# Crafzo IP Lookup > Free IP lookup tool for checking IP location, ISP, ASN, organization, fraud risk, proxy risk, VPN clues, and AI-powered IP health insights. This file contains the full text of Crafzo IP Lookup's tool pages and guides. The short index is at https://ip.crafzo.com/llms.txt. Canonical domain: https://ip.crafzo.com. Language: English. Publisher: Crafzo IP Lookup. Read the content with these limits in mind: IP geolocation is approximate (country and network are usually reliable, city is an estimate, coordinates are the centre of an area, not a device). Risk and reputation scores are signals from third-party providers, not proof, and must be combined with first-party logs and account context before any decision. # Free IP Tools ## What Is My IP Address Canonical: https://ip.crafzo.com/what-is-my-ip Find your public IP address and check its location, ISP, ASN, IPv4 or IPv6 format, and VPN or proxy clues. Use Crafzo when you need to see the public IP address websites can detect, then review the location, ISP, ASN, and network-risk context behind that address. ### What this tool checks - Automatic public IP detection on the main lookup - IPv4 and IPv6 address support - Location, ISP, ASN, and risk context in one report ### How to use it 1. Open the lookup workspace to detect your current public IP automatically. 2. Compare the returned ISP, city, country, and network owner with your expected connection. 3. Turn a VPN or proxy on and run the check again if you want to confirm your visible IP changed. ### Common uses - Confirm the public IP websites can see - Test whether a VPN changed your IP - Troubleshoot home, office, or mobile network routing - Copy your public IP for support or server allowlists ### FAQ **Is my public IP the same as my device IP?** Not always. Your phone or laptop usually has a private local address, while websites see the public IP from your router, carrier, VPN, or proxy. **Why did my public IP change?** ISPs, mobile carriers, VPNs, and office networks can assign or route public IP addresses differently over time. ## IP Address Lookup Tool Canonical: https://ip.crafzo.com/ip-address-lookup-tool Lookup an IP address to find location, ISP, ASN, organization, risk score, proxy clues, and readable network context. Run an IP address lookup when you need a fast answer about where an address appears to come from, who operates the network, and whether the connection has risk signals. ### What this tool checks - Lookup public IPv4 and IPv6 addresses - Show country, region, city, ISP, ASN, and organization - Pair location data with fraud score and proxy-risk context ### How to use it 1. Paste a public IPv4 or IPv6 address into the lookup box. 2. Check the location fields beside ISP, ASN, and organization data. 3. Use the risk score and health summary as context before taking action. ### Common uses - Lookup an IP address from server logs - Check a suspicious visitor or signup source - Verify an API client or webhook source - Understand a VPN, proxy, or hosting network ### FAQ **Can an IP address lookup find a street address?** No. IP lookup estimates network-level location such as country, region, city, ISP, or organization. It should not be treated like GPS. **What IP address formats can I check?** Crafzo accepts public IPv4 addresses such as 8.8.8.8 and IPv6 addresses such as 2001:4860:4860::8888. ## IP Location Lookup Canonical: https://ip.crafzo.com/ip-location-lookup Find the approximate country, region, city, timezone, ISP, ASN, and organization behind a public IP address. Use IP location lookup to estimate where a public network address appears to originate and to understand the provider or organization behind the connection. ### What this tool checks - Country, region, city, latitude, longitude, and timezone context - ISP, organization, and ASN fields for network owner review - Accuracy notes that keep geolocation expectations realistic ### How to use it 1. Enter the public IP address you want to locate. 2. Review country, region, city, and timezone as approximate network data. 3. Compare location with ISP, ASN, VPN, and proxy signals before making decisions. ### Common uses - Check where a login appears to come from - Troubleshoot wrong city or country results - Review analytics or regional traffic patterns - Investigate location mismatches from VPNs or mobile carriers ### FAQ **How accurate is IP location lookup?** Country-level results are often useful, but city-level results can vary because of ISP routing, VPNs, proxies, mobile gateways, and database updates. **Why does my IP show the wrong city?** Your ISP or carrier may route traffic through a nearby hub, or a VPN/proxy may expose a location different from where you physically are. **Is IP country lookup accurate?** Country is the most reliable level of IP geolocation: address blocks are allocated to organizations in one country and rarely cross borders in use. VPNs, proxies, satellite networks and mobile carrier routing are the exceptions that can place an address in another country, and a traveller or a work network can be somewhere other than the account says, so treat a country mismatch as a review signal rather than a final decision. **Can I use country lookup for fraud checks?** Yes, as one signal. Country is useful for language defaults, compliance routing, traffic analytics, login notifications and fraud review, but combine it with user behavior, payment data and account history before acting on it. ## IPv6 Lookup Canonical: https://ip.crafzo.com/ipv6-lookup Lookup an IPv6 address to check approximate location, ISP, ASN, organization, and network-risk context. Modern users increasingly appear through IPv6 networks. Crafzo lets you validate and inspect IPv6 addresses alongside location, ISP, ASN, and risk context. ### What this tool checks - Accepts full and compressed IPv6 address formats - Returns available geolocation and network owner context - Useful for dual-stack debugging and modern carrier traffic ### How to use it 1. Paste a public IPv6 address into the lookup box. 2. Review the returned country, city, ISP, organization, and ASN where available. 3. Check whether IPv4 and IPv6 results differ when troubleshooting a connection. ### Common uses - Debug IPv6-only or dual-stack traffic - Check mobile carrier IPv6 addresses - Validate firewall, WAF, or access-log entries - Compare IPv4 and IPv6 location behavior ### FAQ **Can I lookup compressed IPv6 addresses?** Yes. Standard compressed IPv6 notation such as 2001:4860:4860::8888 is accepted by the lookup. **Can IPv6 show a different location than IPv4?** Yes. IPv4 and IPv6 may route through different network ranges, so their location and ISP context can differ. ## Free IP Checker Canonical: https://ip.crafzo.com/free-ip-checker Check an IP address for location, ISP, ASN, organization, fraud score, VPN or proxy clues, and health context. Use this free IP checker for quick network context when a signup, login, request, or support case includes an address you need to understand. ### What this tool checks - Free lookup for public IPv4 and IPv6 addresses - Location, ISP, ASN, organization, and timezone fields - Risk score, proxy clues, and AI-readable health context ### How to use it 1. Enter the IP address from your alert, log, signup, or support request. 2. Check location and network owner fields for the first-pass explanation. 3. Review risk signals before deciding whether to trust, challenge, or investigate. ### Common uses - Check a visitor IP from website logs - Review a suspicious account signup - Understand a support ticket IP address - Confirm whether traffic came from hosting, VPN, or ISP networks ### FAQ **Is this IP checker free?** Yes. The public lookup is free to use for checking IP location, network context, and available risk signals. **Should I trust an IP checker result by itself?** No. Use IP results as one signal with logs, account history, device behavior, payment data, and your own security rules. ## IP Fraud Score Check Canonical: https://ip.crafzo.com/ip-fraud-score-checker Check any IP fraud score free. Get a 0-100 risk rating with proxy, VPN, Tor, botnet, and blacklist signals, plus what a good score looks like. No signup. An IP fraud score rates how risky traffic from an address looks on a 0-100 scale. Enter any IPv4 or IPv6 address to see its fraud score beside geolocation, ISP, ASN, and proxy or VPN reputation context for security reviews. ### What this tool checks - 0-100 fraud score with a plain-language risk band - Proxy, VPN, Tor, datacenter, and blacklist reputation signals - Country, city, ISP, ASN, and network context beside the score - Useful for signups, payments, logins, and abuse review ### How to use it 1. Enter a public IPv4 or IPv6 address, or leave it blank to check your own IP fraud score. 2. Read the 0-100 fraud score and its risk band beside location and network details. 3. Check the proxy, VPN, Tor, and hosting signals that explain why the score is high or low. 4. Use the result as one signal with account, device, and behavior history. ### Common uses - Check your own IP fraud score - Review fake signup attempts - Investigate chargeback or payment risk - Check suspicious login sources - Prioritize abuse reports ### FAQ **What is a good IP fraud score?** Lower is better. Crafzo shows the Scamalytics band with the score: 0-19 low, 20-59 medium, 60-89 high, 90-100 very high. The score comes from Scamalytics, which describes it as the approximate share of users seen from that address who were linked to fraudulent activity: a score of 70 means roughly 7 in 10. Crafzo shows the provider's band with the score (0-19 low, 20-59 medium, 60-89 high, 90-100 very high). The band is a triage signal, not a verified probability for your traffic, and the provider recommends adjusting thresholds to your own fraud data. Treat the bands as guidance for how much verification to apply, not as a fixed rule. **What does an IP fraud score mean?** An IP fraud score estimates how risky traffic from an address may be based on reputation, proxy, hosting, Tor, blacklist, and abuse signals reported for that address and its network neighbourhood. It scores the network address, not the person using it. **How do I check my own IP fraud score?** Open the lookup without entering an address and your public IP is detected automatically, then its fraud score, location, ISP, and proxy or VPN signals are shown. You can also paste your IP manually to check it. **Why is my IP fraud score high?** Common causes are a VPN, proxy, or Tor exit, a mobile or shared carrier address reused by many users, a datacenter or hosting IP, or a past abuse or blacklist listing tied to the address or its network range. **Can this detect VPNs, proxies, and Tor nodes?** Yes. The check reviews anonymization signals such as VPN usage, proxy connections, Tor exits, hosting providers, and datacenter networks when those signals are available. **Is the IP fraud score check free?** Yes. You can check IP fraud risk for free without creating an account or signing up. **Should I block every high-score IP?** No. Treat the score as a risk signal and combine it with your own logs, user history, device signals, and business rules. **Can a home or mobile IP have a high fraud score?** Yes. Residential and carrier addresses are shared and reassigned, so a compromised device, a residential proxy network or a previous subscriber's abuse can leave a listing behind. Read the score with the network type: a hosting address that scores high may simply be a server talking to your API, while a home address with a high score and nothing else flagged is usually inherited history and a reason to verify, not to block. ## IP Reputation Check Canonical: https://ip.crafzo.com/ip-reputation-check Check IP reputation signals, fraud risk, blacklist status, ISP, and ASN context for suspicious visitors, bots, and abuse investigations. IP reputation helps you understand whether an address is commonly associated with normal users, hosting networks, proxies, spam, or suspicious traffic. ### What this tool checks - Readable risk context for non-specialists - Location and network owner clues - Useful starting point before deeper threat-intelligence checks ### How to use it 1. Paste the IP address you want to investigate. 2. Check the location, network, risk score, and health summary. 3. Compare the result with your logs before taking enforcement action. ### Common uses - Investigate form spam - Review WAF or firewall logs - Check suspicious API clients - Understand unusual account activity ### FAQ **What is an IP reputation check?** An IP reputation check reviews whether an address has risk context such as abuse patterns, blacklist signals, suspicious network type, proxy usage, or unusual traffic history. **Can this help with abuse and blacklist investigations?** Yes. The lookup adds fraud risk, ISP, ASN, and network context that can support abuse reviews before you check deeper threat-intelligence or blacklist sources. **Can IP reputation be wrong?** Yes. Reputation is probabilistic and can change over time, so it should be paired with behavior and account context. **Is reputation the same as geolocation?** No. Geolocation estimates where traffic appears to come from, while reputation estimates whether the address has risk signals. **How often should I check IP reputation?** Check it when risk matters: signup, payment, login and account recovery events, and whenever an address turns up in an abuse investigation. Reputation moves in both directions, since a clean cloud server can be abused, a compromised home device can be cleaned up and ranges are reassigned, so a live check beats an old screenshot or a one-time lookup. ## VPN and Proxy IP Checker Canonical: https://ip.crafzo.com/vpn-proxy-checker Check whether any IP is a VPN, proxy, Tor exit node, hosting provider, or datacenter. Free real-time detection tool. Use this lookup when you need to understand whether traffic is coming from a normal user network, a privacy tool, a proxy, or hosting infrastructure. ### What this tool checks - Proxy, hosting, and network-type clues when available - ISP and ASN context for the visible IP address - Balanced guidance so legitimate VPN users are not treated as automatically bad ### How to use it 1. Run the IP lookup before and after connecting to a VPN. 2. Compare the ISP, ASN, country, and risk indicators. 3. Use stronger verification for high-risk actions instead of blanket blocking. ### Common uses - Test whether a VPN changed your visible IP - Review proxy-heavy signup traffic - Detect data center login attempts - Tune SaaS login security ### FAQ **How can I check if an IP is a VPN or proxy?** Enter the IP address and review the VPN, proxy, Tor, hosting, datacenter, ISP, and ASN clues returned by the lookup. **Can this detect Tor exit nodes and datacenter IPs?** Yes. The checker looks for anonymizer and infrastructure signals including Tor exits, proxies, VPNs, hosting providers, and datacenter networks when available. **Are VPN users always risky?** No. VPNs are common for privacy, travel, and work. Treat VPN or proxy usage as context, not automatic proof of abuse. **Can websites detect every proxy?** No detection method is perfect. Proxy checks work best when combined with reputation, ASN, velocity, and behavior signals. ## Botnet IP Lookup Canonical: https://ip.crafzo.com/botnet-ip-lookup Look up suspicious IPs and review location, network, fraud score, and reputation context during botnet or abuse investigations. A single lookup cannot prove an IP is part of a botnet, but it can help you triage suspicious traffic and decide whether deeper investigation is needed. ### What this tool checks - Fast context for incident-response triage - Location, network, and fraud-risk signals in one place - Practical next-step guidance for security teams ### How to use it 1. Collect the IP address, timestamp, endpoint, and behavior from your logs. 2. Run the lookup to enrich the IP with location, network, and risk context. 3. Look for clusters across ASN, country, endpoint, and repeated behavior. ### Common uses - Investigate WAF alerts - Review credential-stuffing attempts - Triage scanning or scraping traffic - Document abuse cases before blocking ### FAQ **Can this prove an IP is in a botnet?** No. It provides enrichment and risk context. Proof requires logs, behavior, malware telemetry, or trusted threat-intelligence sources. **What should I review for a suspicious IP?** Review the IP's location, ISP, ASN, fraud score, reputation context, request behavior, timestamps, user agent, and whether similar activity appears across related addresses. **What should I save during an investigation?** Save the IP address, timestamps with timezone, request IDs, user agent, endpoint, payload category, and the reason for any action. **Should I block a suspected botnet IP immediately?** Block only when the logs show clear abuse or urgent risk. For uncertain cases, monitor, challenge, rate-limit, or use narrow temporary blocks while preserving evidence. ## ASN Lookup Canonical: https://ip.crafzo.com/asn-lookup Find ASN and network owner context for an IP address, then compare it with location, ISP, and risk signals. ASN context helps you understand the network behind an IP address, such as a residential ISP, cloud provider, university, mobile carrier, or enterprise network. ### What this tool checks - Network owner clues for security and troubleshooting - Country, city, ISP, and organization context - Useful for rate limits, firewall rules, and abuse review ### How to use it 1. Enter the public IP address you want to identify. 2. Review ASN, ISP, organization, and country fields when available. 3. Use RDAP or WHOIS for formal ownership and abuse-contact records. ### Common uses - Tell cloud traffic from residential traffic - Review API clients by network - Investigate suspicious login infrastructure - Plan narrow firewall or WAF rules ### FAQ **Is ASN the same as ISP?** Not always. ASN identifies a routing network, while ISP is often the user-facing provider or organization name. **Can ASN lookup identify a person?