IP Address Lookup: Who Owns This IP?
Check any IPv4 or IPv6 address: public or private, the network and AS number that announce it, the country where that network is registered, and its reverse DNS.
Related tools
All Web & network tools →An unknown address in server logs, an email header or a firewall alert: before asking who owns this IP, you need to know what kind of address it is. This IP address lookup starts by reading it strictly and placing it in its block, because a private address, an operator's shared range or a documentation example belongs to no one in particular. For a public address, it then names the network that announces it on the Internet, found in public tables right inside your browser, followed by its reverse DNS name. The answer is about a network, not a person or a street: only the operator can link an address to a subscriber.
How to use it
- Type or paste an address into “IPv4 or IPv6 address”, or click one of the examples: 8.8.8.8, 1.1.1.1, 2606:4700:4700::1111, 192.168.1.1 or 100.64.0.1.
- Press “Analyse” or Enter; clicking an example runs the analysis straight away.
- If the entry is refused, read the reason under the field and, when a correction is offered, click it, for instance “Analyse 192.168.1.1”.
- Read the “Address analysed” card: canonical form, IPv4 or IPv6 badge, type of address and, for a special address, its block and RFC.
- For a public address, check “Origin network” (network, country of registration, network range, CIDR blocks) and “Reverse DNS (hostname)”.
- Copy the canonical form with “Copy”, or press “Try again” when the network data or the reverse DNS did not answer.
What the lookup checks, in order
First comes the reading. An IPv4 address must have four numbers from 0 to 255 with no leading zero: some software reads 010.1.1.1 as octal, that is 8.1.1.1, so the tool refuses rather than analyse an address other than the one typed. IPv6 is accepted in every text form RFC 4291 allows, square brackets and zone identifier included, then rewritten in its canonical form (RFC 5952). The address is next matched against the IANA special-purpose registries, and a private, loopback or documentation address stops there, without sending a single request.
For a public address, your browser downloads the index of the tables published by the site, then the single fragment covering the address's block (a /8, a /12 or a /16 for IPv4) and the file holding the network names, and finds the range by binary search: the server sees which fragment is requested, never the address. The tables come from iptoasn.com under the PDDL licence (public domain); the import of September 13, 2026 holds 403,290 IPv4 ranges, 96,666 IPv6 ranges and 86,963 network names, contiguous ranges of the same network and country being merged. The result gives the AS number and its name as published, the country where that network is registered, the range and up to eight CIDR blocks.
An IPv6 address that carries an IPv4 one is looked up by that IPv4, the address that actually travels: ::ffff:8.8.8.8 (IPv4-mapped), 64:ff9b::808:808 (NAT64), a 6to4 address in 2002::/16 or a Teredo address in 2001::/32, whose IPv4 is stored with every bit inverted. The local NAT64 prefix 64:ff9b:1::/48 is the exception: the operator decides where the IPv4 sits, so the tool shows it with a caveat and does not look it up. As soon as a public address is analysed, the site's servers ask Cloudflare's and Google's resolvers for its reverse DNS name, and the page distinguishes an address with no published name from resolvers that did not answer.
When an IP lookup is worth it
- Sorting out the addresses hammering your login page or SSH access: the host or provider they come from, and the CIDR blocks to put in a firewall rule, weighing the risk of blocking every customer of that network.
- Checking the Received headers of a suspicious email: do the network and the reverse name of the sending server match the service that supposedly sent it?
- Telling whether an address found in a router, container or virtual machine configuration is private, shared by the operator (CGNAT) or genuinely public.
- Normalising IPv6 addresses written in different ways before comparing them in logs or an allowlist, since the RFC 5952 canonical form is unique for a given address.
- Confirming that a DNS resolver you set by hand, such as 1.1.1.1 or 8.8.8.8, belongs to the network you expect, and seeing its reverse name.
- Decoding a ::ffff: or NAT64 address found in a dual-stack application's logs: the tool extracts the IPv4 inside and looks up that network.
Worked examples
Results obtained with the tables from September 13, 2026; the reverse names are those published on September 14, 2026 and may change.
- 8.8.8.8 is a “Public address”: “Network (autonomous system)” shows GOOGLE (AS15169), “Network's country of registration” United States (US), “Network range” 8.8.8.0 – 8.8.8.255 and “CIDR block(s)” 8.8.8.0/24, while reverse DNS returns dns.google.
- 2001:4860:4860:0000:0000:0000:0000:8888 is displayed as 2001:4860:4860::8888 with “canonical form (RFC 5952)” in the card title, and also belongs to GOOGLE (AS15169). Its range, 2001:4860:480d:: – 2001:4860:ffff:ffff:ffff:ffff:ffff:ffff, does not fit into eight CIDR blocks: the list stops at the eighth and adds “(first eight blocks)”, and the address sits in the fifth one, 2001:4860:4840::/42.
- 192.168.1.1, 100.64.0.1 and 2001:db8::1 stop at the first card, without any request: “Private address” (192.168.0.0/16 · RFC 1918), “Operators' shared address space (CGNAT)” (100.64.0.0/10 · RFC 6598) and “Reserved for documentation” (2001:db8::/32 · RFC 3849).
