Provide current and historical ownership information on domains / IPs. Identify all connections between domains, registrants, registrars, and DNS servers.
TL;DR
- You can now restrict API requests to a list of trusted IP addresses, so a leaked or shared key alone is no longer enough for unauthorized users to use your API key.
- Enterprise account administrators using Parent-Child API keys can see API usage broken down by individual team member or combined for the whole account.
- Both are available now in your account settings. The IP allowlist is off by default, and your account setup stays the same.
Two new account features are live, giving you more control over your WhoisXML API key usage.
Restrict API access to trusted IPs
We have added an additional layer of security to your API access with the new API IP allowlist feature. Once you turn this on, WhoisXML API only accepts requests from approved IP addresses or CIDR ranges, no matter what API key they use. This provides several practical benefits:
- Rejects unapproved requests. When IP restrictions are on, requests from any address outside your approved list are rejected, even if they include a valid API key.
- Protects against API key leaks. If an API key is ever leaked or shared beyond your team, requests from outside your approved IPs still get turned away, giving your account an additional layer of defense
- No disruption until you opt in. The feature is off by default, so nothing changes for existing integrations until you decide to turn it on.

Where to find it: Go to Settings > Settings > API IP allowlist tab. From there, you can switch IP restrictions on or off, add trusted IP addresses or ranges with an optional description, edit or remove entries, and save the list in one click.
See exactly how much credit Child API keys are using
If you use Parent-Child API keys, you can now monitor the usage of each team member individually, alongside the option to view usage for all members combined.
- Per-member visibility. See exactly how many credits each team member’s key is using, instead of only the combined total for the account. Select “All” any time you want the same account-wide total you had before.
- Easier budget and balance planning. See how each team member’s usage adds up to the total, so you can plan and adjust your team-wide budget using real numbers instead of one blended figure.
- Catch problems earlier. A sudden spike in one member’s API key usage stands out right away, whether it’s unexpected use or a key being used somewhere it shouldn’t be, giving you the option to disable or rotate the API key.

Where to find it: Go to Settings > My Products > select the product’s usage stats. A selector there lets you choose a specific team member or select “All” to see usage for the whole account.
Try both features in your account
Here’s how to get started:
Have questions about these account controls or want to learn more about WhoisXML API? Feel free to contact us anytime.