** No. ASN lookup identifies network infrastructure, not an individual subscriber. # IP Lookup Guides ## How to Read Server Logs and Identify Malicious Bot IPs Canonical: https://ip.crafzo.com/blog/how-to-read-server-logs-and-identify-malicious-bot-ips Published: 2026-07-21 | Updated: 2026-09-25 | 5 min read Which log fields expose automated traffic, how to group requests by IP and ASN, and when to confirm a suspect address with a reputation lookup before blocking it. ### What a bot leaves behind in a log An access log line already contains most of what you need: the client IP, timestamp, method and path, status code, response size, referrer and user agent. Automated traffic rarely hides in a single field, but it shows a pattern across several of them. Request rate is the first signal. A browser loads a page and then a burst of assets; a scraper or scanner requests page after page at a steady interval, often around the clock. Look at what is requested too. Probes for wp-login.php, xmlrpc.php, .env, phpMyAdmin, backup archives and admin paths on a site that has none of them are scanners working from a list. Scrapers add their own tells. They skip the navigation a person would follow and go straight to the pages that hold structured data, such as search results, category listings, product or profile pages and API-like endpoints, request them in numbered or alphabetical sequence, and rotate user agents while the shape and timing of the requests stay identical. Status codes tell the same story from the other side. Long runs of 404, 401 or 403 from one address mean guessing. A stream of 200 responses for HTML pages with no requests for CSS, JavaScript or images means something is fetching pages without rendering them. User agents are the weakest evidence because they are trivial to fake, but the defaults are still common: python-requests, curl, Go-http-client, empty strings, or a Chrome version several years old on every request. ### Group by IP, then by network Start by counting requests per address over a fixed window. On a Linux host this is a one-liner: extract the first column of the access log, sort it, count unique values and sort by count. The top of that list is where to look first. Distributed activity does not show up that way. A credential-stuffing run or a scraping job spread over a hosting provider produces hundreds of addresses with a few requests each. Aggregate again by /24 range and by ASN, the network that announces the address. When one hosting ASN accounts for a large share of traffic to a login or checkout endpoint, you are looking at one operation, not many users. ### Confirm before you block Take the top addresses through an IP lookup and read the results together. A hosting or datacenter classification, a VPN or Tor flag, and a presence on abuse blocklists make a strong case when they line up with aggressive paths and no asset requests. A residential ISP with one short burst is a different situation: carrier-grade NAT can place hundreds of subscribers behind one address, so blocking it punishes people who did nothing. Expect the capable operators to arrive from residential addresses. Scraping campaigns increasingly run through residential proxy networks, so a consumer ISP classification does not clear an address that acts like a scraper; the pattern still decides. Look at the spread as well: many addresses in many countries sharing one exact request pattern and timing are one operation, however ordinary each address looks on its own. Rule out the traffic you want before acting. Search engine crawlers publish their address ranges or verify through reverse DNS. Uptime monitors and security scanners you contracted announce themselves. If your site sits behind a CDN or reverse proxy, the client column may hold the proxy's address, and the real client is in the X-Forwarded-For header; blocking the proxy address blocks everyone. ### Act proportionally Match the response to the evidence. Rate limits and challenges handle most scrapers without collateral damage. Expiring blocks on a hosting range stop a scanner for the duration of its run. Reserve permanent blocks for addresses that attack repeatedly over weeks, and record why each rule exists so you can remove it later. Cooperative crawlers can be steered with robots.txt; it is the automation that ignores it that needs the limits and challenges, and the abusive patterns that keep returning that justify stronger bot detection. Log the decision alongside the evidence: the address, ASN, the signals that drove it, and the time. When a customer reports being blocked, that record is how you find and reverse the mistake quickly. ### Common mistakes Blocking on the user agent alone stops honest tools and no attackers. Blocking a CDN or proxy address takes down access for every user behind it. Permanent bans on dynamic addresses outlive the attacker and land on the next subscriber. And one burst of 404s is not an attack; a pattern of probes, failures and missing assets across time is. ### FAQ **Is a high request rate always a bot?** No. A monitoring service, a corporate proxy, a CGNAT gateway or a legitimate crawler can all produce high rates from one address. Rate is a reason to look closer, and the paths, user agents and asset pattern decide the call. **Should I block a whole ASN?** Only for hosting networks that have no business reaching your login or checkout, and with an expiry. Blocking a residential or mobile ASN cuts off real customers. **How do I tell a real Googlebot from a fake one?** Do not trust the user agent. Check that the address is in Google's published crawler ranges or that a reverse DNS lookup resolves to a googlebot.com or google.com host whose forward lookup returns the same IP. **Can scrapers use residential IPs?** Yes. Residential proxies are common in advanced scraping campaigns. **Should I block all cloud IPs?** No. Some legitimate services and integrations use cloud IPs. ### Sources - OWASP: Automated Threats to Web Applications: https://owasp.org/projects/automated-threats-to-web-applications - Cloudflare docs: Bot scores: https://developers.cloudflare.com/bots/concepts/bot-score/ ## IPv4 vs IPv6: What the Shift Means for Your Privacy Canonical: https://ip.crafzo.com/blog/ipv4-vs-ipv6-what-the-shift-means-for-your-privacy Published: 2026-07-21 | Updated: 2026-09-25 | 8 min read IPv6 gives every device a globally reachable address and rotates temporary ones. What that changes for tracking, geolocation and VPN checks compared with shared IPv4. ### Quick Answer IPv6 changes what an IP address reveals about you in two opposite ways. Without NAT, each device usually has its own globally reachable address, so a single address points at one machine rather than a whole household. At the same time, IPv6 privacy extensions rotate the device part of the address on a schedule, so the address a website sees today is unlikely to match the one it sees next week. The network prefix stays stable for as long as your ISP keeps it, which is what geolocation and ISP lookups key on. IPv6 does not encrypt anything by itself: IPsec is part of the IPv6 family of standards, but current node requirements only recommend supporting it, and almost no consumer traffic uses it. What actually protects your privacy is how your ISP assigns prefixes, whether your devices rotate temporary addresses, and whether your VPN tunnels IPv6 at all. ### Key Takeaways IPv4 usually hides many devices behind one shared address (NAT and carrier-grade NAT); IPv6 usually gives each device its own. IPv6 privacy extensions (RFC 8981, which replaced RFC 4941) generate temporary addresses that change on a schedule, typically daily, which limits long-term tracking by address alone. The first part of an IPv6 address, the prefix, identifies your ISP and often your connection; it changes only when the ISP reassigns it, so it is what lookups and geolocation use. IPsec is not mandatory in IPv6 and is not switched on for ordinary browsing. The IPv6 node requirements (RFC 8504) say nodes should support it; they do not require it, and support is not the same as use. A VPN that only carries IPv4 leaves your IPv6 address visible. Test both address families before trusting a VPN. ### How It Works IPv4 uses 32-bit addresses, about 4.3 billion in total. To stretch that pool, networks rely on Network Address Translation (NAT), which places many devices behind one public address, and many mobile and some fixed-line ISPs add carrier-grade NAT on top, so a single public IPv4 address can stand for hundreds of subscribers. That sharing is accidental privacy: a website sees the shared address, not your device, but it also means one abusive user can taint the address for everyone behind it. IPv6 uses 128-bit addresses, roughly 3.4 x 10^38 of them, so every device can have a globally unique address without NAT. A typical home receives a prefix (often a /56 or /64) from the ISP; each device then forms its own addresses inside that prefix. With stateless address autoconfiguration, the device chooses the second half of the address itself. Older implementations derived it from the hardware (MAC) address, which made a device trackable across networks; RFC 8981 privacy extensions replace that with random temporary addresses that are regenerated regularly and retired after a preferred lifetime, one day by default. When you visit a website, the server sees the address your connection uses. Under IPv4 and NAT that address represents many people, so tracking an individual by address alone is hard but not impossible when combined with cookies or fingerprinting. Under IPv6 with privacy extensions the full address changes often, which weakens address-based profiling, but the prefix persists. A tracker that keys on the /64 or /56 prefix rather than the full address can still follow a connection for as long as the ISP keeps the assignment, which for many fixed-line ISPs is weeks or months. Geolocation databases work the same way: they map prefixes to an ISP and an approximate area, so IPv6 lookups are usually no more precise than IPv4 ones and often less, because coverage is thinner. | | IPv4 | IPv6 | | --- | --- | --- | | Address size | 32-bit, about 4.3 billion addresses | 128-bit, about 3.4 x 10^38 addresses | | Notation | Dotted decimal, e.g. 203.0.113.7 | Hexadecimal groups, e.g. 2001:db8::1 | | Sharing | NAT and carrier-grade NAT put many devices behind one public address | Normally one globally reachable address per device | | How the address changes | When the ISP renews or reassigns the lease | Temporary privacy addresses rotate on a schedule; the prefix can change too | | What a lookup identifies | A household, office or NAT pool | Usually a single device's current address | | Geolocation databases | Mature, city-level estimates for most fixed lines | Thinner coverage, more often region-level | | Private and special ranges | 10/8, 172.16/12, 192.168/16, 127/8 loopback | fc00::/7 unique local, fe80::/10 link-local, ::1 loopback | ### What IPsec Does and Does Not Do IPsec is a set of protocols for authenticating and encrypting IP packets, and it was designed alongside IPv6. That history is why many articles say IPv6 "has built-in encryption". It does not, in any practical sense. RFC 8504, the current IPv6 node requirements, states that nodes SHOULD support the IPsec architecture; earlier documents used MUST, and the requirement was deliberately relaxed. Even where a device supports IPsec, nothing turns it on for web traffic. Encryption between your browser and a website comes from TLS (HTTPS), on IPv4 and IPv6 alike, and the network can still see which addresses are talking to each other either way. ### When to Use an IP Lookup Checking VPN or proxy effectiveness: look up your address before and after connecting to see whether your real IPv4 or IPv6 address is still visible. A VPN that only tunnels IPv4 leaks the IPv6 address. Confirming that privacy extensions are active: look up your IPv6 address on two different days. If the part after the prefix has changed, temporary addresses are working; if it is identical, your device may be using a stable or hardware-derived address. Troubleshooting a dual-stack network: knowing whether a connection is using IPv4 or IPv6 tells you which path to debug when a site works on one and fails on the other. Assessing geolocation exposure: compare what a lookup reports for your IPv4 and IPv6 addresses. The two often resolve to different cities because the databases behind them differ, which is a useful reminder of how approximate both are. ### Mistakes to Avoid Assuming IPv6 is automatically safer: a device with privacy extensions disabled, or a server with a static address, is more identifiable than one behind IPv4 NAT. Ignoring dual-stack leaks: many networks run IPv4 and IPv6 together. Test both, and check whether your VPN client either tunnels IPv6 or blocks it. Relying on IP geolocation for security decisions: it is approximate for both protocols and, for IPv6, often only regional. Treat it as context. Overlooking DNS: even with the address hidden, DNS queries can reveal which resolver you use and roughly where you are. Use a resolver inside the VPN tunnel or one you trust. Confusing the prefix with the address: rotating the device half of an IPv6 address does nothing about the prefix, which is what identifies your connection to trackers and to geolocation databases. Treating every new IPv6 address as a new user: this one is for site owners. With privacy extensions on, a returning device presents a fresh address every day or so, so per-address counters, bans and "new device" alerts misfire. Group activity by the /64 prefix or, better, by account and device; make sure logging, validation and rate limits handle IPv6 at all instead of carrying over IPv4-only assumptions; and read a new address as new context, not as a new person. ### How to Use Crafzo IP Lookup Crafzo shows both of your public addresses when your connection has both, together with the ISP, organization and approximate location that lookups associate with each. Open the lookup page without entering an address. Crafzo detects your public IPv4 and, where present, IPv6 address and shows them side by side in the result header. Record the baseline: note both addresses, the ISP and the reported location. This is what any website sees when you are not using a VPN. Connect your VPN and run the lookup again. Both addresses should now belong to the VPN provider. If the IPv6 address is unchanged from your baseline, the VPN is leaking IPv6; disable IPv6 in the VPN client or on the device, or choose a client that tunnels it. Repeat a day later to confirm that the IPv6 address after the prefix has rotated. If it has not, check the privacy-extensions setting on your operating system. ### FAQ **Is IPv6 more private than IPv4?** Not automatically. Privacy depends on network configuration, temporary addresses, and how services collect data. **Should websites support IPv6?** Yes. IPv6 support improves reachability for users on modern networks and carriers. **Can one device have multiple IPv6 addresses?** Yes. It is common for IPv6-enabled devices to have multiple addresses for different purposes. **Do temporary IPv6 addresses hide my location?** They can reduce address-based tracking, but they do not necessarily hide your network or region. ### Sources - RFC 4291: IP Version 6 Addressing Architecture: https://www.rfc-editor.org/rfc/rfc4291 - RFC 8981: Temporary Address Extensions for Stateless Address Autoconfiguration in IPv6: https://www.rfc-editor.org/rfc/rfc8981 - RFC 8504: IPv6 Node Requirements: https://www.rfc-editor.org/rfc/rfc8504 - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space (carrier-grade NAT): https://www.rfc-editor.org/rfc/rfc6598 ## The Difference Between a VPN, a Proxy, and a Tor Node Canonical: https://ip.crafzo.com/blog/the-difference-between-a-vpn-a-proxy-and-a-tor-node Published: 2026-07-21 | Updated: 2026-09-24 | 5 min read VPNs, proxies and Tor all put another address in front of yours, but they differ in encryption, in who can see your traffic, and in how they appear in an IP lookup. ### Three ways to put another address in front of yours When you connect directly, the website sees the public IP address your ISP assigned. A VPN, a proxy and Tor each insert a relay between you and the destination, so the destination sees the relay's address instead. That is where the similarity ends. They differ in what gets encrypted, how much of your traffic is covered, who runs the relay and can see what, and how the resulting address looks in an IP lookup. ### VPN: one encrypted tunnel for the whole device A VPN client encrypts all traffic from your device and sends it through a tunnel to a server run by the VPN provider. The server decrypts it and forwards it to the destination, which sees the server's address. Your ISP and the local network see only encrypted traffic to the VPN server. The trade-off is that the provider now sits where the ISP used to. It can see your real address and every destination, so its logging policy and jurisdiction matter. Because VPN servers live in datacenters, an IP lookup on a VPN exit typically returns a hosting or cloud ASN and, for known providers, an explicit VPN flag. The location shown is the server's registered location, which may differ from the city the provider advertises. ### Proxy: a relay for one application A proxy forwards requests on behalf of a single application or connection, usually configured in a browser, a scraper or an operating system setting. HTTP proxies handle web traffic; SOCKS proxies handle arbitrary TCP connections. Traffic that is not routed through the proxy leaves your device with your real address. A proxy adds no encryption of its own. If the connection to the destination is HTTPS, the content stays encrypted end to end and the proxy sees only the host you are connecting to; if it is plain HTTP, the proxy operator can read everything. Datacenter proxies look like hosting networks in a lookup. Residential and mobile proxies route through consumer connections, so the lookup shows an ordinary ISP or carrier, which is exactly why fraud and scraping operations pay for them. ### Tor: three relays and no single point of trust Tor wraps traffic in layers of encryption and sends it through a circuit of three volunteer relays. The entry relay sees your address but not your destination; the exit relay sees the destination but not your address; the middle relay sees neither. The destination sees the exit relay's address. Exit relays are public. The Tor Project publishes the list, so any site can recognise Tor traffic, and many treat it with suspicion or block it. Tor is slower than a VPN and traffic between the exit and a plain HTTP destination is readable by the exit operator, so HTTPS still matters. In an IP lookup, a Tor exit appears as a known Tor relay, usually with the operator's hosting ASN. ### What an IP lookup shows for each A VPN exit: a hosting or cloud organisation, frequently a VPN flag, and the server's registered city. A datacenter proxy: a hosting classification without a VPN flag, sometimes a proxy flag. A residential proxy: a consumer ISP or mobile carrier that looks like any home user, which is why detection relies on behaviour and reputation rather than the address alone. A Tor exit: a Tor flag drawn from the public relay list. | | VPN | Proxy | Tor | | --- | --- | --- | --- | | What is relayed | All traffic from the device | One application or connection | Traffic from Tor Browser or apps configured for Tor | | Encryption added | Tunnel between device and VPN server | None of its own | Three layers, one per relay | | Who sees your real IP | The VPN provider | The proxy operator | The entry relay only | | Who sees your destination | The VPN provider | The proxy operator | The exit relay only | | Speed | Close to normal | Close to normal | Noticeably slower | | How it appears in an IP lookup | Hosting network, often a VPN flag | Hosting network, or an ordinary ISP for residential proxies | A listed Tor exit relay | | Typical use | Privacy from the local network and ISP, region access | Per-app routing, testing, crawling within a provider's terms | Anonymity from observers | ### Which one fits the job Use a VPN when you want everything from a device protected from the local network and ISP, or when you need to appear in another country for a service you are entitled to use. Use a proxy when one application needs a different route, such as testing a site from another region or running a crawler within a provider's terms. Use Tor when the goal is anonymity from observers and you can accept the speed and the blocks. Whatever you choose, logging into an account identifies you to that service regardless of the address it sees. ### FAQ **Is a VPN more anonymous than Tor?** No. A VPN moves all your trust to one provider, which sees your real address and your destinations. Tor splits that knowledge across three relays operated by different people. Tor is slower and more often blocked, but it is built for anonymity; a VPN is built for privacy from your local network and ISP. **Can a website tell that I am using a VPN?** Often yes. VPN exit addresses sit in hosting ranges and on published VPN lists, and an IP lookup will show a hosting classification or a VPN flag. Smaller providers and residential exits are harder to classify. **Is a proxy encrypted?