IP address intelligence
An IP address identifies a network allocation, not a place and not a person. This module reports what the regional internet registries and routing tables actually publish, and is deliberately careful about what that does and does not mean.
Example: 1.1.1.1
What this module collects
- RDAP network allocation, CIDR range and handle
- Responsible organisation for the allocation
- Regional internet registry
- Registry country code, labelled as a registration attribute
- Autonomous system number and name from Team Cymru
- Announced BGP prefix
- Reverse DNS (PTR) records
- Spamhaus, URLhaus and other reputation verdicts, reported separately
- AbuseIPDB reports where an API key is configured
What this module will not do
These limits are deliberate. Each one is a place where a tool could produce a confident-looking answer that is not supported by public evidence.
No geolocation presented as a physical location
Commercial IP geolocation estimates where a network is registered or announced, which can be a different continent from the device. Only the registry country is reported, and it is labelled as exactly that.
Reputation sources are never averaged into a score
Each source keeps its own verdict. When they disagree, the disagreement is shown, because that is the most useful thing an analyst can learn from conflicting feeds.
A PTR record is not proof of what runs on the address
Reverse DNS is set by the network operator and can name anything. It is recorded as an inferred association, not a confirmed one.