Skip to content
osint.platform

IP address intelligence

An IP address identifies a network allocation, not a place and not a person. This module reports what the regional internet registries and routing tables actually publish, and is deliberately careful about what that does and does not mean.

Accepts an email address, username, domain, IP address or URL.

Example: 1.1.1.1

What this module collects

  • RDAP network allocation, CIDR range and handle
  • Responsible organisation for the allocation
  • Regional internet registry
  • Registry country code, labelled as a registration attribute
  • Autonomous system number and name from Team Cymru
  • Announced BGP prefix
  • Reverse DNS (PTR) records
  • Spamhaus, URLhaus and other reputation verdicts, reported separately
  • AbuseIPDB reports where an API key is configured

What this module will not do

These limits are deliberate. Each one is a place where a tool could produce a confident-looking answer that is not supported by public evidence.

  • No geolocation presented as a physical location

    Commercial IP geolocation estimates where a network is registered or announced, which can be a different continent from the device. Only the registry country is reported, and it is labelled as exactly that.

  • Reputation sources are never averaged into a score

    Each source keeps its own verdict. When they disagree, the disagreement is shown, because that is the most useful thing an analyst can learn from conflicting feeds.

  • A PTR record is not proof of what runs on the address

    Reverse DNS is set by the network operator and can name anything. It is recorded as an inferred association, not a confirmed one.