** Not by itself. A plain HTTP or SOCKS proxy relays traffic without adding encryption; only the encryption already present in the connection, such as HTTPS to the destination, protects the content. A VPN encrypts the tunnel between your device and the VPN server regardless of the application. ### Sources - Tor Project: About Tor: https://support.torproject.org/about-tor/ - Cloudflare Learning Center: What is a VPN?: https://www.cloudflare.com/learning/access-management/what-is-a-vpn/ - Tor Project: Relay Search: https://metrics.torproject.org/rs.html ## Web Scraping Without Getting Blocked: Understanding IP Trust Scores Canonical: https://ip.crafzo.com/blog/web-scraping-without-getting-blocked-understanding-ip-trust-scores Published: 2026-07-21 | Updated: 2026-09-22 | 4 min read Why sites score the IPs that hit them, which signals (datacenter ranges, blocklists, bot scores) trigger blocks, and how to keep a legitimate crawler's addresses clean. ### Quick Answer IP trust scores measure how likely an address is to be seen as abusive or suspicious by websites. Low scores lead to CAPTCHAs, throttling, or bans when scraping. Check scores before large crawls, rotate to healthy IPs, and use tools like Crafzo IP Lookup to verify reputation, geolocation, and blacklist status. ### Key Takeaways IP trust scores reflect historical abuse, blacklist listings, and proxy/VPN usage. Poor scores trigger defensive measures such as CAPTCHAs or IP bans on target sites. Pre-crawl checks and IP rotation with reputable addresses reduce block risk. Crafzo IP Lookup provides quick reputation, geolocation, and security. ### How IP Trust Scores Work Websites and security services assign a trust score to each connecting IP address by analyzing multiple signals. These signals include whether the address appears on known spam or malware blacklists, if it belongs to a data center or hosting provider, and whether it has been reported for abusive behavior such as credential stuffing or DDoS attacks. Residential IPs from legitimate ISPs usually receive higher scores, while addresses from cloud hosting ranges, VPN exit nodes, or Tor relays often score lower because they are easier to automate and abuse. The score is not a universal standard; each provider uses its own algorithm and data sources. Some services output a simple rating like "good," "moderate," or "bad," while others give a numeric value between 0 and 100. Regardless of format, the principle is the same: a lower score indicates higher risk, prompting the target site to apply stricter anti-bot measures. ### When to Use IP Trust Scores in Scraping Before launching a scraping job, especially one that will send many requests to the same domain, it is wise to sample the IP addresses you plan to use. If you are using a proxy pool, check a few addresses from each subnet to gauge their reputation. For low-volume or occasional scraping, a quick check may not be necessary, but for sustained data collection-such as price monitoring, lead generation, or content aggregation-verifying trust scores helps you avoid sudden blocks that can halt a project. You should also re-evaluate scores periodically. IP reputations can change; an address that was clean yesterday might get listed after a spam campaign. Setting up a lightweight monitoring step that pings your IP lookup service every few hours lets you rotate out deteriorating addresses before they affect your scraper. ### Common Mistakes to Avoid One frequent error is assuming that any proxy or VPN will work equally well. Free or cheap proxy lists often contain addresses with poor trust scores because they are heavily reused and quickly flagged. Relying on them without verification leads to a high rate of CAPTCHAs and bans, wasting time and bandwidth. Another mistake is ignoring the geolocation component of trust. Some sites serve different content or apply stricter rules based on the perceived location of the visitor. An IP that scores well globally may still be treated suspiciously if it originates from a country associated with high fraud rates. Use both trust score and geolocation checks to ensure compatibility with the target’s audience. Finally, many scrapers overlook the importance of request pacing. Even a high-trust IP can be throttled if it sends requests too quickly. Combine reputation checks with sensible delay patterns, randomizing intervals, and respecting the site’s robots.txt guidelines to maintain a low profile. ### Using Crafzo IP Lookup to Check Trust Scores Crafzo IP Lookup provides a straightforward way to assess an IP address before you use it in a scraper. Enter the address or a list of addresses, and the tool returns: Trust/reputation indicator - shows whether the IP is clean, moderate, or high risk based on blacklist data and usage patterns. Geolocation - country, region, and city, helping you match the IP to the target audience. VPN/Proxy detection - flags if the address is known to belong to a VPN service, data center, or residential provider. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - Cloudflare docs: Bot scores: https://developers.cloudflare.com/bots/concepts/bot-score/ - OWASP: Automated Threats to Web Applications: https://owasp.org/projects/automated-threats-to-web-applications ## Why You Got an IP Banned Error and How to Fix It Canonical: https://ip.crafzo.com/blog/why-you-got-an-ip-banned-error-and-how-to-fix-it Published: 2026-07-21 | Updated: 2026-09-22 | 4 min read The usual reasons an address gets banned: shared NAT, abuse from a neighbour, a listed range. How to confirm your reputation and what actually gets you unblocked. ### Quick Answer You see an IP banned error when a service blocks your IP address because it matches a blacklist, shows abusive patterns, or violates a geo-rule. Fix it by checking your IP’s reputation, switching networks or using a trusted VPN, contacting the site’s support, and ensuring your traffic looks legitimate. ### Key Takeaways IP bans stem from blacklist listings, abuse detection, or geographic restrictions. Verify your IP with multiple reputation sources before assuming a block. Change your network, use a reputable VPN, or request a review to lift the ban. Monitor your IP regularly with a reliable lookup tool to catch issues early. ### How IP Bans Work When you connect to a website, API, or online service, the server sees the IP address your traffic originates from. Services maintain internal blocklists or consult public DNSBLs (DNS-based Blackhole Lists) that flag IPs associated with spam, credential stuffing, scrapers, or other malicious behavior. If your IP appears on one of those lists, or if the service’s own abuse-detection system notices rapid requests, failed logins, or traffic from a high-risk region, it returns an error such as "403 Forbidden" or a specific "IP banned" message. Some platforms also enforce geographic licensing. If your IP is routed through a data center in a country where the service isn’t allowed, the connection is refused even though your address isn’t abusive. VPNs and proxies often trigger this because their exit nodes are known and catalogued. ### When to Check Your IP Status Check your IP whenever you: Receive a sudden access denied message from a site you normally use. Notice that CAPTCHAs appear more frequently than usual. Are setting up a new server, VPN, or proxy and want to confirm the address is clean. Switch between networks (home, office, mobile hotspot) and want to verify each address’s reputation. Suspect that a script or automation tool is being flagged as abusive. A quick lookup gives you insight into whether the problem is address-based or something else like account-level restrictions. ### Common Mistakes to Avoid Assuming the ban is permanent - many blocks are temporary or tied to a specific IP that will change. Ignoring blacklist results - if multiple reputable lists flag your IP, the issue is likely reputation-based, not a glitch. Using free, unreliable VPNs - low-cost services often share IPs with many users, increasing the chance of blacklisting. Continuing to send the same traffic pattern - if you keep scraping or making rapid requests after a ban, you’ll extend the block or trigger stricter rules. Overlooking ISP-level blocks - some ISPs themselves block certain ports or destinations; a lookup won’t show that, but a traceroute or port test will. ### Using Crafzo IP Lookup to Diagnose Crafzo IP Lookup provides a straightforward way to see how your address appears to the outside world. Enter your IP (or let the tool detect it) and you’ll receive: Geolocation data (country, city, ISP) to confirm whether a geo-restriction could apply. Blacklist status from major DNSBLs such as Spamhaus, Barracuda, and AbuseIPDB. Proxy/VPN detection flags that reveal if your address is associated with known anonymity networks. ASN and hosting information helpful when you need to contact the network owner about a false positive. To use it: Visit the lookup page and note the displayed IP. Review the "Reputation" tab for any blacklist hits. If a hit appears, click the link to the listing’s details page for delisting instructions. If the geo-location shows an unexpected country, consider switching networks or contacting your ISP about IP reassignment. After taking corrective steps (e.g., requesting delisting, switching to a clean network, or adjusting request rates), re-run the lookup to confirm the status is clear before retrying the blocked service. Regularly running this check-especially after network changes or when deploying new automation-helps you catch reputation issues before they lead to access problems. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - IPinfo: IP address data and lookup: https://ipinfo.io/ - Spamhaus: blocklists and IP reputation: https://www.spamhaus.org/ - AbuseIPDB: IP abuse reports: https://www.abuseipdb.com/ - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space: https://www.rfc-editor.org/rfc/rfc6598 ## Can I Change or Hide My IP Address? Practical Guide for Security-Savvy Users Canonical: https://ip.crafzo.com/blog/can-i-change-or-hide-my-ip-address Published: 2026-07-18 | Updated: 2026-09-22 | 4 min read Restarting a router, switching networks, a VPN and Tor each change the address a site sees in different ways. What works, what stays visible, and how to verify it. ### Quick Answer Yes, you can change or hide your IP address by routing your internet traffic through a VPN, proxy, Tor network, or by manually reconnecting to get a new address from your ISP. These methods replace your public IP with one from the service you use, masking your true location and helping protect privacy. Always verify the change with a reliable IP lookup tool before trusting the connection. ### Key Takeaways Changing your IP address is achievable with VPNs, proxies, Tor, or ISP-initiated renewal. Hiding your IP enhances privacy, thwarts geo-blocks, and reduces online tracking. Free proxies often lack encryption and may leak data; prefer reputable, paid services. Confirm your new IP with a trusted lookup service like Crafzo IP Lookup before relying on it. ### How It Works Your public IP address is the identifier that websites and online services see when you connect. When you use a VPN, your device creates an encrypted tunnel to a VPN server; all traffic exits that server, so the destination sees the server’s IP instead of yours. Proxies work similarly but usually lack encryption, forwarding requests through an intermediary server that presents its own IP. Tor routes traffic through multiple volunteer relays, each peeling away a layer of encryption, so the exit node’s IP is what sites see. Finally, disconnecting and reconnecting to your ISP (or releasing/renewing your DHCP lease) can sometimes give you a different address from your ISP’s pool. ### When to Use It Use IP masking when you want to: Access region-locked content such as streaming libraries or news sites. Prevent websites, advertisers, or attackers from linking your activity to your physical location. Bypass IP-based rate limits or bans while performing legitimate tasks like web scraping (respecting terms of service). Add a layer of security on public Wi-Fi by encrypting your traffic via a VPN. Test how your service appears from different geographic locations for development or SEO purposes. ### Mistakes to Avoid Relying on free web proxies for sensitive tasks; many inject ads, log data, or fail to encrypt traffic. Assuming a VPN makes you invisible; DNS leaks, WebRTC leaks, or misconfigured kill switches can expose your real IP. Ignoring the provider’s logging policy; a VPN that keeps connection logs that could be handed over to authorities. Switching IPs too frequently on services that flag rapid changes as suspicious, potentially triggering CAPTCHAs or blocks. Forgetting to verify the change; always check your IP with a lookup tool before assuming you’re masked. ### How to Use Crafzo IP Lookup Crafzo IP Lookup lets you see the IP address that the public internet sees from your current connection, along with basic geolocation and ISP details. To verify that your IP has changed: Connect to your chosen VPN, proxy, or Tor. Open your browser and go to https://ip.crafzo.com/. Note the displayed IP address, country, and ISP. Disconnect and repeat the visit to see your original ISP-assigned IP. If the addresses differ, your masking method is working. For advanced checks, use the site’s API (https://ip.crafzo.com/api/json) to retrieve JSON data that you can script into automated tests or monitoring dashboards. ### FAQ **Is it legal to change or hide my IP address?** In most jurisdictions, using a VPN, proxy, or Tor to change your IP address is legal as long as you’re not engaging in illegal activities. Some countries restrict or ban anonymity tools, so check local laws before use. Always comply with the terms of service of any website or service you access. **Will hiding my IP make me completely anonymous online?** Hiding your IP masks your location and ISP, but anonymity also depends on browser fingerprinting, cookies, login accounts, and other tracking methods. For stronger privacy combine IP masking with tracker blockers, private browsing modes, and avoid logging into personal accounts while using the hidden IP. **Can my ISP still see that I’m using a VPN or proxy?** Your ISP can see that you’re connected to a VPN or proxy server, but they cannot see the content of your traffic or the final destination sites if the connection is encrypted. Choose a provider with a strict no-logs policy and strong encryption (e.g., OpenVPN or WireGuard) to limit what the ISP can infer. ### Sources - RFC 1918: Address Allocation for Private Internets: https://www.rfc-editor.org/rfc/rfc1918 - Tor Project: About Tor: https://support.torproject.org/about-tor/ - Cloudflare Learning Center: What is a VPN?: https://www.cloudflare.com/learning/access-management/what-is-a-vpn/ ## How Does an IP Lookup Service Actually Work? Canonical: https://ip.crafzo.com/blog/how-does-an-ip-lookup-service-actually-work Published: 2026-07-18 | Updated: 2026-09-22 | 4 min read Where lookup data comes from: registry allocations, ISP announcements, geolocation databases and reputation feeds, and why different services disagree. ### Quick Answer An IP lookup service queries public and commercial data sources-WHOIS records from Regional Internet Registries, BGP routing tables, geolocation databases, and abuse blacklists-to return details about an IP address such as its owner, approximate location, connection type, and whether it appears on VPN, proxy, or threat lists. The process happens in milliseconds via an API that aggregates and normalizes these varied inputs into a single response. ### Key Takeaways IP lookup services combine WHOIS, RIR, BGP, and commercial geolocation databases to answer queries. Geolocation accuracy varies by method: city-level is common, while street-level is rare and often inferred. VPN/proxy detection relies on known data center ranges, port scans, and behavioral fingerprints. Regularly updating your blacklist sources and validating results reduces false positives in security workflows. ### How It Works When you send an IP address to a lookup service, several behind-the-scenes steps occur: WHOIS and RIR query - The service first checks the Regional Internet Registry (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC) for the IP’s registration record. This reveals the allocating organization, registration date, and contact information. BGP and ASN lookup - By examining the Border Gateway Protocol tables, the service determines the Autonomous System Number (ASN) that currently announces the IP. This tells you which network operator is routing the traffic and often hints at the business type (ISP, hosting, enterprise). Geolocation database match - Commercial providers maintain mappings of IP blocks to geographic points derived from latency measurements, user-submitted data, and infrastructure metadata. The service returns the best-fit latitude/longitude, city, region, and country. Connection-type classification - Using signals such as ASN reputation, port-scan feedback, and known data-center prefixes, the service labels the IP as residential, business, mobile, hosting, or data-center. VPN, proxy, and Tor detection - Lists of known VPN and proxy exit nodes, data-center ranges, and Tor relay IPs are consulted. Some services also run active probes (e.g., checking for open proxy ports) to improve detection. Blacklist and threat-intel check - The IP is compared against spam, abuse, malware, and fraud databases (Spamhaus, AbuseIPDB, AlienVault OTX, etc.). Any matches are returned as flags. Response assembly - All collected data is normalized into a JSON or XML payload, cached for a short period to speed repeated queries, and returned to the caller. Because each step uses a different data source with its own update frequency, the overall freshness of the result depends on how often the service refreshes its caches-typically every few minutes to a few hours. ### When to Use an IP Lookup Security monitoring - Flag logins from high-risk countries, VPNs, or known malicious IPs before granting access. Content localization - Serve language-specific pages or restrict media based on geographic licensing. Fraud prevention - Detect mismatches between billing address and IP location, or spot traffic from hosting providers often used for credential stuffing. Network troubleshooting - Identify whether a problematic address belongs to your ISP, a peer network, or a cloud provider. Compliance and auditing - Verify that data processing stays within allowed jurisdictions. ### Common Mistakes to Avoid Treating geolocation as exact - City-level data can be off by tens of kilometers; never rely on it for legal evidence alone. Ignoring stale blacklists - Abuse lists change quickly; using outdated feeds leads to both false positives and missed threats. Overlooking mobile carrier NAT - Many mobile users share a single public IP, making individual identification impossible. Assuming all data-center IPs are malicious - Legitimate services (CDNs, SaaS) operate from data centers; apply context-based scoring instead of blanket blocks. Skipping rate-limit checks - Excessive lookup calls can get you blocked by the provider; cache results whenever possible. ### Using Crafzo IP Lookup Crafzo’s IP Lookup endpoint follows the same principles described above but adds a few practical touches for developers and security teams: Unified response - Returns location, ISP, connection type, VPN/proxy flag, Tor flag, and a consolidated threat score in a single JSON object. Adjustable granularity - Choose between a lightweight “basic” ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - RFC 7020: The Internet Numbers Registry System: https://www.rfc-editor.org/rfc/rfc7020 - IANA: IPv4 Address Space Registry: https://www.iana.org/assignments/ipv4-address-space - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy - RFC 8805: A Format for Self-Published IP Geolocation Feeds: https://www.rfc-editor.org/rfc/rfc8805 ## Can You Find Someone's Address From Their IP? Canonical: https://ip.crafzo.com/blog/can-you-find-someone-s-address-from-their-ip Published: 2026-07-03 | Updated: 2026-09-22 | 4 min read An IP address points to a network and a rough area, not a street. What a lookup actually reveals, why the city can be wrong, and where the legal limits are. ### The short answer No. An IP address identifies a connection on a network, and a lookup can tell you which ISP or organisation operates that network and roughly where its customers are. It cannot tell you who the customer is or where they live. Street-level identification requires the ISP's subscriber records, and those are released only to law enforcement with a court order or equivalent process. ### What a lookup actually gives you Country is the most reliable field and is right in the large majority of cases for fixed broadband. Region and city are estimates that get worse as they get more specific. ISP, organisation and ASN describe the network operator and are usually accurate because they come from registry records rather than guesses. Connection type, proxy, VPN and hosting flags describe the kind of network, not the person on it. The latitude and longitude that come with a city result are the centre of the area the database associates with that range. Several databases place unknown locations at a country's geographic centre, which is how ordinary homes near such points have ended up receiving visits from people who trusted the coordinates. ### Why the city is often wrong Mobile carriers route traffic through gateways that may be in another city or another state, so a phone user appears wherever the gateway is. Carrier-grade NAT puts hundreds of subscribers behind one address. VPNs and proxies place the user wherever the exit server is registered. Business networks are frequently registered at a head office while the traffic comes from a branch. Databases also lag behind reallocations, so a range that moved to a new ISP can show its old home for months. ### How investigators actually do it Law enforcement pairs an IP address with an exact timestamp and serves the ISP with legal process. The ISP looks up which subscriber held that address at that moment and returns account details. Without the timestamp the request is meaningless on dynamic networks, and without the legal process the ISP does not answer. There is no shortcut around this for a private person, and services that promise one are selling the same approximate geolocation as everyone else. ### What you can legitimately do Find the network operator with a WHOIS or RDAP lookup and use its abuse contact to report harassment, spam or attacks; the operator can act on its own subscriber. Use the address as context in a fraud or security review alongside account history and behaviour. Keep the result in proportion: a match between an address's estimated city and someone's claimed location is weak evidence, and a mismatch is weaker still. Do not use an approximate location to confront anyone or to publish where you think they live. Being wrong is likely, and being right does not make it lawful. ### FAQ **Can I get a street address from an IP address?