# How Does RDAP Evidence Help Resolve IP Address Disputes in 2026?

iprs.cloud · October 2, 2026

> What RDAP Evidence Can—and Cannot—Prove RDAP evidence is the machine-readable registration record produced through the Registration Data Access...

## What RDAP Evidence Can—and Cannot—Prove

RDAP evidence is the machine-readable registration record produced through the Registration Data Access Protocol (RDAP). It can show which organization currently holds a registration for an IP address or autonomous system number, when that record changed, and what contact or registrar information the registry publishes. That makes RDAP useful when an IP dispute turns on control of a network resource, such as an assignment disagreement, suspected hijacking, transfer dispute, or inaccurate registry record. It does not, by itself, prove ownership of a trademark, copyright, domain name, customer account, or physical internet connection. The key distinction is between registration evidence and substantive legal rights.

**Also worth reading:** [How Do Blockchain IP Evidence Systems Work for Registration, Disputes, and Court-Ready Proof?](https://iprs.cloud/knowledge/how_do_blockchain_ip_evidence_systems_work_for_registration_disputes_and_court-ready_proof.php) · [What Evidence Proves an IPv4 Address Transfer Is Legitimate?](https://iprs.cloud/knowledge/what_evidence_proves_an_ipv4_address_transfer_is_legitimate.php) · [How Should IP Teams Handle RDAP Redaction Without Losing Evidence?](https://iprs.cloud/knowledge/how_should_ip_teams_handle_rdap_redaction_without_losing_evidence.php)

As of 2 October 2026, RDAP is the modern successor to WHOIS for structured registry queries, although availability and deployment can vary by registry and registrar. RFC 7480 defined RDAP in January 2015, while RFC 9082 published the HTTP query format for RDAP in November 2020. RDAP responses can include object identifiers, status values, events, entities, remarks, links, and referral records. For a legal or operational review, the raw response, query time, requesting system, and any response headers should be preserved because a live record may later change.

RDAP is therefore strongest as corroborating evidence of what a registry reported, not as a universal title document. A record showing AFRINIC or another Regional Internet Registry as the sponsor of an allocation does not decide whether the named organization acted lawfully, whether a court has ordered a transfer, or whether a private contract assigned particular addresses. Counsel should combine RDAP material with allocation records, registration agreements, invoices, internal addressing plans, router telemetry, correspondence, and applicable law.

## How RDAP Evidence Differs from Ordinary WHOIS Evidence

RDAP replaces free-form WHOIS output with standardized HTTP responses and a JSON format based on the JavaScript Object Notation. Standardization improves consistency and makes repeated records easier to compare. WHOIS may still provide historical or registry-specific information, especially through third-party archival services, but its fields and query behavior are less uniform. RDAP also provides explicit links to authoritative servers, allowing clients to follow referrals rather than rely only on a generic search portal.

The evidentiary value of either source depends on authenticity and context. A screenshot can capture the visible text but may omit response headers, extensions, referral links, or machine-readable fields. A direct RDAP response saved in a file, together with its HTTP metadata, usually offers a better technical audit trail. Even so, preservation does not make the data infallible: registries can receive incorrect data, organizations can fail to maintain contacts, and public records may intentionally omit personal information for privacy reasons.

| Feature | RDAP | WHOIS |
| --- | --- | --- |
| Output format | Standardized JSON over HTTPS | Mostly text-based, protocol and field layouts vary |
| Main basis | RFC 7480 and RFC 9082 | Historical registry and registrar protocols |
| Privacy | Can omit or redact personal data | Availability of personal data varies by policy and jurisdiction |
| Audit handling | Raw HTTP response and headers can be captured | Text output and server metadata can be captured |
| Best use | Current registration facts and referrals | Legacy compatibility and some historical research |
| Legal limitation | Does not independently establish all ownership or usage rights | Has the same ownership and accuracy limitations |

Neither system should be treated as conclusive merely because its output looks authoritative. Registry records establish a published administrative position unless a statute, transfer policy, contract, or judgment gives them a stronger legal effect. In a dispute, the stronger document may be a signed allocation or registration agreement, a notarized assignment, a court order, or reliable network traffic evidence.

## Practical Method for Collecting Dispute-Grade RDAP Records

First, record the disputed resource exactly: the IP address, prefix, autonomous system number, registry, responsible organization, and relevant date range. Query the relevant RIR’s authoritative RDAP service, not only an aggregator. Follow referrals when required and capture the final response. Preserve the complete HTTP exchange, including the URL, UTC timestamp, status code, response headers, and JSON body. Convert the timestamp to UTC and retain the original machine-readable file without editing it.

