Terminal
Documentation

IPWala Documentation

A high-performance, terminal-native toolkit for DNS querying, network reconnaissance, and infrastructure debugging.

IPWala provides a UNIX-style command-line interface directly in your browser. It acts as an abstraction layer over raw OSINT APIs and low-level network sockets, allowing developers to rapidly diagnose network routing issues, verify DNS propagation, and audit infrastructure exposure without switching contexts to traditional terminal emulators.


Commands

A comprehensive reference of all supported commands and their use-cases.

DNS Lookup (lookup)

Query specific Domain Name System (DNS) records to identify how a domain routes its traffic.

Why it's needed

Used during server migrations or domain setups to verify that A, CNAME, or TXT records are correctly configured on your authoritative nameserver.

Usage Examples

lookup google.comFetches the default IPv4 (A) records for google.com.
lookup github.com TXTRetrieves text records, often used to verify domain ownership.
lookup example.com NSLists the authoritative nameservers for the domain.

DNS Propagation (propagation)

Queries multiple geographic DNS resolvers simultaneously to check record propagation status.

Why it's needed

DNS changes take time to propagate globally due to TTL caching. This tool visualizes exactly which regions have received your latest DNS updates.

Usage Examples

propagation github.comChecks if GitHub's IPv4 address is synchronized globally.
propagation example.com TXTVerifies that a newly added TXT record is visible everywhere.

WHOIS Lookup (whois)

Query official RDAP registries to retrieve domain registration and ownership data.

Why it's needed

Essential for identifying when a domain expires, discovering the domain registrar, or checking if a domain is currently available for purchase.

Usage Examples

whois stripe.comDisplays the registrar, creation date, and expiration date.
whois alltracker.onlineChecks the registry status and nameservers for a specific top-level domain.

IP Geolocation (ip)

Resolves an IPv4 or IPv6 address to its physical location, ISP, and Autonomous System (AS) number.

Why it's needed

Crucial for analyzing server logs, investigating suspicious login attempts, or verifying if traffic is routed through a specific data center or VPN.

Usage Examples

ip 8.8.8.8Looks up Google's public DNS resolver to find its ASN and geographical region.
ip 1.1.1.1Identifies the network provider (Cloudflare) associated with the IP.

MX Records (mx)

Quickly checks the Mail Exchange (MX) records of a domain to see where emails are routed.

Why it's needed

If emails from your domain are failing to send or receive, this verifies that your email provider (e.g. Google Workspace, Outlook) is correctly linked.

Usage Examples

mx gmail.comLists Google's primary mail servers and their priority weights.
mx example.comVerifies if the domain is capable of receiving emails.

TXT/SPF/DMARC (txt)

Extracts TXT records, which often contain critical email security policies like SPF and DMARC.

Why it's needed

Essential for debugging email deliverability. If your emails are going to spam, you need to ensure your SPF and DMARC TXT records are correctly formatted.

Usage Examples

txt google.comRetrieves Google's SPF configuration and site verification tokens.
txt stripe.comInspects Stripe's DMARC policies for email security.

SSL / TLS Checker (ssl)

Inspects the target's HTTPS certificate and extracts critical HTTP security headers.

Why it's needed

Ensures your web application is securely encrypting traffic and strictly enforcing security policies like HSTS (Strict-Transport-Security) and CSP.

Usage Examples

ssl github.comVerifies the validity of GitHub's TLS certificate and checks its security headers.
ssl expired.badssl.comAnalyzes a domain with an expired or invalid certificate.

ICMP Ping (ping)

Measures the round-trip latency and packet loss to a target host.

Why it's needed

The standard diagnostic tool for testing basic network connectivity and measuring the responsiveness of a remote server.

Usage Examples

ping vercel.comSends consecutive packets to Vercel's edge network to measure response latency.
ping 192.168.1.1Tests local network connectivity (blocked by SSRF protection in production).

HTTP Headers (headers)

Issues a HEAD request to a URL to fetch its raw HTTP response headers.

Why it's needed

Useful for debugging cache-control policies, identifying the underlying server software (e.g., Nginx, Cloudflare), and diagnosing redirection loops.

Usage Examples

headers google.comFetches the headers for google.com over HTTPS.
headers http://example.comExplicitly requests headers over unencrypted HTTP to inspect redirect behaviors.

Port Scanner (scan)

Performs a fast TCP connection check against common network ports (22, 80, 443, 3306, etc.).

Why it's needed

Used by system administrators to audit server security perimeters and verify if database or SSH ports are inadvertently exposed to the public internet.

Usage Examples

scan example.comScans the standard web ports to see if example.com is actively listening.
scan 142.250.190.46Directly scans a specific IP address for open TCP services.

Subdomain Enumeration (subdomains)

Queries public OSINT databases to enumerate known subdomains mapped to a primary domain.

Why it's needed

Critical for security reconnaissance and bug bounties. It helps map out a company's external attack surface by finding forgotten development environments.

Usage Examples

subdomains tesla.comDiscovers mapping for dev.tesla.com, staging.tesla.com, etc.
subdomains alltracker.onlineReveals publicly resolvable subdomains registered under this zone.

DNSBL Blacklist (blacklist)

Checks an IP address against over 50 global anti-spam and malware databases (DNSBLs).

Why it's needed

If your server's emails are bouncing or going to spam, this tool identifies if your server's IP has been flagged by services like Spamhaus or Sorbs.

Usage Examples

blacklist 1.2.3.4Checks if the IP 1.2.3.4 is blacklisted.
blacklist mail.example.comResolves the mail server to an IP and checks its reputation.

MAC OUI Lookup (mac)

Looks up the Organizationally Unique Identifier (OUI) of a MAC address.

Why it's needed

When analyzing local network traffic or router DHCP logs, this translates cryptic hardware addresses into human-readable manufacturer names.

Usage Examples

mac 00:1A:2B:3C:4D:5EIdentifies the vendor of the specified MAC address.
mac 48:E2:44Looks up the vendor using just the first 3 bytes (the OUI prefix).

Client Identity (whoami)

Extracts the public IP address, User-Agent, and geographic location of the computer running the command.

Why it's needed

A rapid diagnostic tool to verify if your VPN is active or to test how external servers perceive your HTTP request headers.

Usage Examples

whoamiReturns your current network identity and browser software string.
whoamiUsed to verify your outgoing public IP when configuring firewalls.