** No. Geolocation databases map address ranges to areas, not to buildings, and the mapping is often a city or region wide. The subscriber behind an address is known only to the ISP. **What do the latitude and longitude in a lookup mean?** They are the centre point of the area the database associates with the range, sometimes just the centre of a city or a country. They do not indicate a house, and precision in the decimals does not mean precision on the ground. **Is it legal to look up someone's IP address?** Looking up a public address is legal in most places; it is public network information. Using the result to harass, stalk or dox someone is not, and that is where the law applies. ### Sources - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy - Electronic Frontier Foundation: Online privacy: https://www.eff.org/issues/online-privacy ## Best Free IP Lookup Tools: Which One Should You Use? Canonical: https://ip.crafzo.com/blog/best-free-ip-lookup-tools-which-one-should-you-use Published: 2026-06-23 | Updated: 2026-09-22 | 4 min read Compare top free IP lookup services for geolocation, VPN detection, blacklist checks, and security insights. Find the right tool for your needs. ### Quick Answer Choose a free IP lookup tool based on what you need: basic geolocation from sites like IPinfo.io or WhatIsMyIPAddress.com, VPN/proxy detection from IP2Location’s free demo, and blacklist checks from AbuseIPDB or Spamhaus. For a single dashboard that combines location, ISP, threat intel, and API access, try Crafzo IP Lookup. Cross-check at least two services to avoid blind spots. ### Key Takeaways Free tools differ in depth-some focus on location, others on threat data. Use multiple services together for a complete view (geolocation, ISP, VPN/proxy, blacklist). Never rely on one source for security-critical decisions; verify with a second lookup. Crafzo IP Lookup provides a unified interface and optional developer API. ### How IP Lookup Works An IP lookup service queries public registration databases (RIR WHOIS records) and proprietary reputation feeds to return details about an address. The process typically involves: WHOIS lookup - pulls registration info such as the allocating RIR, ISP, and registration dates. Geolocation databases - map IP ranges to physical locations using data from ISPs, mobile carriers, and user-submitted sources. Threat intelligence feeds - check the IP against lists of known spammers, malware hosts, botnet C2 servers, and VPN/Tor exit nodes. Connection classification - flags whether the IP belongs to a data center, residential ISP, corporate network, or mobile carrier. These steps happen in milliseconds, and the results are presented as a simple web page or JSON response for API users. ### When to Use an IP Lookup Tool Investigating suspicious traffic - locate the source of odd login attempts or port scans. Verifying VPN or proxy use - confirm whether a visitor is masking their true IP. Checking email sender reputation - see if the sending IP appears on spam blacklists before accepting a message. Network troubleshooting - identify the ISP or organization responsible for a routing issue. Content localization - serve language-specific pages based on a visitor’s country. In each case, start with a free tool for a quick answer, then escalate to a paid source if you need deeper historical data or SLAs. ### Common Mistakes to Avoid Assuming geolocation is exact - city-level data can be off by tens of kilometers; treat it as an approximation. Ignoring VPN/proxy flags - an IP may appear legitimate but actually be a relay; always check the anonymity status. Relying on a single blacklist - different lists have different criteria; an IP clean on one may be listed on another. Using outdated data - free sites sometimes update weekly; for fast-moving threats, refresh more often or use a service with real-time feeds. Overlooking IPv6 - many tools still focus on IPv4; ensure your lookup supports both address families if your network uses IPv6. ### Using Crafzo IP Lookup Crafzo IP Lookup brings together the most useful free data streams into one interface. To get started: Visit the Crafzo IP Lookup page and enter the IP address you want to check. The results pane shows: Location - country, region, city, latitude/longitude, and accuracy radius. ISP/Organization - name, ASN, and connection type. Threat intel - blacklist status from AbuseIPDB, Spamhaus, and known VPN/Tor exit nodes. API access - a free tier key for developers who need automated lookups. For repeated checks, copy the provided cURL example or integrate the REST endpoint into your scripts. If you need higher request volumes or historical data, consider upgrading to the paid plan, which adds daily updated feeds and SLA guarantees. The tool is designed for both quick manual checks and programmatic use, making it a practical first stop for security analysts, network admins, and developers. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. **Is a free IP lookup tool enough for security?** It is useful for checks and investigations, but production systems need integrated controls and logging. **What IP formats should a tool support?** It should support both IPv4 and IPv6. ### Sources - IANA: IPv4 Address Space Registry: https://www.iana.org/assignments/ipv4-address-space - ARIN WHOIS/RDAP search: https://whois.arin.net/ui/ - RIPE Database query (WHOIS): https://apps.db.ripe.net/db-web-ui/query - APNIC WHOIS search: https://wq.apnic.net/static/search.html - AbuseIPDB: IP abuse reports: https://www.abuseipdb.com/ - Spamhaus: blocklists and IP reputation: https://www.spamhaus.org/ - IP2Location: free lookup demo: https://www.ip2location.com/demo - IPinfo: IP address data and lookup: https://ipinfo.io/ - WhatIsMyIPAddress: public IP lookup: https://whatismyipaddress.com/ ## How Accurate Are IP Address Location Lookups? Canonical: https://ip.crafzo.com/blog/how-accurate-are-ip-address-location-lookups Published: 2026-06-23 | Updated: 2026-09-25 | 4 min read Country-level results are usually right; city-level results depend on the ISP, mobile carriers and VPNs. What accuracy to expect and how to sanity-check a result. ### Accuracy by level Think of an IP location result as a set of nested estimates. Country is the strongest: address blocks are allocated to organisations in a specific country and rarely cross borders in use, so country results are right for the large majority of fixed broadband connections. Region or state is next, usually correct but not always. City is an estimate that is often right for cable and fibre customers in dense areas and often wrong elsewhere. Coordinates are the weakest field of all: they mark the centre of the area the database chose, not the device. Providers that publish their own accuracy figures make the same point in numbers. MaxMind, whose databases many lookup tools use, reports high country-level accuracy and materially lower city-level accuracy, and its figures differ by country and by whether the connection is fixed, mobile or business. ### Where the data comes from Nobody measures your device. Geolocation databases are built from several indirect sources. Regional Internet Registries record which organisation holds each block and where that organisation is based. ISPs can publish geofeeds, a standard format defined in RFC 8805 that states where their ranges are used. Providers add latency measurements from many vantage points, partner data, and corrections submitted by users and network operators. Each source is approximate in its own way, and the database is a best guess that reconciles them. ### What makes a result wrong Mobile networks are the most common cause. A phone's traffic exits at a carrier gateway that can be hundreds of kilometres away, and every user behind that gateway appears to be there. Carrier-grade NAT, used by mobile and many fixed ISPs, puts many subscribers behind one address. VPNs and proxies move the apparent location to the exit server. Business and university networks are often registered at a headquarters while traffic comes from branches. Satellite services route through ground stations. And databases lag: when a block is reassigned to a new ISP or a new region, the old location can persist until the next update cycle. ### How to sanity-check a result Compare two independent providers; agreement on the city is reassuring, disagreement means treat it as regional. Read the ISP and connection type before the city: a mobile carrier or a hosting provider tells you the city field is not describing a home. Check whether the time zone in the result matches the region shown. Look at the region and country rather than the city when they disagree with expectations. And treat coordinates as the centre of a circle whose radius you do not know. ### Using the result responsibly City-level geolocation is well suited to localisation, currency and language defaults, regional pricing, fraud context and troubleshooting where a rough location is enough. It is not suited to identifying a person, enforcing a precise boundary on its own, or deciding that a user is lying because the city differs from what they said. Read it as network context and combine it with other signals before acting. City data earns its place as context. It helps spot a login that appears far from where an account is normally used, it localises content and pricing, and it explains traffic patterns in analytics. When a decision has consequences for a user, pair the city with stronger evidence, such as login history, device consistency and a [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) for the address, rather than acting on the city alone. ### FAQ **Can an IP lookup find an exact address?** No. The most specific honest answer is a city or postal area, and even that is an estimate. No IP geolocation database knows which building an address is used in. **Why does my own IP show a different city?** Your traffic exits your ISP's network at a gateway that may be far from you, mobile carriers concentrate users at a few gateways, and databases update slowly after ranges are reassigned. A VPN or proxy moves the apparent location to its exit server. **Which level is the most accurate?** Country. Providers that publish accuracy figures report country results as close to certain for fixed broadband, with region and city correct less often and with wide variation between countries and network types. **Can IP lookup find my exact address?** No. It usually estimates network location such as city or region. **Why is country more reliable than city?** Country-level network assignment is generally easier to infer than exact city routing. ### Sources - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy - RFC 8805: A Format for Self-Published IP Geolocation Feeds: https://www.rfc-editor.org/rfc/rfc8805 ## How Do I Check My Own IP Address? Canonical: https://ip.crafzo.com/blog/how-do-i-check-my-own-ip-address Published: 2026-06-23 | Updated: 2026-09-25 | 5 min read Three ways to see the public address websites receive, why it differs from your router's private address, and what an IPv6 result means. ### The quickest way Open an IP lookup and read the address it shows. That is the public address your connection presents to every website you visit, and the lookup adds the ISP, organisation and approximate location that go with it. If you use this site's lookup with the Use my IP action, you will also see whether an IPv4 address, an IPv6 address or both are in use. ### Public versus private addresses Your devices and your router talk to each other with private addresses from ranges reserved for that purpose, most commonly 192.168.x.x, 10.x.x.x and 172.16 to 172.31. These are defined in RFC 1918 and never appear on the internet. Your router translates between them and the single public IPv4 address your ISP assigned to the connection, which is why every device on your Wi-Fi shows the same public IPv4 address. The address printed by your operating system is almost always the private one. On Windows, ipconfig shows it; on macOS and Linux, ifconfig or ip addr do. The public address lives on the router's WAN interface, visible in the router's admin page, or through any service that echoes the address it received. ### Checking from the command line If you prefer a terminal, request a service that returns the address it saw. For example, fetching https://api64.ipify.org returns your IPv6 address when you have one and your IPv4 address otherwise, and https://api.ipify.org returns the IPv4 address only. Comparing the two tells you whether your connection is dual-stack. ### Why the result changes Most home connections get a dynamic address that the ISP can renew or reassign, so the public IPv4 address changes occasionally without any action from you. Switching from Wi-Fi to mobile data moves you to a carrier network with a different address. A VPN replaces the address with its exit server's. On IPv6, privacy extensions rotate the device's temporary address on a schedule, so the IPv6 result can differ from day to day even when nothing else changed. ### IPv4 and IPv6 results If your ISP provides IPv6, your connection has two public identities. Websites that support IPv6 will see the IPv6 address; the rest see IPv4. Both are legitimate, both are yours, and a lookup on each may show slightly different location data because they come from different address blocks. The IPv6 address is generally specific to one device, whereas the IPv4 address is shared by the whole household behind the router. ### What to do with the address Use it to confirm a VPN is active before doing something sensitive, to check whether an access rule or allowlist contains the right address, to see whether your address carries a reputation problem when a site blocks you, and to understand why a service thinks you are in another city. The same lookup tells you whether a proxy is leaking your real address (the result should show the proxy's address and location, not your ISP's) and whether your ISP has quietly reassigned your connection since you last looked, which matters when an allowlist somewhere still holds the old value. It is worth making the check a habit after any change to your network: a new router, a new VPN client, a change of ISP, or IPv6 being switched on. It takes a few seconds, needs nothing beyond a browser or a terminal, and catches the surprise before a blocked login or a failed allowlist does. ### FAQ **Why is my IP address different on my phone and my laptop?** On the same Wi-Fi they share one public IPv4 address, but each device usually has its own public IPv6 address. On mobile data the phone uses the carrier's network and a completely different address. **Is my IP address secret?** No. Every website and service you connect to receives it; that is how responses reach you. It is not secret, but it does tie your traffic to your ISP account, which is why privacy tools replace it. **Why does the location shown for my IP look wrong?** IP geolocation estimates where your ISP's gateway is, not where you are. Mobile carriers and large ISPs route traffic through gateways that can be far away, and databases update slowly. **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - RFC 791: Internet Protocol: https://www.rfc-editor.org/rfc/rfc791 - RFC 1918: Address Allocation for Private Internets: https://www.rfc-editor.org/rfc/rfc1918 - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## Is It Illegal to Look Up Someone's IP Address? Canonical: https://ip.crafzo.com/blog/is-it-illegal-to-look-up-someone-s-ip-address Published: 2026-06-23 | Updated: 2026-09-22 | 4 min read Looking up a public IP address is legal almost everywhere; what you do with the result is where the law applies. Where research ends and harassment begins. ### Quick Answer Looking up an IP address is not illegal in itself when the address is publicly visible or you have a legitimate reason, such as network security or abuse prevention. Problems arise only when the information is used to harass, stalk, commit fraud, or otherwise violate laws or service terms. ### Key Takeaways Public IP addresses can be queried legally for informational or security purposes. Misusing IP data for intimidation, doxxing, or unauthorized access breaks the law. Always check the terms of service of any IP lookup tool you use. Crafzo IP Lookup delivers accurate, compliant data for developers and security teams. ### How IP Lookup Works Every device connected to the internet has an IP address that routers use to route traffic. When you visit a website, send an email, or use an app, your public IP is visible to the remote server. IP lookup services query public databases-like regional internet registries (RIRs) or commercial geolocation providers-to return details such as the associated organization, approximate location, and whether the address appears on known threat lists. These services do not hack or break into systems; they aggregate information that is already published or licensed for redistribution. The accuracy varies: geolocation is often city-level, while ownership data reflects the ISP or hosting provider that received the address block from IANA. ### When to Use IP Lookup Security monitoring: Spot suspicious login attempts, brute-force attacks, or traffic from known malicious networks. Abuse prevention: Identify sources of spam, comment fraud, or credential stuffing to block or challenge them. Network troubleshooting: Verify that traffic is routing correctly or diagnose connectivity issues with partners or cloud services. Compliance checks: Ensure users are not connecting from sanctioned regions when your service has geographic restrictions. Content localization: Serve language or regional variants based on the visitor’s general location (city-level). In each case, the goal is to protect your systems, improve user experience, or meet regulatory obligations-not to identify or harass an individual. ### Mistakes to Avoid Assuming pinpoint accuracy: IP geolocation rarely gives an exact street address; treating it as such can lead to false accusations. Ignoring rate limits: Over-aggressive querying can get you blocked by the lookup provider or violate their acceptable-use policy. Using data for stalking or doxxing: Publishing someone’s IP with intent to intimidate is illegal in many jurisdictions and may violate anti-harassment statutes. Overlooking consent: If you collect IPs from users for analytics, disclose this in your privacy policy and offer opt-out where required. Relying on outdated lists: Threat intelligence feeds change frequently; stale blacklists can cause false positives or miss new threats. ### How to Use Crafzo IP Lookup Crafzo IP Lookup is built for developers, security analysts, and IT teams who need reliable, fast responses without legal guesswork. The service provides: Geolocation: Country, region, city, latitude/longitude (city-level accuracy). Ownership: ISP or hosting organization, ASN, and registration details. Threat intel: Indications if the IP appears on malware, botnet, or spam blacklists. VPN/Proxy detection: Flags that help you spot anonymized traffic. To integrate, simply make an HTTPS GET request to the API endpoint with the target IP as a parameter. The response is JSON, making it easy to feed into firewalls, SIEMs, or application logic. All queries are logged for audit purposes, and the service’s terms prohibit using the data for harassment, illegal surveillance, or any activity that violates local laws. Because Crafzo sources its data from licensed providers and public registries, you can trust that the information is redistributable for legitimate security and operational uses. Always pair the lookup with your own policy review-if you’re unsure whether a particular use case is permitted, consult your legal counsel or data protection officer. ### FAQ **Can I get in trouble for checking an IP address that appears in my server logs?