Copied!
Methodology

How our IP data is built: five sources, cross-checked, corrected by hand

Every IP address record on this site is assembled from several independent sources and checked against each other. No single feed is trusted on its own. This page explains where the data comes from, how disagreements are settled and how accurate you should expect a result to be.

  • Database updated September 22, 2026
  • 3,541,220 curated IPv4 ranges
  • 296,971 IPv6 ranges
  • 73,315 networks

Where the data comes from

Five inputs. Each one is good at something the others are not.

  1. Regional internet registries

    Allocation and assignment records from RIPE, ARIN, APNIC, LACNIC and AFRINIC tell us who an address block is registered to, in which country, and under which network name. We parse the full registry databases, not just per-query WHOIS.

  2. Operator-published geofeeds

    Many ISPs publish geofeed files (RFC 8805) that map their own ranges to cities. We collect hundreds of thousands of these entries, but apply them only after checking that the feed is fresh, referenced in the registry, and consistent with what the network itself shows.

  3. Reverse DNS analysis

    Hostnames assigned by operators often encode the connection type and the city of the access node. A pool named after a DSL access concentrator in a specific town is strong evidence of both technology and location. We resolve and classify millions of these hostnames.

  4. Routing and RPKI

    Live BGP data tells us which network actually announces a prefix today, which catches stale registry records. RPKI validation flags announcements that are not cryptographically authorized by the address holder.

  5. Commercial and community data

    We include GeoLite2 data created by MaxMind, available from maxmind.com, as one input among several, and community abuse reports for the security sections.

How records are verified

Sources disagree with each other constantly, and that is where most of the work is.

When two of the three main signals (registry, geofeed, reverse DNS) agree and one disagrees, the outlier is corrected. Changes are applied per network, never by blanket pattern matching, and every change batch is logged and reversible. Ranges where the evidence is genuinely ambiguous are left untouched rather than guessed.

Ownership details such as the operating brand, parent company and connection type are researched manually against the operator's own published information before being recorded.

What accuracy to expect

Country is solved. City depends on how much the operator tells the world about its network.

Country-level accuracy is effectively solved for allocated space. Region and city accuracy depend on how much an operator publishes about its own network: strongest in North America and Europe, weaker where geofeeds are sparse. Mobile, satellite and VPN ranges are inherently less precise because the address is shared or intentionally relocated. City-level results should always be read as the location of the access infrastructure, not of a person.

3,541,220
IPv4 ranges
296,971
IPv6 ranges
28,793
VPN and proxy ranges
7,957
ISPs with speed data

Corrections

Operators know their own networks best. Their corrections go in first.

If you operate a network and see wrong data on your ranges, send the correct values or your geofeed URL through the contact page. Verified corrections are usually applied within a day.

Send a correctionInclude the IP range, the right values and, if you have one, the geofeed URL.