Every signal, from authoritative sources.
Each lookup is enriched by layering more than a dozen independent datasets — geolocation, network registries, BGP routing, and live threat feeds — so one request answers where, who, and how risky. Here is exactly what powers it.
Address-family coverage: every lookup surface accepts IPv4 and IPv6. Core geolocation covers both families; some registry, routing, cloud, crawler, Spamhaus, and commercial-proxy feeds remain IPv4-only upstream. Source-specific fields are omitted when that source has no coverage for the queried address family, rather than inferred from a truncated address.
Where the address is.
MaxMind GeoLite2
City, subdivision, country, continent, coordinates, and time zone for IPv4 and IPv6.
Includes GeoLite2 data created by MaxMind, available from maxmind.com.
DB-IP IP-to-City Lite
A second geolocation source that corroborates city and country resolution.
IP geolocation by DB-IP (CC BY 4.0).
SimpleMaps World Cities
Nearest populated place — city, admin name, capital status, and population.
Basic database from simplemaps.com.
Country metadata
Currency, official languages, EU membership, and whether GDPR applies to the visitor.
Curated reference data, refreshed with each release.
Which network it belongs to.
RIPE NCC database
netname, org, ripe_org_id, and allocation status for European, MENA, and Central-Asian ranges.
Source: the RIPE NCC registry.
RouteViews & IP-to-ASN
BGP-derived prefix-to-ASN mapping resolves the autonomous system, operator, and ASN country.
University of Oregon RouteViews / CAIDA prefix2as.
Mobile carriers
Flags mobile-carrier ranges so you can tell cellular traffic from fixed-line.
Carrier allocation data, keyed by ASN.
Cloud providers
Identifies datacentre ranges and names the provider (AWS, Azure, GCP, DigitalOcean, and more).
Published provider IP ranges, refreshed regularly.
How risky it is.
Tor Project
Live exit-node and relay lists flag is_tor_exit_node and is_tor_full_node.
Official Tor Project node lists.
Spamhaus DROP
The DROP / eDROP lists mark hijacked and malicious networks via is_spam.
Source: Spamhaus DROP/eDROP.
VPN & proxy ranges
Known commercial VPN and open-proxy ranges set is_vpn / is_proxy with a proxy_type.
Aggregated provider ranges.
Anycast & multicast
Detects anycast and multicast addressing so shared infrastructure is not mistaken for a user.
IANA special-purpose registries.
Crawler signatures
Matches known search-engine and bot crawlers by IP and User-Agent via is_crawler.
Maintained crawler signature set.
Satellite ISPs
Flags satellite-ISP ranges so high-latency or roaming traffic is identifiable.
Satellite carrier allocations.
Credit where it's due.
We honour every upstream licence. This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com, and IP geolocation data by DB-IP licensed under CC BY 4.0. Network data derives from the RIPE NCC, RouteViews, and IANA registries; threat data from the Tor Project and Spamhaus. Datasets are refreshed on a rolling schedule so results track real-world changes.