** No. Reviewing IPs that connect to your own systems for security or troubleshooting is a legitimate, lawful use of IP lookup. **Is it illegal to use an IP geolocation service to find someone's approximate location?** Generally not if the data is publicly available and you use it for legitimate purposes like fraud prevention or network diagnostics. **Does using a VPN or proxy to hide my IP make looking up others' IPs illegal?** No. The legality of an IP lookup depends on how you use the information, not on whether you hide your own address. ### Sources - RFC 791: Internet Protocol: https://www.rfc-editor.org/rfc/rfc791 - Wikipedia: IP address: https://en.wikipedia.org/wiki/IP_address - Electronic Frontier Foundation: Online privacy: https://www.eff.org/issues/online-privacy ## What Information Can People See From Your IP Address? Canonical: https://ip.crafzo.com/blog/what-information-can-people-see-from-your-ip-address Published: 2026-06-21 | Updated: 2026-09-25 | 6 min read Your IP reveals an ISP, an approximate area and whether you use a VPN or proxy. It does not reveal your name or street. What is exposed, and to whom. ### Quick Answer Your IP address reveals the geographic area (usually city or region) linked to your Internet Service Provider, the ISP or organization that assigned the address, and whether the address is associated with a VPN, proxy, Tor exit node, or hosting service. It can also appear on public blacklists if it has been flagged for spam, malware, or abusive activity. No exact street address or personal name is exposed directly through the IP alone. ### Key Takeaways Your IP shows approximate geographic location and the ISP or organization that assigned it. It can indicate whether you are using a VPN, proxy, or Tor exit node. Public blacklists may flag an IP for spam, malware, or abusive behavior. Using a trusted IP lookup tool helps you see what others can observe and take action if needed. ### How IP Address Information Works An IP (Internet Protocol) address is a numeric label assigned to each device connected to a network that uses the Internet Protocol for communication. IPv4 addresses look like four decimal numbers separated by dots (e.g., 192.0.2.1), while IPv6 uses longer hexadecimal groups. When you visit a website, your browser includes the source IP in the request headers so the server knows where to send the response. Because IP addresses are allocated in blocks to ISPs, corporations, or data centers, public WHOIS and geolocation databases can map an address to the organization that received the block and, often, to the city or region where that block is commonly used. These mappings are not exact; they rely on registration data and aggregated user-location signals. Services that offer IP lookup combine several data sources: WHOIS/RIR records - show the registering entity (ISP, hosting provider, university). Geolocation databases - estimate latitude/longitude based on aggregated latency, user-submitted data, and infrastructure mapping. Proxy/VPN detection lists - flag addresses known to belong to VPN services, proxies, Tor exit nodes, or hosting platforms. Blacklist feeds - collect reports of spam, malware, brute-force attempts, or other abusive behavior from mail servers, security firms, and community projects. When you perform an IP lookup, the tool queries these sources and returns a consolidated view of what a remote server could infer about your connection. ### When to Use IP Lookup Tools Checking your IP is useful in several everyday and professional scenarios: Troubleshooting connectivity - If a service blocks you, an lookup can show whether your IP appears on a spam or abuse list. Verifying VPN or proxy performance - Confirm that the IP you see matches the expected VPN endpoint and is not leaking your real address. Assessing online privacy - See what a website could learn about your approximate location and provider before deciding to use additional privacy measures. Managing server reputation - Mail administrators routinely check their sending IPs against blacklists to maintain deliverability. Investigating suspicious activity - When reviewing logs, an IP lookup can quickly tell you whether an address belongs to a known data center, residential ISP, or anonymity network. ### Common Mistakes to Avoid Assuming exact location - Geolocation is often accurate to the city level but can be off by dozens of miles, especially with mobile carriers or large ISPs that route traffic through central hubs. Trusting a single source - Different geolocation providers may disagree; cross-checking with two or three tools gives a more reliable picture. Ignoring IPv6 - Many lookup tools default to IPv4. If your network uses IPv6, be sure to query that address separately, as the information can differ. Overlooking proxy headers - Some websites detect the original IP via headers like X-Forwarded-For. A lookup of the visible IP may not reveal the true client IP if those headers are present. Believing blacklist status is permanent - Listings can be outdated or erroneous. Follow the delisting process of the specific blacklist if you believe your IP is incorrectly listed. ### How to Use Crafzo IP Lookup Crafzo shows you what a website can see about your connection, using the same kind of data websites buy from geolocation and reputation providers. Open the homepage. With nothing entered, the page detects your public IPv4 address and, where your connection has one, your IPv6 address, and shows them side by side. Read the location panel. It shows the country, region and city that geolocation associates with the address, with a dot map. This is where the network is registered or routed, not where you are standing; the page says so, and a mobile or corporate connection can be off by a city or a country. Read the network panel. ISP, organization and ASN tell you which provider holds the address block. This is the part that is genuinely visible to every site you visit and is what abuse reports and legal requests are addressed to. Read the signals. VPN, proxy, Tor and hosting show whether your connection looks like an ordinary consumer line or like an anonymizer; the [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) shows how the address's reputation reads to a site's risk system. Each card names the provider that reported it. Repeat with your VPN on. If the addresses, location and ISP now belong to the VPN provider, the tunnel is working; if your IPv6 address is unchanged, it is leaking. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. **Can someone find my house from my IP address?** Usually no. A normal IP lookup may estimate a city or ISP region, but it does not provide a street address or apartment number. **Does my IP address reveal my name?** No, an IP address does not directly show your name to ordinary websites or lookup tools. Your ISP may know which subscriber used an address at a specific time, but that information is not public lookup data. **How can I reduce what my IP reveals?** You can use a reputable VPN, Tor, or a privacy-focused proxy to change the IP address websites see. Also limit tracking cookies and avoid staying logged in when you want less activity tied to your identity. ### Sources - Electronic Frontier Foundation: Online privacy: https://www.eff.org/issues/online-privacy - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## Can Someone Find My Location From My IP Address? Canonical: https://ip.crafzo.com/blog/can-someone-find-my-location-from-my-ip-address Published: 2026-06-20 | Updated: 2026-09-22 | 4 min read A public IP address usually resolves to a city or region, not a home. How close geolocation gets, who can see your IP, and what actually hides it. ### What your IP address reveals Your public IP address tells an observer which ISP or mobile carrier you use and roughly where that network's customers are. A lookup will show a country with confidence, a region with less, and a city as an estimate that is frequently wrong. It also reveals whether the address belongs to a hosting provider, a VPN or a consumer network. It does not reveal your name, your account, or your street. ### Who can see it Every website and app server you connect to receives your address, because that is how the response finds its way back. So does anyone you connect to directly: peers in online games and some video-call apps, other participants in a torrent swarm, and the owner of any link built to log the addresses of visitors. Email is mixed: many providers strip the sender's address from headers, but some clients and self-hosted setups leave it in. ### How close it gets On a fixed home connection the estimate is often the right city or a neighbouring one. On mobile data it is frequently the city of the carrier's gateway rather than yours. Behind carrier-grade NAT, you share the address with many other subscribers, so it points to a group rather than a person. The only party that can connect the address to you is your ISP, and it releases that information only in response to legal process. ### The real risks The address alone does not bring anyone to your door. The risk is what it enables in combination with other information. A harasser who already knows your name and city can use an address to confirm the city. Someone with your address can send a flood of traffic at a home connection and knock it offline for a while, which is a known problem for streamers and competitive gamers. Scammers use the estimated location to make a message look local. Treat the address as one piece of information worth limiting, not a secret whose exposure is a disaster. ### How to reduce exposure A VPN replaces your address with the provider's for everything on the device; Tor does the same through volunteer relays with stronger anonymity and lower speed. For games and calls, prefer services that route through their own servers rather than connecting peers directly. Do not open links from people you do not trust, especially shortened ones. If your ISP offers it, enable IPv6 privacy extensions so your device's address rotates. And check what your address currently reveals with a lookup; if it shows a hosting network or a VPN when it should not, or a city far from you, you have learned something about your connection. ### FAQ **Can the police find my location from my IP address?** With legal process, yes. They ask your ISP which subscriber held the address at a given time, and the ISP answers from its records. Private individuals and companies cannot do this. **Does a VPN hide my location?** From the websites and services you use, yes: they see the VPN server's address and location. The VPN provider itself sees your real address, so choose one whose logging policy you trust. **Can someone find my home address from my IP?** No. Geolocation places an address in an area, often the wrong one. The coordinates some tools show are the centre of that area, not a building. **Can police track an IP to an exact address?** Law enforcement may request subscriber information from an ISP through legal channels. The public IP lookup itself does not show the exact address. **Can hackers find my home from my IP?** A normal attacker cannot get your home address from an IP lookup alone. They may infer an approximate city or provider, but exact identity requires other data sources. **How accurate is IP location?** Country-level results are often useful, while city-level results vary much more. VPNs, mobile routing, shared networks, and stale databases can all reduce accuracy. ### Sources - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy - Electronic Frontier Foundation: Online privacy: https://www.eff.org/issues/online-privacy ## How to Find Someone's IP Address: A Simple Guide Canonical: https://ip.crafzo.com/blog/how-to-find-someone-s-ip-address-a-simple-guide Published: 2026-06-20 | Updated: 2026-09-24 | 5 min read Where IP addresses legitimately show up (email headers, server logs, game hosts), how to look one up, and the limits of what the result can tell you. ### Quick Answer You can find someone's IP address by checking server logs, email headers, or using an online IP lookup tool that takes a domain, email, or known IP and returns geolocation, ISP, and threat data. These tools query public databases and return the information in seconds. ### Key Takeaways IP addresses show network and approximate location, not personal details. Use lookups for security, troubleshooting, or verifying anonymity services. Avoid treating IP data as precise location or legal proof. Crafzo IP Lookup offers free, fast checks with VPN/proxy and blacklist insights. ### How IP Lookup Works Every device connected to the internet gets an IP address from its Internet Service Provider (ISP). This address is part of a global routing system managed by regional registries like ARIN, RIPE, and APNIC. When you run an IP lookup, the tool queries these registries and other public databases to retrieve the registered owner, approximate geographic location, and any associated abuse reports. Some services also cross-check the address against known VPN, proxy, or Tor exit node lists and spam blacklists. The process is passive: you provide an IP or a domain that resolves to an IP, and the tool returns what is already publicly available. No packet is sent to the target device, and the lookup does not notify the IP holder. ### When to Use an IP Lookup IP lookup is helpful in several everyday scenarios: Security monitoring: Spot unexpected login locations or detect traffic from known malicious networks. Troubleshooting: Verify why a service blocks a user or why a website shows incorrect regional content. Privacy checks: Confirm that your VPN or proxy is effectively masking your real IP. Abuse investigation: Provide evidence to an ISP or hosting provider when dealing with spam, hacking attempts, or harassment. It is not a substitute for legal process; law enforcement must follow proper channels to obtain subscriber details from an ISP. ### Common Mistakes to Avoid Assuming exact location: An IP may only point to the ISP’s nearest hub, which could be dozens of miles away. Relying on a single check: IP addresses can change, especially for mobile or residential users on dynamic plans. Ignoring VPN/proxy flags: A lookup might show a data center IP; without checking for VPN use you could misjudge the user’s true location. Using outdated databases: Some free tools update their geolocation or blacklist data infrequently, leading to stale results. Always treat IP data as a starting point, not definitive proof. ### Using Crafzo IP Lookup Crafzo IP Lookup is built for quick, reliable checks. To use it: Visit the lookup page and paste the IP address, domain, or email header you want to investigate. Click “Lookup”. The tool returns: Geolocation: Country, region, and city based on the IP’s registration. ISP and organization: The company that assigned the address. VPN/Proxy detection: Whether the address belongs to a known privacy service. Blacklist status: Checks against common spam and abuse lists. Review the results and, if needed, run a reverse DNS check to see any hostnames tied to the IP. The lookup needs no account and keeps no history of the addresses you check. It is built for looking at one address at a time; for repeated or bulk checks you would use a geolocation provider's API in your own tooling. ### FAQ **Is it legal to look up someone else's IP address?** Looking up an IP address that is publicly visible, such as from a server log or email header, is generally legal. However, using that information to harass, stalk, or gain unauthorized access to systems is illegal and violates privacy laws in many jurisdictions. **Can an IP address reveal a person's exact home address?** No. An IP address typically points to the ISP or organization that assigned it, giving only a rough geographic area like a city or region. Precise street-level location requires additional data that ISPs do not disclose publicly. **Does using a VPN hide my real IP address from lookup tools?