Second, calculate a cryptographic hash, such as SHA-256, of the saved response and document the collection method. A hash helps show that the retained copy has not changed since collection, but it does not prove who controlled the network at the moment of collection. Record the analyst’s identity, tools, network location, and steps. Screenshots can be added as convenience images, although they should supplement rather than replace the raw record.

Third, compare the current record with earlier observations. RDAP event fields may reveal registration, expiration, last-changed, transfer, or restoration events, depending on the registry’s implementation. History can show when a sponsor changed, but an event date is not automatically the date on which every practical right changed. Search applicable registry archives, trusted internal logs, certificate-transparency records where relevant, and contemporaneous emails. Do not assume that a missing historical event means no event occurred; public data may be incomplete or redacted.

Fourth, connect registry facts to the claim. If the allegation is misallocation, identify the conflicting allocation record and request a certified copy or registry explanation. If it is unauthorized use, compare the registration sponsor with routing and application traffic. If it concerns a brand or domain-name dispute, use trademark, registry, contract, and use evidence in addition to RDAP. A defensible chronology should distinguish the time of registration, notice, transfer request, takeover, last-known contact, and traffic observation.

Finally, obtain platform assistance through the proper registry, registrar, hosting provider, or RIR security route while evidence preservation continues. Reporting abuse does not suspend a transfer or resolve a civil dispute automatically. Organizations should avoid threatening registry action unsupported by accurate records, because weak submissions can delay resolution and may consume the complainant’s limited dispute opportunities.

## AFRINIC and the Role of Regional Internet Registries

AFRINIC is the Regional Internet Registry responsible for Internet Protocol address and autonomous system number resources for Africa and parts of the Indian Ocean region. Its published scope includes African countries and nearby islands in the Indian Ocean, although exact resource boundaries should be checked against current registration data rather than inferred from geography. When an AFRINIC-sponsored address appears in a dispute, the relevant questions include which entity is recorded as sponsor, whether the resource is properly assigned, and which registration policy governs the relationship.

Regional registry status is not a substitute for national or private ownership proof. AFRINIC can maintain registration data and operate transfer or dispute procedures, but it generally does not adjudicate every contractual disagreement between an organization and its reseller. Some resources may have multiple levels of administration: a registry delegates or registers a resource, a registrar or reseller manages the customer relationship, and a network operator announces or uses the addresses. RDAP can expose those layers through entities and referrals, but the exact terminology and delegation model must be confirmed in the current response.

An AFRINIC dispute should therefore begin with the authoritative RDAP endpoint and the applicable current policies. Counsel should identify whether the issue involves an allocation, a registration agreement, a reseller relationship, resource transfer, or policy non-compliance. Each path has different evidence requirements. A registry contact record may help locate the responsible party, while a signed sub-allocation agreement may establish the actual customer and permitted use.

The registry’s role also has limits. An RIR generally manages delegated number resources rather than trademarks, websites, domain names, copyright, or the content carried over an address. A party asserting a trademark claim may need to show confusion, authorization to use the mark in the relevant class, and the applicable jurisdiction. A party asserting infringement may also need evidence of copying or other legally relevant conduct. RDAP supports the identification process but does not replace that analysis.

## Costs, Timing, and Operational Expectations

Authoritative RDAP queries are normally free public access, so the direct collection cost can be $0 for an attorney, engineer, or developer. Some commercial intelligence, historical-data, preservation, expert, or e-discovery services charge fees ranging from modest monthly subscriptions to several thousand dollars or more per matter, depending on coverage and features. A formal registry certification, registrar document retrieval, legal opinion, or expert report can cost substantially more than the original RDAP query. No fixed global price exists, and a quoted service should be evaluated for source quality rather than volume alone.

Simple RDAP collection may take minutes, but resolving a dispute can take weeks or months because records must be validated and the competing claims assessed. Immediate action is appropriate when there is active unauthorized routing, phishing infrastructure, a suspected transfer, imminent evidence loss, or an approaching legal deadline. It is also reasonable to monitor without escalating when the discrepancy appears administrative and no harmful conduct is occurring. Speed does not itself improve the quality of evidence; collecting before changes occur is more valuable than filing quickly with an incomplete record.

A small internal review may consume roughly 1 to 3 hours once the resource and registry are known. More complex matters requiring historical reconstruction, multiple jurisdictions, or expert analysis can take 20 to 80 hours or longer. Organizations should budget for monitoring and repeat collection at meaningful milestones, such as before and after a formal complaint, rather than assuming one snapshot settles the issue. The cost is often lower when a documented RDAP workflow is established in advance.

