 69.64.39.5
I ran it through the following WHOIS website: https://whoer.net/checkwhois.
Here are the results:

IP address: 69.64.39.5
Location
:
us.png
United States (US), North America
Region:
Missouri (MO)
City:
Saint Louis
ZIP:
63101


Hostname:
static-ip-69-64-39-5.inaddr.ip-pool.com → 69.64.39.5
IP range:
69.64.35.15 - 69.64.50.101
ISP:
HEG US
Organization:
HEG US


Blacklist:
No
TOR:
No


Time

Zone:
America/Chicago
Local:
Sun Oct 1 2017 13:41:16 GMT-0500 (CDT)


Whois:

NetRange 69.64.32.0 - 69.64.63.255
CIDR 69.64.32.0/19
NetName HEGUS-1
NetHandle NET-69-64-32-0-1
Parent NET69 (NET-69-0-0-0-0)
NetType Direct Allocation
OriginAS AS30083
Organization HEG US Inc. (SERVE-6)
RegDate 2003-07-30
Updated 2017-03-01
Ref https://whois.arin.net/rest/net/NET-69-64-32-0-1

OrgName HEG US Inc.
OrgId SERVE-6
Address 210 North Tucker Blvd.
Address Suite 910
City Saint Louis
StateProv MO
PostalCode 63101
Country US
RegDate 2003-04-15
Updated 2017-03-01
Ref https://whois.arin.net/rest/org/SERVE-6

OrgNOCHandle SWI19-ARIN
OrgNOCName Wintz, Sascha
OrgNOCPhone +1-314-300-2200
OrgNOCEmail sascha.wintz@heg.com
OrgNOCRef https://whois.arin.net/rest/poc/SWI19-ARIN

OrgAbuseHandle HUAD-ARIN
OrgAbuseName HEG US Abuse Department
OrgAbusePhone +1-314-266-3638
OrgAbuseEmail abuse@heg-us.com
OrgAbuseRef https://whois.arin.net/rest/poc/HUAD-ARIN

OrgTechHandle SWI19-ARIN
OrgTechName Wintz, Sascha
OrgTechPhone +1-314-300-2200
OrgTechEmail sascha.wintz@heg.com
OrgTechRef https://whois.arin.net/rest/poc/SWI19-ARIN

RTechHandle SWI19-ARIN
RTechName Wintz, Sascha
RTechPhone +1-314-300-2200
RTechEmail sascha.wintz@heg.com
RTechRef https://whois.arin.net/rest/poc/SWI19-ARIN

RNOCHandle SWI19-ARIN
RNOCName Wintz, Sascha
RNOCPhone +1-314-300-2200
RNOCEmail sascha.wintz@heg.com
RNOCRef https://whois.arin.net/rest/poc/SWI19-ARIN

RAbuseHandle HUAD-ARIN
RAbuseName HEG US Abuse Department
RAbusePhone +1-314-266-3638
RAbuseEmail abuse@heg-us.com
RAbuseRef https://whois.arin.net/rest/poc/HUAD-ARIN

NetRange 69.64.39.5 - 69.64.39.5
CIDR 69.64.39.5/32
NetName ARIN-69-64-39-5-32
NetHandle NET-69-64-39-5-1
Parent HEGUS-1 (NET-69-64-32-0-1)
NetType Reassigned
OriginAS AS30083
Organization Nxhost (NXHOS)
RegDate 2017-08-29
Updated 2017-08-29
Ref https://whois.arin.net/rest/net/NET-69-64-39-5-1

OrgName Nxhost
OrgId NXHOS
Address Tapejara 471
City Tapejara
StateProv
PostalCode 99950000
Country BR
RegDate 2017-01-12
Updated 2017-01-12
Ref https://whois.arin.net/rest/org/NXHOS

OrgTechHandle FWF-ARIN
OrgTechName Filho, Francisco Witschoreck
OrgTechPhone +55.54.33440135
OrgTechEmail vendas@nxhost.com.br
OrgTechRef https://whois.arin.net/rest/poc/FWF-ARIN

OrgAbuseHandle FWF-ARIN
OrgAbuseName Filho, Francisco Witschoreck
OrgAbusePhone +55.54.33440135
OrgAbuseEmail vendas@nxhost.com.br
OrgAbuseRef https://whois.arin.net/rest/poc/FWF-ARIN


I'm, most interested in all the "Whois" information. What does it all mean? How do I read that? I also notice at the bottom there appears to be a foreign country (BR), address, name, and phone number. What the heck? Why do the initial Whois data indicate "HEG US Inc", but further down it says "NXHOS" in some city named "Tapejara", in the country "BR"??
 

JackMDS

Elite Member
Super Moderator
Oct 25, 1999
29,531
416
126
In most cases today IPs that are issue by the commercial entity that is lic. to do so are Protected.

I.e., You would be told the IP was issued (as an example) by GoDaddy or enom etc., but you will not find info about who is actually is using the IP. At times you might get info about who is providing the server tp th email but Not the actual id of the user (unless you have a court order).

Gmail is a good way, or if you use something else and want to stay with it you can try this.

http://www.mailwasher.net/

The regular version is free.

The Pro version is Excellent but it is Not free.


:cool:
 

Ram4x4

Junior Member
Oct 1, 2017
2
0
1
I've tried SpamFighter, but it doesn't work very well. I'll check out mailwasher.

I'm not running a mail server. I am using Outlook to connect to my mailbox at my ISP. I've contacted my ISP (Windstream) to complain about all the SPAM and see why they aren't filtering much, if any like most others do. I was pointed to the online filters and told I had to create my own filters there. They are useless.

I can't, and don't want to move to gmail. I have too many things connected to this email address and it would be a royal PIA to try to make all those changes.

I don't expect I'll ever stop every spam email, but if I can reduce what gets to my inbox at this point, I'll be happy. So far, my method of adding criteria to my Outlook rules is working ok.

I was just curious what the Whois data above for that IP meant (why it shows two different apparent owners or users, one U.S. and one foreign). So far, in my method I am trying to avoid trashing any U.S. based IP addresses and only block emails from U.S. IPs by key words in the headers (like "250K life insurance", etc, etc). If however, a foreign entity is using a U.S. IP to send out spam, I'll trash that IP, no problem.

If I happen to miss legitimate emails because of it, so be it. I'm just fed up with this crap. If I could, I'd just get rid of email completely, but I can't.
 

mxnerd

Diamond Member
Jul 6, 2007
6,799
1,103
126
Forward everything arrived at your existing email box to newly created Gmail account, and setup Gmail account to forward back to your email box.

Gmail will filter out the spam emails before doing the forwarding.

You don't have to move your email account to Gmail.

Figure out whether WHOIS info is correct or not really does not help.

https://whois.icann.org/en/accuracy
 

Genx87

Lifer
Apr 8, 2002
41,091
513
126
Ouch, the mail host refuses to filter spam for you? That is terrible, time to find a new host imo.
 

XavierMace

Diamond Member
Apr 20, 2013
4,307
450
126
You're never going to effectively filter based off Whois data. Domain registrant has no bearing on where the servers are actually located.