** Yes. When you connect to a VPN, your traffic appears to come from the VPN server's IP address, masking your actual IP. Lookup tools will show the VPN's location and may flag the address as belonging to a known VPN or proxy service. **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - ARIN: American Registry for Internet Numbers: https://www.arin.net/ - RIPE NCC: Regional Internet Registry for Europe, the Middle East and Central Asia: https://www.ripe.net/ - APNIC: Regional Internet Registry for the Asia Pacific: https://www.apnic.net/ - WhatIsMyIPAddress: public IP lookup: https://whatismyipaddress.com/ - IPinfo: IP address data and lookup: https://ipinfo.io/ ## What Is an IP Address and Why Should I Care? Canonical: https://ip.crafzo.com/blog/what-is-an-ip-address-and-why-should-i-care Published: 2026-06-20 | Updated: 2026-09-25 | 6 min read An IP address is how the internet routes traffic to your connection. Public vs private addresses, IPv4 vs IPv6, and why the address matters for security. ### Quick Answer An IP address is a numeric label assigned to each device connected to a computer network that uses the Internet Protocol for communication. It serves two main purposes: identifying the host or network interface and providing the location of the device in the network so that data can be routed correctly. Understanding your IP address helps you troubleshoot connectivity, assess privacy risks, and use security tools effectively. ### Key Takeaways An IP address uniquely identifies a device on a network and enables routing of data. IPv4 uses 32-bit dotted decimal notation; IPv6 uses 128-bit hexadecimal groups. IP lookup tools reveal geolocation, ISP, proxy/VPN status, and blacklist listings. Never rely solely on an IP address for identity; combine it with other signals for security decisions. ### How IP Addresses Work IP addresses function like postal addresses for the internet. When you send a request-say, loading a webpage-your device includes its source IP address in the packet header. Routers read the destination IP address and forward the packet hop by hop until it reaches the target network. The protocol comes in two versions: IPv4, the original design, uses four decimal numbers separated by dots (e.g., 203.0.113.45). Each number ranges from 0 to 255, giving roughly 4.3 billion unique addresses. Because the pool was exhausted, IPv6 was introduced. IPv6 writes eight groups of hexadecimal digits separated by colons (e.g., 2001:0db8:85a3:0000:0000:8a2e:0370:7334). This format provides an astronomically larger address space, simplifies routing, and includes built-in support for security features like IPsec. Addresses are allocated hierarchically. The Internet Assigned Numbers Authority (IANA) distributes large blocks to Regional Internet Registries (RIRs) such as ARIN for North America or RIPE NCC for Europe. RIRs then allocate smaller blocks to Internet Service Providers (ISPs), enterprises, and other organizations. Your ISP assigns you either a dynamic address that may change periodically or a static address that remains constant. ### What Your Own IP Address Says About You The address your connection presents to the internet is public by design: every website, app and API you use receives it so that responses can find their way back. On its own it reveals an approximate location (usually a country, a region and a city-sized area), the ISP or organization that holds the address, and the connection type, such as home broadband, a mobile carrier, a business network or a hosting provider. It does not reveal your name, your street address or the private details of the device you are using, and it is normally shared: every device behind the same home or office router presents the same public IPv4 address. People look up their own address for practical reasons: to confirm that a VPN or proxy is actually in use, to work out why a service is blocking or misplacing them, to see which address a server presents, or to make sense of an unusual-login alert. Site owners and developers run the same lookup in the other direction, to see whether a visitor arrives from a residential network, a data center, a proxy or an address with a poor reputation. Checking is simple: an IP lookup shows the address the site received, together with the ISP and location that go with it, and you can enter any other valid IPv4 or IPv6 address to see what it reveals. If you use a VPN or proxy, compare the result with and without the tunnel active; both the address and the location should change. The [guide to checking your own IP address](https://ip.crafzo.com/blog/how-do-i-check-my-own-ip-address) covers the command-line and router-side methods as well. ### When to Use IP Lookup IP lookup tools are valuable in several practical scenarios: Geolocation - Determine the approximate country, region, and city of an IP address. This helps content providers serve localized language or pricing, and it assists investigators in tracing the origin of suspicious traffic. VPN and Proxy Detection - Many lookup services flag whether an address belongs to a known VPN, proxy, or Tor exit node. This information is useful for fraud prevention, access control, and compliance with geographic licensing restrictions. Blacklist and Reputation Checks - Tools compare an IP against databases of spam sources, malware distribution points, or abusive behavior. If an address appears on a list, you might block it from commenting on your site, reject its email connections, or require additional authentication. Network Troubleshooting - When a service is unreachable, checking the IP address of the problematic host can reveal routing issues, ISP-level blocks, or misconfigured firewalls. Security Monitoring - Security teams correlate IP addresses with login attempts, malware callbacks, or data exfiltration events to build a timeline of malicious activity. ### Common Mistakes to Avoid Assuming geolocation is exact - IP-based location is often accurate to the city level but can be off by dozens of miles, especially with mobile carriers or large ISPs that route traffic through central hubs. Treating an IP as a permanent identity - Dynamic IP addresses change over time, and multiple users may share the same address via NAT or carrier-grade solutions. Relying solely on IP for authentication can lead to false positives that lock out legitimate users, and to false negatives when an attacker sits behind a familiar address. Treat the address as one signal among several. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. **Is my public IP the same on every device?** Devices behind the same home or office router often share one public IP address. ### Sources - RFC 791: Internet Protocol: https://www.rfc-editor.org/rfc/rfc791 - RFC 1918: Address Allocation for Private Internets: https://www.rfc-editor.org/rfc/rfc1918 - RFC 4291: IP Version 6 Addressing Architecture: https://www.rfc-editor.org/rfc/rfc4291 ## Credential Stuffing IP Intelligence: Detect Attacks with IP Lookup Canonical: https://ip.crafzo.com/blog/credential-stuffing-ip-intelligence Published: 2026-06-17 | Updated: 2026-09-25 | 5 min read Credential stuffing arrives from datacenter ranges, proxies and rotating addresses. Which IP signals separate an attack from a real user, and how to act on them. ### Quick Answer Credential stuffing uses automated login attempts with stolen credentials; IP intelligence adds context like geolocation, VPN/proxy status, and reputation to each request, letting you spot abnormal patterns-such as many attempts from a single data-center IP or a sudden surge from a high-risk country-and respond with challenges, rate limits, or blocks before attackers succeed. ### Key Takeaways IP intelligence adds geolocation, VPN/proxy status, and reputation data to login attempts. Unusual geographic spikes or known malicious IPs often signal credential stuffing. Combine IP data with velocity checks and device fingerprinting for stronger defenses. Avoid relying on IP alone; attackers use residential proxies and compromised hosts. Use Crafzo IP Lookup to automate enrichment and trigger blocks or challenges in real time. ### How IP Intelligence Works IP intelligence services enrich a raw IP address with contextual data that security systems can evaluate in real time. Typical enrichment includes: Geolocation: country, region, city, latitude/longitude, and sometimes the organization or ISP. Connection type: whether the IP belongs to a residential ISP, a corporate network, a data center, a VPN, a proxy, or a Tor exit node. Reputation: presence on threat feeds, botnet lists, spam databases, or records of abusive behavior. ASN and ownership: the autonomous system number and the organization that administers the IP block. When a login request arrives, your security stack queries the IP intelligence source (via API or local database) and receives these attributes. You then apply rules-for example, block any request from an IP flagged as a known bad actor, or present a CAPTCHA when the IP is from a VPN and the login velocity exceeds a threshold. ### When to Use IP Intelligence for Credential Stuffing IP intelligence is most valuable at the perimeter of authentication systems, especially: Public-facing login pages where you cannot control the client device. API endpoints used by mobile apps or third-party integrations that accept username/password. Privileged access portals such as admin consoles or remote-desktop gateways. Any service that experiences sudden traffic spikes from unfamiliar locations, which often precede credential stuffing waves. In these scenarios, enriching each request with IP data lets you differentiate between legitimate users traveling abroad and attackers using anonymizing services. ### Common Mistakes to Avoid Treating IP as a perfect identifier - Attackers frequently hijack residential IPs or use proxy networks that look benign. Relying solely on IP blocks can block legitimate users and miss sophisticated attacks. Ignoring velocity and behavioral signals - A single IP with a low reputation might still be legitimate if it belongs to a traveling user. Combine IP data with login frequency, device fingerprint, and time-of-day patterns. Using stale intelligence - IP reputations change quickly; outdated feeds can let malicious IPs slip through or cause false positives on newly clean addresses. Over-blocking based on geolocation alone - Blocking entire countries can harm legitimate customers; instead, use geolocation as a risk factor, not a hard rule. Failing to log and analyze - Without logging the enriched IP data, you cannot tune thresholds or investigate incidents effectively. ### How to Use Crafzo IP Lookup for Protection Crafzo is a manual lookup tool, not an API. It belongs in the investigation step of a credential-stuffing defence, once your own rate limits or login-failure counters have flagged an address, rather than inline in the login path. Start from your own signal. A spike of failed logins from one address, or many accounts tried from one address in a short window, is the trigger. Paste that address into Crafzo. Read the network first. A hosting or data-center classification, a VPN or proxy flag, or a Tor exit are the patterns credential-stuffing tools hide behind. A residential ISP with none of those flags is more likely to be one compromised device or a shared connection. Check the [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) and its band. The score is shown with the provider's band and the time of the check. A high or very high band on an address that is also hammering your login form is strong corroboration; a low band does not clear an address that your own logs say is attacking you. Score it for your own rules. A simple scheme many teams use: +2 for a hosting or data-center network, +2 for a VPN, proxy or Tor flag, +1 for a blacklist listing, +1 for a country your users never log in from, and +3 if the address already failed logins on several accounts. Three points or more earns a CAPTCHA or step-up authentication on that address; five or more earns a temporary block. Tune the numbers to your false-positive rate rather than treating them as fixed. Record the evidence. Copy report gives you every field with its source and timestamp for the incident notes, and the shared link lets a colleague open the same result. For per-request enrichment inside the login path you need a provider's API in your own stack; Scamalytics, whose score Crafzo shows, publishes one with a free tier, as do IPQualityScore and MaxMind minFraud. Keep the scoring rules above in your own code, where they can be tuned and audited. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - Cloudflare: Turning threat indicators into real-time WAF rules: https://blog.cloudflare.com/realtime-threat-intel-waf-rules/ - OWASP: Credential stuffing: https://community.owasp.org/attacks/Credential_stuffing ## IP Risk Score Explained: How Fraud Teams Use It to Stop Bad Actors Canonical: https://ip.crafzo.com/blog/ip-risk-score-for-fraud-teams Published: 2026-06-17 | Updated: 2026-09-24 | 6 min read What goes into an IP risk score, how fraud teams combine it with geolocation, proxy and blocklist signals, and why the score is evidence rather than a verdict. ### Quick Answer An IP risk score is a numeric rating that predicts how likely an IP address is to be involved in fraudulent activity. It combines geolocation consistency, proxy/VPN status, blacklist listings, and abuse history into a single value (often 0-100). Fraud teams use this score in real time to block, challenge, or allow traffic, improving detection while reducing manual review workload. ### Key Takeaways An IP risk score combines multiple signals-geolocation, proxy/VPN status, blacklist reputation, and behavior-to produce a single risk rating. Fraud teams apply the score in real time to block high-risk traffic, step-up authentication, or trigger manual review. Common mistakes include relying on a single data source, ignoring score thresholds, and failing to update models as threats evolve. Crafzo IP Lookup provides a ready-to-use risk score API that can be dropped into existing fraud-prevention stacks. ### How It Works IP risk scoring starts with raw data points collected from various sources. Geolocation services compare the IP’s registered location with the user’s declared location or typical behavior patterns. Proxy and VPN detectors examine network traits, such as known data center ranges, Tor exit nodes, or commercial VPN IP lists. Blacklist feeds provide historical abuse reports, spam trap hits, and records of IPs seen in credential stuffing or carding attacks. Additional signals may include the IP’s autonomous system number (ASN) type, connection speed, and whether the address appears in recent honeypot logs. Each signal is normalized to a common scale and weighted according to its predictive power. For example, an IP on a recent spam blacklist might receive a high weight, while a residential ISP with clean history gets a low weight. The weighted values are summed and scaled to produce the final score. Many providers update these weights continuously using machine learning models that learn from confirmed fraud and legitimate traffic. ### When to Use It Fraud teams insert IP risk scoring at the earliest possible point in the traffic flow-often at the edge or API gateway-so decisions happen before any application logic runs. Typical use cases include: Login protection: Block or challenge logins from IPs scoring above a threat threshold, reducing account takeover attempts. Transaction screening: Flag payments originating from high-risk IPs for additional verification or manual review. Content abuse prevention: Stop comment spam, fake account creation, or coupon abuse by rejecting submissions from risky addresses. API security: Rate-limit or block requests from IPs with a history of scraping or credential stuffing. Because the score is a single number, it integrates easily with existing rules engines, SIEMs, or fraud platforms that already consume IP lookup, geolocation, and blacklist data. ### Mistakes to Avoid Over-reliance on one signal - Using only blacklist status or only VPN detection can miss sophisticated attackers who use clean residential IPs or newly compromised hosts. Static thresholds - Setting a fixed cutoff (e.g., score > 80) without periodic review can cause drift as fraud tactics evolve; regularly recalibrate based on observed false positive and false negative rates. Ignoring network sharing - Legitimate users behind CGNAT, corporate proxies, or public Wi-Fi may inherit a high score from a few bad actors; consider combining IP risk with device or session-level signals. Failing to feed back outcomes - Not logging whether a blocked IP was truly malicious prevents model improvement; maintain a feedback loop to retrain scoring models. Neglecting latency - Some scoring services add hundreds of milliseconds; choose a low-latency provider or cache results for short periods to keep user experience smooth. ### How to Use Crafzo IP Lookup Crafzo is a manual lookup tool, not an API: there is no key to obtain and no endpoint to call. It fits the parts of a fraud workflow where a person is looking at one address, which is most of them once an automated rule has fired. Paste the address from the alert, the login event or the chargeback record into the lookup field. IPv4 and IPv6 both work. Read the risk overview first. The 0-100 score is shown with the provider's own band (low, medium, high, very high) and the time it was checked, so the number in your case notes carries its own context. Check the signals that explain the score. VPN, proxy, Tor, hosting and blacklist each name the provider that reported them and say "Not reported" when a provider did not return the field, so you can tell a real negative from a gap. Compare the network with the account. The ISP, organization and ASN tell you whether the address belongs to a consumer carrier, a corporate network or a hosting provider; a residential ISP on a new account and a cloud provider on a checkout deserve different questions. Copy the report into the case. The Copy report button produces a plain-text record with every field, its source and the lookup time, which is what a reviewer needs later. For automated, per-request scoring you need a provider's API in your own stack. The score Crafzo displays comes from Scamalytics, which offers an API with a free tier; other options include IPQualityScore, MaxMind minFraud and ipinfo. Whichever you pick, the checklist above still applies: log the score with its band and provider, review the boundary cases by hand, and feed the outcomes back into your thresholds. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - Cloudflare: Turning threat indicators into real-time WAF rules: https://blog.cloudflare.com/realtime-threat-intel-waf-rules/ - OWASP: Automated Threats to Web Applications: https://owasp.org/projects/automated-threats-to-web-applications ## IP Risk Score for Ecommerce Canonical: https://ip.crafzo.com/blog/ip-risk-score-for-ecommerce Published: 2026-06-17 | Updated: 2026-09-25 | 6 min read How an IP risk score fits a checkout review: pairing the score with address mismatch, proxy and hosting signals so fake orders are caught without blocking real buyers. ### Where the IP score fits in a checkout A checkout review already has several signals: address verification and card security codes, the age and reputation of the email address, device fingerprints, order velocity and the order's own shape. The IP risk score adds the network dimension. It condenses what is known about the address into a number and a label: whether it belongs to a proxy, VPN or hosting range, whether it appears on abuse blocklists, and how it has behaved elsewhere. Used alone it will both miss fraud and block good customers; used with the other signals it sharpens both. ### The signals that matter for orders Hosting and datacenter addresses on a consumer checkout deserve attention because real shoppers rarely buy from a cloud server. Proxy or VPN use matters most when it coincides with a billing address in one country and a shipping address in another, or with a shipping address that resolves to a freight forwarder. A three-way mismatch between the IP country, the billing country and the card issuer's country is stronger than any single mismatch. Velocity is the clearest signal of all: several orders from one address or one hosting network within minutes, especially with different cards, is a test run. Tor exits and addresses recently added to abuse lists raise the score for good reason, but they should trigger verification rather than automatic refusal. ### A checkout checklist Reviewers work faster with a fixed list, so here is the one this guide implies, in the order that usually settles a case quickest: Compare the IP country with the billing country, the shipping country and the card issuer's country. One mismatch is common; two or three together are not. Check whether the address is a hosting or data-center range, a VPN or a proxy, and read the [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) and its label for the address. Look at velocity: how many orders, cards and accounts this address or its network has produced in the last hour and the last day, and whether it appeared on earlier failed attempts. Check the customer's own history. An address that is new for a customer with successful past orders reads differently from a first order on a fresh account. Note repeated card failures and several accounts from one address; both are hallmarks of card testing. Remember what the list is for. IP signals are strongest alongside payment behavior, email reputation, the shipping address, device signals and order velocity, and weakest on their own, especially for mobile networks and shared residential addresses where one IP stands for many households. ### Reading the score without over-blocking Work in tiers. A low score with consistent signals, such as a residential ISP in the billing country and a shipping address that matches, should be accepted without friction. A medium score, or a low score with one mismatch, is a case for stepping up: 3-D Secure, a confirmation email or SMS, or a short manual look. A high score combined with corroborating mismatches goes to review or is held until the customer verifies. The rule that protects revenue is simple: no decline is driven by the IP alone, because the false positives there are travellers, VPN users and the many people sharing a carrier-grade NAT address. ### Three orders, three outcomes An order from a residential cable ISP in the billing country, with matching billing and shipping addresses and a low score, is accepted. An order from a cloud hosting range with a VPN flag, a billing address in one country, shipping to a known forwarder in another and a high score, is held for review. An order from a mobile carrier whose estimated city is two hundred kilometres from the billing address, with a low score and everything else consistent, is accepted; mobile geolocation is imprecise and the mismatch means nothing on its own. ### Operating it well Store the score, the risk label and the individual signals with each order, so that when a chargeback arrives you can see what the network looked like at the time. Review declined and held orders monthly for false positives. Calibrate thresholds per product line if the fraud exposure differs. And keep the provider's own label rather than inventing cutoffs; the label reflects how the provider built the score, and your chargeback history tells you how much to trust it for your customers. Give every decision a reason code (accepted, stepped up, held or declined, and why) and keep the review outcome with the order alongside the score and signals you already store. Reason codes are what make thresholds tunable later, and when a chargeback is disputed, a timestamped record of the address, the network it belonged to and the checks that passed is the documentation that supports your case. ### FAQ **Should I block every order placed through a VPN?