## Common Mistakes in Using RDAP in IP Disputes

A frequent mistake is treating the organization named in RDAP as indisputably responsible for every activity observed on the address. The record may identify a sponsor, registrant, holder, or administrative contact, depending on the registry and resource type. Another error is comparing a current record with an allegation without fixing the relevant date. Registrations, transfers, loans, and operational use can change over time, so a current sponsor may not match the sponsor during the incident.

Analysts also sometimes overlook referral and extension fields, trim JSON down to a few attractive attributes, or use an aggregator when the authoritative registry record was available. Others assume that RDAP exposes personal contact details, despite privacy redactions and differences among jurisdictions. Redaction should not be read as evidence of concealment, while the presence of a public email address should not be read as proof that the organization controlled the disputed activity at a particular time.

The most serious legal mistake is claiming that RDAP conclusively proves trademark or copyright ownership. Registry records can support a chronology and identify resources, but the legal claim remains dependent on the governing law and the rights asserted. Finally, contacting a registry informally while failing to preserve evidence can allow the relevant record to change before review. A complaint, support ticket, and formal legal request have different effects; teams should choose the route that matches the urgency and preserve all submissions and receipts.

## When to Act and How to Organize the Evidence for Counsel

Act promptly when the disputed address is being announced by an unauthorized party, when a transfer or deletion may occur, or when evidence could expire. The first hour should include recording the resource, capturing RDAP, routing data, application or incident observations, and the exact UTC time. Counsel can then determine whether emergency injunctive relief, registry escalation, registrar abuse reporting, contract enforcement, or ordinary investigation is appropriate. Immediate technical action should not be taken solely on RDAP output, because an incorrect or stale record can misdirect the response.

A counsel-ready package should contain an indexed chronology, source inventory, preserved RDAP files, response headers, hashes, routing snapshots, relevant contracts, emails, and a plain-language explanation of what each item proves and does not prove. Use UTC consistently and identify each collection source. Where records disagree, state the disagreement rather than selecting the most convenient result. If the organization has a compliance or incident-response process, preserve its ticket identifiers and internal approvals.

RDAP evidence is particularly valuable to B2B intellectual-property teams because it can connect disputes to registry-level administration and help distinguish a naming problem from a network-resource problem. Registry operations, product security, procurement, and legal teams may all hold relevant records. A shared evidence protocol reduces repeated collection, preserves consistent timestamps, and prevents one team from communicating a registration fact as though it were a legal conclusion. It also supports SaaS workflows that need permissioned access, audit logs, retention schedules, and review status rather than unstructured screenshots.

The defensible position is not “RDAP proves we own the dispute.” It is that RDAP shows what authoritative registry data reported, at a documented time, and that this evidence has been tested against other records and applicable rights. That formulation is accurate, reviewable, and useful in negotiations, technical investigations, and legal proceedings.

## Quick answers

### Does RDAP prove ownership of an IP address?

RDAP shows current or historical registration information published by the relevant registry, including sponsor or administrative entities when those fields are available. It does not independently prove contractual ownership, authorization to use every address in a prefix, or responsibility for all traffic. Use it with allocation records, agreements, routing evidence, and applicable law.

### Is RDAP better than WHOIS for dispute evidence?

RDAP is generally easier to validate and compare because it uses structured JSON and standardized HTTP responses. WHOIS can remain useful for legacy systems and historical research, but its output varies between servers. The better evidence is the one obtained from the authoritative source, preserved completely with timestamps and provenance.

### How much does an RDAP lookup cost?

Authoritative RDAP queries are normally free. Commercial historical-data platforms, forensic services, formal registry certifications, and expert reports may cost from modest subscription fees to thousands of dollars or more. The cost depends on the depth, urgency, and jurisdiction of the investigation, not on the basic query itself.

### Can RDAP identify a person responsible for online infringement?

It may identify an organization, sponsor, registrar, or administrative contact connected to the address, but public records can be redacted or inaccurate. It does not automatically identify the person operating a website or account. Investigators should correlate RDAP with domain, hosting, account, payment, telemetry, and legal evidence where lawfully available.

### Does AFRINIC resolve every IP address dispute?

AFRINIC administers Internet number resources for Africa and nearby Indian Ocean areas, but the precise remedy depends on whether the issue concerns registry policy, allocation, a registration agreement, or a downstream reseller relationship. Trademark, copyright, and contractual claims may require another forum or evidence. The current AFRINIC policies and the exact resource record should be checked before filing.

Canonical: https://iprs.cloud/knowledge/how_does_rdap_evidence_help_resolve_ip_address_disputes_in_2026.php
Markdown: https://iprs.cloud/knowledge/how_does_rdap_evidence_help_resolve_ip_address_disputes_in_2026.php/index.md