- 192.168.001.1 is refused with “No leading zeros in the numbers: 192.168.1.1.” and an “Analyse 192.168.1.1” button; 192.168.1.1:8080 gets “Remove the port number (:8080): enter the address on its own.”, with the same button.
Limits of an IP lookup
- No location: no city and no coordinates, only the country where the network is registered, which can differ from where the address is used. The “My IP address” tool gives an approximate location, but only for your own connection.
- What you find is a network, not a user: a hosting provider's address leads to the host, not its customer, and a residential address to the operator, never to the subscriber.
- The tables are a dated copy, not a live BGP feed: a range announced since the last import shows “No BGP announcement covers this address”, and the range displayed can merge several contiguous announcements from the same network.
- Network names are the ones in the tables, often in capitals and shortened, such as CLOUDFLARENET; a number without a name is shown on its own, with “name not in the public tables”.
- Reverse DNS is set by whoever runs the block's reverse zone, so it can be missing, generic or misleading. Beyond 30 requests a minute the site answers “Too many requests: try again in a minute.”, and an answer may be served from cache for up to 5 minutes.
- One address at a time, 64 characters at most: a domain name is refused (“That is a domain name, not an IP address.”), and so is a CIDR block, for which only the address written before the slash is offered for analysis.
Privacy
Browser, and a server for one featureReading and classifying the address happen in your browser; for a private or reserved address, nothing leaves it. For a public address, your browser downloads public files from the site, and the server sees which fragment of the tables is requested, not the address. Reverse DNS goes out as soon as the analysis runs: the address passes through the site's servers, where an anti-abuse counter keeps a fingerprint of your connection, then through Cloudflare's and Google's resolvers, which see the address asked about but not you. The tool keeps no history and stores nothing locally, since an address typed here may belong to someone else.
Frequently asked questions
Can you find out who is behind an IP address?
Not with a public lookup. It tells you which network announces the address, such as an operator or a hosting provider, and in which country that network is registered. The link between an address, a point in time and a subscriber exists only at the operator, which normally discloses it only within a legal procedure. Behind CGNAT, even the exact time and port are needed to tell apart the customers sharing one address.
Why doesn't the country shown match where the address is used?
Because the row gives the country where the network is registered, not where the address is. 1.1.1.1 shows United States (US), the registration country of CLOUDFLARENET, although that resolver answers from many countries thanks to anycast, and a European operator can announce ranges used on other continents. Placing an address would take a geolocation database, which the tool neither ships nor queries.
Why is 192.168.001.1 refused?
Because a leading zero is ambiguous. Older network functions such as inet_aton read 010.1.1.1 as octal, meaning 8.1.1.1, so accepting that spelling would risk analysing an address other than the one typed. The tool refuses, shows “No leading zeros in the numbers: 192.168.1.1.” and offers a button for the corrected version. A number above 255 gets a different message: “Each number goes from 0 to 255.”
What do “Network range” and “CIDR block(s)” mean?
The range runs from the first to the last address that the tables attach to the same network around the address you looked up. The CIDR blocks write that range the way firewalls and routers expect: 8.8.8.0/24 means the 256 addresses from 8.8.8.0 to 8.8.8.255. When the range does not fit into one block, the tool lists eight at most and says so. Think before blocking a whole block: it may serve thousands of customers.
Why does my IPv6 address look different from what I typed?
Because the same IPv6 address can be written in many ways, and the tool brings it back to the single spelling defined by RFC 5952: lower case, leading zeros removed, the longest run of zero groups (two or more) shortened to a double colon. 2001:0DB8:0000:0000:0000:0000:0002:0001 thus becomes 2001:db8::2:1, and the card title adds “canonical form (RFC 5952)”. A zone identifier such as %en0 is removed from the address and shown on its own row, “Zone (interface)”.
What does it mean when an IP address is not routed?
That on the date of the tables, no network announced a range containing that public address, so it is not reachable on the Internet: either it is assigned to nobody, or its holder does not announce it. A range announced after the import can show the same message. It is an answer, not an outage: when the tables themselves cannot be loaded, the tool says “Network data unavailable right now.” and offers “Try again”.
Does the reverse DNS name prove who owns the address?
No. That name is published by whoever controls the block's reverse zone, and nothing prevents a misleading name or no name at all. It works as corroborating evidence: 8.8.8.8 returns dns.google and belongs to GOOGLE (AS15169), 1.1.1.1 returns one.one.one.one and belongs to CLOUDFLARENET (AS13335). When the name and the network disagree, trust the network, which comes from routing data, and check with a DNS lookup that the name points back to the address.
How is this different from a whois lookup?
A whois query asks the regional registry that allocated the block and returns its registration record: holder organisation, technical and abuse contacts, dates. This tool queries no registry; it reads a table derived from BGP announcements and registry data, which gives the AS number, its name and its country of registration. The address never leaves your browser for that part, but to report abuse you will still need the abuse contact that whois provides.