** No. Many legitimate customers use VPNs on public Wi-Fi or by company policy. A VPN flag on its own is a reason to look at the rest of the order, not to decline it. **What score counts as high risk?** Use the risk label your provider assigns rather than inventing a threshold, then adjust for your own outcomes. A score that predicts chargebacks in one store may be noise in another with different customers. **Does an IP country that differs from the card country mean fraud?** It is a signal, not proof. Travellers, expatriates and people using VPNs produce the same mismatch. It becomes meaningful when it coincides with a hosting address, a shipping address that differs from billing, or unusual order velocity. **Can a high-risk IP still place a real order?** Yes. That is why risk-based verification is often better than automatic rejection. **Can IP data stop all chargebacks?** No. It can reduce risk, but chargeback prevention needs layered controls. **Should I block data center IPs at checkout?** For consumer checkout, data center IPs may deserve extra verification, but not every case is fraud. ### Sources - Cloudflare: Turning threat indicators into real-time WAF rules: https://blog.cloudflare.com/realtime-threat-intel-waf-rules/ - OWASP: Automated Threats to Web Applications: https://owasp.org/projects/automated-threats-to-web-applications ## Residential Proxy Detection for Login Risk: How to Spot and Block Suspicious IPs Canonical: https://ip.crafzo.com/blog/residential-proxy-detection-for-login-risk Published: 2026-06-17 | Updated: 2026-09-25 | 8 min read Residential proxies make attack traffic look like home users. The signals that still give them away, and how to use them in login risk decisions without false positives. ### Quick Answer Residential proxy detection identifies login attempts that come from IP addresses leased to real households but are actually being routed through a proxy service. By checking ASN data, connection headers, and behavioral signals-not just IP reputation-you can spot these stealthy proxies and apply step-up authentication or block the request before account takeover occurs. ### Key Takeaways Residential proxies blend in with normal user traffic, making simple blacklists insufficient. Effective detection uses ASN, IP reputation, header anomalies, and device-fingerprinting. Apply checks at login, password reset, and high-value transaction points. Combine real-time scoring with adaptive authentication to avoid false positives. ### Where Residential Proxies Show Up A residential proxy network routes traffic through IP addresses that belong to consumer connections: home broadband and mobile lines whose owners installed an app or SDK that rents out their bandwidth, knowingly or not. To every website the traffic looks like it comes from an ordinary household. Some of that use is legitimate, such as price monitoring, ad verification and testing a site from another region. The same networks also carry scraping, fake account creation, ad fraud and credential attacks, because they defeat the simplest defense there is. That defense is the data-center block. Blocking hosting ranges catches naive automation, but a residential proxy exit belongs to an ISP rather than a cloud provider, so it passes. Blocking residential networks instead is not an option, since that is where real users live. Detection therefore has to move from where the address is to how it behaves: request velocity, countries that rotate within one session, device signals that contradict the claimed browser, and repeated account creation from addresses that should each represent one home. Login is where the cost of missing this is highest, which is why the rest of this guide concentrates there, but the same signals apply to signups, checkout and API traffic. ### How Residential Proxy Detection Works Residential proxies are attractive to attackers because they use IP addresses that look like ordinary home connections. Detection therefore goes beyond checking whether an IP appears on a known-bad list. Instead, systems examine several layers of information: ASN and ISP data - Each IP belongs to an autonomous system number (ASN). Residential ISPs have distinct ASN ranges and naming patterns (e.g., containing "Cable", "DSL", or "FTTH"). If an IP’s ASN matches a hosting provider or data center, it’s likely not residential. Conversely, if the ASN is residential but the connection shows signs of tunneling (unusual headers, missing browser fingerprints), it raises suspicion. Connection characteristics - Proxies often strip or alter certain TCP/IP headers. Look for missing or spoofed X-Forwarded-For, Via, or Forwarded headers. Residential connections typically have a consistent TTL and window size; abrupt changes can indicate a middleman. Behavioral and device signals - Even if the IP looks legitimate, the way a client behaves can reveal a proxy. Examples include: Unusual request timing (rapid-fire login attempts from the same IP). Mismatch between declared user-agent and observed browser features (headless browsers, automation tools). Geographic impossibility (login from a residential IP in one country, then seconds later from another continent). Reputation and threat feeds - Some residential IPs are leased to proxy services and appear in specialized threat intelligence feeds. Feeds that track known proxy exit nodes, VPN services, or residential proxy networks add another data point. By scoring each of these signals and combining them into a risk score, you can decide whether to allow the login, prompt for multi-factor authentication, or block the attempt outright. ### When to Use Residential Proxy Checks Not every login needs the same level of scrutiny. Focus proxy detection on moments where the cost of a false negative is high: Initial login - Especially after a period of inactivity or from a new device. This is where credential stuffing attacks often start. Password reset or account recovery - Attackers frequently try to hijack accounts via reset flows; a residential proxy can help them bypass geo-locks. Sensitive transactions - Changing email, adding a payment method, or initiating a wire transfer are high-value actions that warrant extra verification. Access from unfamiliar locations - If a user normally logs in from a specific city and suddenly appears from a residential IP in a different region, trigger a step-up challenge. High-risk user roles - Administrators, finance staff, or anyone with elevated privileges should have stricter proxy scrutiny. Implementing detection at these checkpoints reduces the chance that an attacker leverages a residential proxy to stay under the radar while attempting account takeover. ### Common Mistakes to Avoid Even with good intentions, teams often misapply proxy detection and create friction or blind spots. Watch out for these pitfalls: Relying solely on static IP blacklists - Criminals rotate residential IPs constantly; a list that’s outdated by a day can miss many threats. Over-blocking based on ASN alone - Some legitimate users are behind carrier-grade NAT or use mobile ISPs that appear in residential ranges; blocking them outright leads to false positives and support tickets. Ignoring header consistency - A sophisticated proxy may forge headers to look like a direct connection. Cross-checking header values with observed TCP/IP traits helps catch inconsistencies. Neglecting velocity checks - A single residential IP used for dozens of login attempts in a minute is a red flag, even if the IP itself looks clean. Skipping step-up authentication - Blocking outright can frustrate legitimate users. Instead, challenge suspicious logins with a second factor or CAPTCHA, then allow passage after success. Failing to update detection logic - Proxy networks evolve; set a regular cadence to review logs, adjust scoring thresholds, and incorporate new threat feeds. Avoiding these mistakes keeps your security effective while maintaining a smooth experience for genuine users. ### Using Crafzo IP Lookup for Proxy Detection Crafzo is a manual lookup page, not a data feed or an API, so it sits in the review step rather than in the login path itself: your own velocity and device checks flag a login, and Crafzo is where an analyst looks at the address behind it. Look up the flagged address. Paste it into the lookup field. The network panel shows the ISP, organization and ASN; the signal cards show VPN, proxy, Tor and hosting, each with the provider that reported it. Read the ASN and ISP against the story. A consumer ISP (cable, DSL, fibre, mobile) with no anonymizer flags is consistent with a real household, which is exactly what a residential proxy is trying to look like, so it does not clear the address on its own. A hosting or data-center classification means the "residential" appearance is already broken. Weigh the anonymizer signals. When the proxy card says "Sources disagree", one provider sees a relay and the other does not; treat that as an unconfirmed signal, not as noise. "Not reported" means the provider did not return the field, which is common for residential proxy exits and is not a negative. Combine with what only you can see. Login velocity from the address, device fingerprint consistency, the user's location history and header anomalies are yours; Crafzo cannot see them. A clean-looking residential address that fails dozens of logins a minute is still an attack. Choose a proportionate response. Step-up authentication or a CAPTCHA for medium confidence, a temporary block for high confidence with corroborating velocity, and a note in the incident record with the copied report. For real-time scoring on every login you need a provider's API in your own stack. Scamalytics (whose score Crafzo displays), IPQualityScore and Spur all publish residential-proxy fields; keep the thresholds in your own code and review them against your false-positive rate. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. **Can a residential IP be risky?** Yes. Residential proxy networks and compromised devices can create risk from consumer-looking IPs. **How do I respond to residential proxy abuse?** Use behavior-based detection, rate limits, and verification instead of blocking whole consumer ISPs. **Should SaaS apps block VPNs?** Usually no. They should use VPN as one risk signal among several. **What actions need stronger checks?** Admin access, billing changes, exports, password resets, and token creation deserve stricter review. ### Sources - OWASP: Credential stuffing: https://community.owasp.org/attacks/Credential_stuffing - Cloudflare docs: Bot scores: https://developers.cloudflare.com/bots/concepts/bot-score/ ## IP Intelligence for Login Risk Canonical: https://ip.crafzo.com/blog/ip-intelligence-for-login-risk Published: 2026-06-12 | Updated: 2026-09-22 | 4 min read Which IP signals matter at sign-in (new ASN, hosting ranges, proxy or Tor, blocklists), how to weigh them, and how to avoid locking out travelling users. ### Why the address matters at sign-in A correct password proves that whoever is logging in has the password, not that they are the account owner. Credential stuffing and account takeover both arrive with valid credentials. What distinguishes them from the owner is context, and the IP address is the context you get for free on every request: where the connection appears to come from, which network it belongs to, whether that network is a consumer ISP or a rented server, and how the address has behaved elsewhere. ### The signals to check Compare the login to the account's own history first. A country or an autonomous system the account has never used before is the most useful single anomaly, because it is specific to that user. Then read the network type: hosting and datacenter ranges are where automated attacks run from and where few real customers sign in. Proxy, VPN and Tor flags indicate that the visible address is a relay. Presence on abuse blocklists or recent abuse reports adds weight. Then look across accounts. One address or one /24 range attempting many different usernames, especially with a high failure rate, is credential stuffing regardless of what any single attempt looks like. Impossible travel, two logins from places too far apart for the time between them, is strong when both addresses are residential and weak when one is a VPN or a mobile gateway. ### Responding in tiers Allow logins whose signals match the account's history. Step up when something is new but not alarming: a new country on a residential ISP, a VPN flag, a first login from a new device. A second factor, a confirmation email or a push notification resolves most of these with little friction. Block and notify only when the evidence stacks: a hosting range plus a blocklist hit plus a pattern of attempts across accounts, or a login that follows a credential-stuffing burst from the same network. Every block should generate a message to the account owner, because a false positive that the user can clear quickly is a minor annoyance and a silent one is a support ticket. ### Avoiding false positives Travellers change country. Carrier-grade NAT means a single mobile address can carry hundreds of unrelated users, one of whom may be attacking you. Corporate VPNs put an entire company behind a hosting range. IPv6 privacy extensions rotate a device's address daily. None of these is an attack, and a system that treats them as one trains users to expect lockouts. Weight IP signals against device recognition, typing and navigation behaviour, and the account's value, and let remembered devices bypass step-up for low-risk changes. ### Logging and review Record the address, ASN, network type, reputation signals and the decision for every login attempt, successful or not. Review blocks and step-ups weekly for patterns you did not anticipate, and feed confirmed takeovers back into the thresholds. The goal is a system that gets quieter and more accurate over time, not one that blocks more. ### FAQ **Should I block logins from VPNs?** No. Ask for a second factor instead. VPN use is common and legitimate; blocking it locks out customers and pushes attackers to residential proxies that you cannot flag anyway. **How does IP data reveal credential stuffing?** By volume and shape: many different accounts attempted from one address or one hosting network, a high failure rate, and traffic from ranges where your users do not live. Individual logins look normal; the aggregate does not. **What is impossible travel?** Two successful logins from locations too far apart for the time between them, such as one city and another continent within an hour. It is a strong signal when both addresses are residential and weak when either is a VPN or mobile gateway. **Should I block logins from new countries?** Usually no. Use a challenge or notification first unless other risk signals are present. **Can IP checks stop credential stuffing?** They help, especially when combined with rate limits, MFA, and bot detection. ### Sources - Cloudflare: Turning threat indicators into real-time WAF rules: https://blog.cloudflare.com/realtime-threat-intel-waf-rules/ - OWASP: Credential stuffing: https://community.owasp.org/attacks/Credential_stuffing ## IP Geolocation for Illegal IPTV: Detection & Prevention Guide Canonical: https://ip.crafzo.com/blog/ip-geo-location-for-illegal-iptv Published: 2026-05-31 | Updated: 2026-09-24 | 5 min read How rights holders and platforms use IP geolocation, ASN ownership and hosting signals to trace illegal IPTV streams, and the accuracy limits of that evidence. ### Quick Answer IP geolocation translates an IP address into a geographic location, helping you spot IPTV streams originating from unexpected regions or data centers. When combined with VPN/proxy checks and blacklist lookups, it flags suspicious sources so you can block or investigate illegal content. ### Key Takeaways IP geolocation reveals mismatches between claimed service regions and actual IP locations, a common sign of illicit IPTV. Layer geo-data with VPN detection, ISP reputation, and threat intel for stronger protection. Never rely on location alone; verify with headers, behavior, and account data to reduce false positives. Crafzo IP Lookup is a manual tool for examining one flagged address at a time: location, ISP, ASN and anonymizer signals with their sources. Automated monitoring needs a geolocation provider's API in your own platform. ### How IP Geolocation Works Every IP address is allocated to an organization or ISP by a regional registry (ARIN, RIPE, APNIC, LACNIC, AFRINIC). Geolocation providers match those allocations to physical locations using registration data, latency measurements, and user-submitted information. The result is a latitude/longitude or a city-country pair. For IPTV, legitimate services usually register IPs in the countries they claim to serve. Illegal operators often host streams in low-cost data centers or use compromised residential IPs elsewhere. Seeing a US-based channel served from an IP registered in Eastern Europe or a cloud provider can raise a red flag. Geolocation queries return fields such as country, region, city, postal code, timezone, and sometimes the associated organization or AS number. Accuracy is highest at the country level; city-level data can be off by dozens of miles, especially for mobile or satellite connections. ### When to Use IP Geolocation for IPTV Monitoring Use geo-checks whenever you need to validate the origin of a stream or a client connection: Stream source verification - Before accepting a feed, check the IP’s declared country against the channel’s official broadcast territory. Client access control - When users log in, compare their IP location to their account’s registered region; sudden jumps may indicate credential sharing or VPN use. Abuse tracking - Identify IPs repeatedly linked to pirated content and feed them into blacklists or rate-limiting rules. Incident response - During a takedown notice, geo-data helps locate the hosting provider for quicker abuse reports. Combine these checks with VPN/proxy detection (spot known data center ranges or Tor exit nodes) and reputation feeds (spam, malware, abuse) to build a multi-layered defense. ### Common Mistakes to Avoid Treating geo-data as proof of illegality - A foreign IP does not automatically mean pirated content; legitimate users travel or use overseas servers. Ignoring VPN and proxy evasion - Many illicit services route traffic through residential proxies or VPNs to mask their true location. Relying on outdated databases - IP allocations change frequently; stale geo-files produce false mismatches. Over-blocking based on city-level errors - City inaccuracies can block innocent users; use country-level thresholds for automated actions. Neglecting header and behavioral signals - User-agent, request timing, and payment details often reveal fraud better than location alone. Always view geolocation as one signal in a broader risk-scoring model. ### Using Crafzo IP Lookup for IPTV Checks Crafzo is a manual lookup tool: it has no endpoint to call and returns no JSON. It fits the point where a rights holder or platform operator is examining one stream source or one subscriber address that monitoring has already flagged. Extract the address from your streaming server logs or the client's connection details. Look it up. Paste it into the lookup field. The result shows the country, region and city that geolocation providers associate with the address, the ISP, organization and ASN, and the VPN, proxy, Tor and hosting signals with their sources. Compare the location with the licence. If the reported country does not match the region the content is licensed for, that is a reason to review the account, not proof of circumvention: geolocation is approximate, mobile carriers and corporate networks route traffic across borders, and the page says so beside the result. Read the network type. A hosting or data-center classification on a supposed home viewer, or a VPN or proxy flag, suggests an attempt to hide the real origin. A consumer ISP with no flags is consistent with an ordinary subscriber. Record what you saw. Copy report captures every field with its provider and the time of the check, which is what a takedown notice or an abuse report to the ISP needs. For checking every connection automatically, integrate a geolocation provider's API (MaxMind GeoIP2, ip-api's paid tier or IPinfo, for example) into your streaming platform and keep the policy decisions in your own code. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - ARIN: American Registry for Internet Numbers: https://www.arin.net/ - RIPE NCC: Regional Internet Registry for Europe, the Middle East and Central Asia: https://www.ripe.net/ - APNIC: Regional Internet Registry for the Asia Pacific: https://www.apnic.net/ ## What Is IP Geolocation Service and How to Use It Effectively Canonical: https://ip.crafzo.com/blog/ip-geolocation-service Published: 2026-05-23 | Updated: 2026-09-25 | 5 min read What an IP geolocation service returns, where the data comes from, how accurate each field is, and how to use it for localisation, fraud checks and troubleshooting. ### Quick Answer An IP geolocation service takes an IP address and returns an approximate geographic location-typically country, region, city, latitude, and longitude-based on public registration data, routing information, and proprietary databases. It is used for content localization, fraud detection, network security, and analytics, though it does not provide exact physical addresses. ### Key Takeaways IP geolocation gives a location estimate, not an exact address. Helpful for tailoring content, spotting fraud, and securing networks. Accuracy drops with mobile, VPN, or proxy IPs. Choose a reputable tool and verify results when making decisions. ### How It Works When a device connects to the internet, its IP address is assigned by an Internet Service Provider (ISP) or network administrator. That address is recorded in regional internet registries (RIRs) such as ARIN, RIPE NCC, or APNIC. Geolocation providers combine this registration data with latency measurements, user-submitted location hints, and data from partner networks to infer where the IP is likely being used. The process does not involve GPS; instead, it relies on the fact that IP blocks are often allocated to organizations in specific geographic areas. Most services return a set of fields: Country and country code (e.g., US, JP) Region/state and city Postal code (when available) Latitude/longitude (often the center of the city) Time zone Connection type (broadband, mobile, corporate) Threat indicators (VPN, proxy, Tor, hosting) Because IP addresses can be reassigned, routed through data centers, or masked by privacy services, the confidence level varies. Providers usually include an accuracy radius or a confidence score to help you gauge reliability. ### When to Use It IP geolocation is valuable in several everyday scenarios: Content localization - Serve language-specific pages, show local prices, or display relevant news based on the visitor’s country. Fraud prevention - Flag transactions where the IP country differs from the billing address, or detect multiple accounts originating from the same suspicious range. Security monitoring - Identify traffic from known malicious networks, block IPs from high-risk regions, or trigger alerts when a login comes from an unexpected location. Analytics and marketing - Understand where your audience resides, adjust ad targeting, and measure campaign performance by region. Network troubleshooting - Correlate latency spikes with geographic patterns to spot routing issues. In each case, treat the geolocation data as a clue rather than definitive proof. Combine it with other signals-such as user-provided location, device fingerprinting, or behavioral analysis-for stronger conclusions. ### Mistakes to Avoid Assuming pinpoint accuracy - IP geolocation rarely reaches street-level precision. Expect city-level accuracy at best, and treat country-level results as reliable for broad decisions. Ignoring mobile and VPN IPs - Cellular carriers often pool IP addresses across large regions, and VPN services can exit from data centers far from the user’s true location. Relying solely on IP for location in these cases leads to false conclusions. Using outdated databases - IP allocations change; an old database may misplace newly assigned blocks. Schedule regular updates or subscribe to a service that refreshes frequently. Overlooking privacy regulations - Some jurisdictions treat IP addresses as personal data. Ensure your use of geolocation complies with GDPR, CCPA, or other applicable laws, especially when storing or profiling users. Failing to validate with secondary checks - If a decision hinges on IP location (e.g., blocking a transaction), verify with additional factors like billing address, device language, or transaction history. ### How to Use Crafzo IP Lookup Crafzo is a manual lookup page for one address at a time; it has no API and no bulk mode. Open the homepage and paste the IPv4 or IPv6 address into the lookup field, or leave it blank to look up your own connection. Read the location panel: country, region, city, postal code where available, coordinates and time zone, with the provider named beneath. Treat the coordinates as the centre of the area the provider associates with the network, not as a device position. Read the network panel: ISP, organization, ASN and the network type (consumer ISP, mobile carrier, hosting or data center). Read the signals: VPN, proxy, Tor, hosting, blacklist and the [fraud score](https://ip.crafzo.com/ip-fraud-score-checker), each with the provider that reported it and the time of the check. Judge the confidence yourself. Crafzo does not receive an accuracy radius from its providers, so it does not show one. Country is usually reliable; city is an estimate that is more often right for fixed-line broadband than for mobile, VPN or corporate connections, and the page says so beside the result. For bulk or automated geolocation, use a provider's API or database in your own tooling: MaxMind GeoIP2, IPinfo and ip-api's paid tier all document their fields, update cadence and, in MaxMind's case, an accuracy radius per record. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy - RFC 8805: A Format for Self-Published IP Geolocation Feeds: https://www.rfc-editor.org/rfc/rfc8805 ## Starlink IP Addresses and Geolocation: What to Expect Canonical: https://ip.crafzo.com/blog/starlink-ip-addresses-geolocation Published: 2026-05-21 | Updated: 2026-09-22 | 7 min read Why Starlink connections geolocate to a distant city: CGNAT, ground-station routing and shared address pools, plus what to check before trusting a lookup. ### Quick Answer Starlink IP geolocation can show a different city, region, or sub-region from your actual dish location because websites usually see Starlink network routing, shared public IP infrastructure, or geolocation database records rather than GPS. Starlink says it assigns an IP in the same country as the service address, but a specific local location is not guaranteed. ### Key Takeaways Starlink IP geolocation may match your country but still show a different city, state, province, or region. Default Starlink IPv4 uses CGNAT, so many users may share public internet routing while their router receives a private 100.64.0.0/10 address. Starlink IPs can change as the network grows, routing changes, or mobile users move between regions. Treat IP lookup as network context, not GPS-level proof of where a Starlink dish or user is physically located. ### Why Starlink IP Geolocation Looks Different Starlink is not a traditional fixed cable or fiber ISP with every customer routed through a nearby local exchange. It is a satellite network with ground infrastructure, dynamic routing, service regions, and public IP ranges that can be mapped differently by websites and geolocation databases. When a website checks your location, it usually does not see your Starlink dish coordinates. It sees the public IP address used for your internet session and asks a geolocation database where that IP range belongs. If that database maps the IP to a Starlink router, point of presence, or broader service area, the result can look far from your actual home, office, RV, vessel, or remote site. Starlink's own help center says internet geolocation may be farther than your actual location by several states, provinces, or sub-regions. It also says Starlink currently assigns an IP address in the same country as the service address, but an IP in your specific location is not guaranteed. ### How Starlink IPv4 and CGNAT Affect Lookup Results Starlink says it provides two IPv4 policies: default and public. The default IPv4 configuration uses Carrier Grade Network Address Translation, commonly called CGNAT. With CGNAT, customer equipment can receive an address from the 100.64.0.0/10 private shared address range while outbound traffic reaches websites through Starlink public infrastructure. That matters because the IP shown by your router may not be the same address websites see. A public IP lookup tool shows the address visible on the internet, not necessarily the private WAN address inside your Starlink network. If many sessions use shared or dynamic routing, geolocation can be less local than people expect. Starlink also says it always provides a public IPv6 /56 prefix. IPv6 lookup results can differ from IPv4 results because databases may have different coverage, accuracy, and update timing for each address family. If you are troubleshooting, check both IPv4 and IPv6 where possible. ### Public IP, Static IP, and Mobile Starlink Behavior A public IP is reachable from the internet, but that does not mean it is static. Starlink says it does not provide static IP addresses at this time. The network is dynamic, and IP addresses can change as Starlink improves resilience, adds capacity, or expands into new countries. Mobile Starlink users can see more frequent changes. Starlink notes that if a mobile user moves between regions and ground stations, the user may acquire a new IP address as the connection migrates. That can create temporary differences in search results, content location, login alerts, or service availability. For most everyday browsing, this is only an annoyance. For remote access, security rules, firewall allowlists, payment review, or streaming rights, it can matter. If your workflow depends on a fixed public IP or a precise local city result, Starlink's dynamic behavior needs to be planned around. ### What Websites and Apps May Get Wrong Websites that rely only on IP location may show the wrong local news, ads, search results, taxes, store availability, or streaming region. Some apps may think you are in a neighboring region, a distant province, or a different part of the same country. Security systems may also interpret Starlink traffic differently. A login from a new Starlink IP may look like travel, even when the user has not moved. A fraud tool may mark the network as unusual if the IP range is new, shared, satellite-based, or seen from different regions over time. That does not mean the Starlink user is suspicious. It means IP geolocation should be combined with account history, device signals, authentication strength, ASN or ISP data, VPN/proxy status, and behavior. For low-risk actions, a region mismatch may simply be normal Starlink routing. ### How to Check a Starlink IP Address Start with a public IP lookup from the device connected to Starlink. Note the IPv4 address, IPv6 address if available, ISP or organization, ASN, country, city, region, timezone, and whether the result shows VPN, proxy, hosting, or blacklist signals. Then compare that result with your expected service country and your actual use case. If the country is correct but the city is wrong, that may fit Starlink's stated geolocation limitations. If the country is wrong, if streaming access is blocked, or if business systems are affected, collect the IP address, timestamp, affected service, and screenshots before contacting support. For site owners, do not make high-impact decisions from Starlink geolocation alone. A Starlink IP can be a normal residential or mobile satellite connection even if the city field looks odd. Use the IP result as one signal in a broader review. ### What You Can Do If the Location Is Wrong If search or streaming results are wrong, first confirm whether the service uses IP geolocation or device location. Some mobile apps can use GPS or browser location permission, while websites often rely on the public IP address. If the affected service is a content provider, bank, marketplace, or work system, report the incorrect location to that provider as well as Starlink support where appropriate. Many providers buy geolocation data from third-party databases, so they may need to update their own records or accept Starlink's published geolocation feed. If you need remote access into your Starlink network, consider whether your plan supports a public IP policy, whether IPv6 works for your setup, or whether a VPN tunnel, relay, or reverse proxy is safer than relying on inbound IPv4. Avoid assuming port forwarding will work on default CGNAT IPv4. ### FAQ **Why does my Starlink IP show the wrong location?** Starlink says IP geolocation may be farther than your actual location and that a specific local city or region is not guaranteed. Your traffic may exit through Starlink routing infrastructure that maps to another nearby region or sub-region. **Does Starlink give every customer a public IPv4 address?** No. Starlink says the default IPv4 policy uses Carrier Grade NAT with private 100.64.0.0/10 addresses. Public IPv4 is a separate policy for eligible plans or accounts, and Starlink does not provide static IP addresses at this time. **Can Starlink IP geolocation affect streaming or search results?** Yes. If a website relies on IP geolocation, it may show search results, ads, local services, or streaming availability for the region tied to the Starlink public IP rather than your exact physical location. **Is Starlink IP geolocation the same as GPS location?** No. IP geolocation estimates network location from routing and geolocation databases. It is not GPS and usually cannot identify a precise dish, household, street address, or person. ### Sources - Starlink support: IP addresses: https://starlink.com/na/support/article/ac09301b-cef6-a125-c251-856196a77f92 - Starlink support: Geolocation is incorrect: https://starlink.com/si/support/article/08ecdfe4-f2a9-2b3d-fcba-a435404a2db3 - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy - Cisco: Carrier-Grade NAT (CGNAT) IPs: https://www.cisco.com/c/en/us/support/docs/security/umbrella/225267-configure-cgnat-carrier-grade-nat-ips.html ## What Does It Mean When Your IP Is Blacklisted? Canonical: https://ip.crafzo.com/blog/what-does-it-mean-when-your-ip-is-blacklisted Published: 2026-05-21 | Updated: 2026-09-25 | 9 min read What an IP blocklist listing means for your email and web traffic, why addresses get listed, how to check your reputation, and how delisting works. ### Quick Answer When your IP is blacklisted, it means a blocklist, mail provider, website firewall, or reputation system has marked that IP address as risky, abusive, or not allowed for a specific use. It is a warning signal, not always proof that you personally did something wrong. The right response is to identify the list, understand the reason, fix the cause, and then request delisting if needed. ### Key Takeaways An IP blacklist usually means suspicious activity, spam, malware, abuse, or a policy mismatch was observed from the address or network range. A listing can affect email delivery, account access, API traffic, payments, or website security checks depending on who uses that list. Shared networks, VPNs, cloud hosting, reassigned addresses, and ISP ranges can make innocent users inherit bad reputation. Do not request delisting first. Confirm the reason, stop the bad traffic, improve configuration, and then use the official removal path. ### What an IP Blacklist Actually Means An IP blacklist, often called a blocklist or DNSBL in email systems, is a reputation dataset used to decide whether traffic from an IP address should be trusted, challenged, filtered, or rejected. The list may focus on spam, malware, open proxies, compromised devices, bot activity, or policy rules. For example, a mail server may check the connecting IP address during the SMTP transaction. If that IP appears on a major spam-related blocklist, the receiving server may reject the message or place it in spam. A website firewall may use reputation data differently: it might rate-limit the address, ask for extra verification, or block requests that match suspicious behavior. The important detail is scope. A blacklist is not one universal internet court. One list may be about email spam, another about bot traffic, another about residential IP ranges that should not send direct mail, and another about provider-specific abuse history. That is why the first question should always be: which list or service is saying the IP is blacklisted? ### Common Reasons an IP Gets Blacklisted The most common reason is abusive traffic. That can include spam campaigns, credential stuffing, scraping, malware callbacks, phishing infrastructure, botnet traffic, or repeated policy violations. If you run a server, this may come from a compromised account, a leaked API key, an insecure mail form, a vulnerable CMS plugin, or an open relay. Email configuration problems are another major cause. Missing or broken SPF, DKIM, DMARC, PTR, and HELO/EHLO alignment can make legitimate senders look suspicious. Google sender guidance notes that messages from blocklisted IP addresses are more likely to be treated as spam, so reputation and authentication need to work together. Some listings are not a punishment at all. Policy lists may include residential or dynamic IP ranges because those addresses should not send unauthenticated mail directly to destination mail servers. In that case, the fix is usually to send mail through your ISP or email service provider, not to fight the policy listing. ### How Mail Providers Use IP Reputation Email is where IP reputation bites hardest, because the receiving server judges the connecting address before it reads a line of the message. Large providers keep a running reputation for every sending IP, built from spam complaints, bounce rates, sending volume and how steady it is, whether the mail authenticates with SPF, DKIM and DMARC, and the address's abuse history. A good reputation gets messages into the inbox; a poor one sends them to spam or has the connection refused outright. That reputation is attached to the address, which is why shared sending IPs carry a shared risk. On a shared pool at an email service provider or a small host, another customer's spam campaign lowers the standing of every sender on that address. A dedicated IP isolates you from your neighbours, but it has to be warmed up gradually, because a sudden jump in volume from an address with no history is itself read as a spam pattern. If you are investigating a suspicious message rather than sending one, the headers hold the sending server's address: the Received line added by your own mail server records the IP that connected to it. Look that address up. The network owner, country and connection type tell you whether the message came from a mainstream provider or from cheap hosting, a compromised server or the rotating infrastructure that phishing campaigns favour. Treat it as context rather than proof; the links, the message content and the authentication results decide. