How ipaddress.si works
What we see, what we keep, and where every number on this site comes from.
What we see
Like every website, our server receives a few things with each request:
- Your IP address — the public address your connection uses. Behind a home router, a mobile network or a VPN this is the router’s, carrier’s or VPN’s address, not your device’s.
- Request headers your browser sends — user agent, preferred languages, and privacy signals such as Do Not Track and Global Privacy Control.
- The page you asked for, including anything you typed into a lookup.
Your browser also knows things it never sends us — your screen size, its time zone, the HTTP protocol it negotiated. Where we show those, they are computed in your browser and stay there.
What we store
- Our own copies of public datasets, downloaded and compiled on our server every 24 hours: the global BGP routing table and AS names (APNIC), address delegations from the five regional internet registries, IP geolocation (DB-IP Lite), place names and time zones (GeoNames), the Tor exit list and the IEEE MAC vendor registry.
- Aggregate page counts: the path of each page view (with lookup values removed, e.g.
/ip/[query]) and a daily counter. No IP, no cookie, no identifier. Disabled when your browser sends Do Not Track or Global Privacy Control. - Data source statistics: how many requests each source answered and how long it took, per hour — needed to monitor reliability. No lookup values are kept.
- Short-lived caches of results in memory (minutes to hours, never written to disk), so the same question isn’t asked twice.
- Messages you send through the contact form, until they are answered (deleted after at most 12 months).
What we don't store
- We do not log visitor IP addresses in our application. Rate limiting works on keyed hashes held in memory, rotated daily.
- We do not keep a history of the IPs, domains or ASNs you look up.
- We do not set tracking cookies. The only cookies are a language preference you choose, and — only if you accept — those set by Google Analytics or AdSense when the site operator has enabled them.
- We do not sell or share any visitor data.
Infrastructure in front of the application (the reverse proxy and hosting provider) may keep standard access logs for security and operations, with short retention.
How a lookup works
- Your input is validated strictly. Only IP addresses, ASNs and syntactically valid public domain names are accepted; private, internal and reserved names never leave our server.
- Network, routing, registry, location and Tor data come from our own datasets on our server. No third-party IP intelligence service is asked about your address.
- Two things are inherently live and are queried at the moment you ask: DNS (forward and reverse lookups, sent by our own DNS client to recursive resolvers) and registration records (RDAP or WHOIS, asked directly of the registry responsible for the address, AS number or domain).
- Every field shows where it came from. Values that are inferred rather than recorded — such as the network type guessed from an operator’s name — are labelled as a guess.
- If a source fails or is slow, the page shows what is available and marks the rest as not available — never a made-up value.
Commercial data providers can be connected by the site operator as an optional extra; they are switched off by default and listed below with their current status.
Data sources
Live status of every data source this site can use.
| Source | Provides | Runs | Status |
|---|---|---|---|
| Routing & registry data (own) Global BGP routing table (APNIC Thyme), AS names, and delegation records from all five regional internet registries, compiled into local indexes every 24 hours. | BGP routing | On our server | Operational 2 seconds ago |
| Geolocation data (own, DB-IP Lite + GeoNames) DB-IP IP to City Lite compiled into a local index, with time zones from the nearest GeoNames place. Refreshed every 24 hours (DB-IP publishes monthly). | Geolocation & ASN | On our server | Operational 2 seconds ago |
| Tor exit list (own copy) The Tor Project's list of exit relay addresses, refreshed with the other datasets and matched locally. | Security signals | On our server | Operational 2 seconds ago |
| DNS (own client, server resolver) Queries the resolvers this server is configured with (or DNS_RESOLVERS) over the DNS wire protocol, with EDNS0 and DNSSEC flags, returning TTLs for every record type. | DNS resolution | On our server | Operational 31 seconds ago |
| AS registry data (own) AS names (APNIC Thyme) and AS number delegations from the five RIRs, from our local indexes. | ASN data | On our server | Operational 6 minutes ago |
| BGP table (own copy) Announced prefixes per AS and the route covering any address, from our compiled copy of the global routing table. | BGP routing | On our server | Operational 6 seconds ago |
| RDAP (IANA bootstrap) Registration data from the authoritative RDAP servers of the RIRs and domain registries, discovered via IANA's bootstrap registry. | Registration data | External API | Operational 13 minutes ago |
Limitations
- IP geolocation is an estimate. It describes where an address block is likely used, often the location of a provider’s equipment. Country is usually right; city is often wrong, especially on mobile networks, satellite links, VPNs and CGNAT. It is never precise enough to identify a person or a street address, and must not be used to do so.
- Coordinates are rounded to two decimal places (about 1 km) and shown with an honest accuracy radius.
- Our datasets are refreshed daily, but upstream sources update on their own schedules (DB-IP monthly, the registries daily). A block that changed hands recently may show its previous holder for a while.
- Network type (residential, mobile, hosting…) is inferred from the operator’s name and labelled as a guess. Proxy and VPN use cannot be reliably detected from public data; we only report what a dataset actually records, such as Tor exit relays.
- Registration data is published by registries and may be outdated or redacted for privacy.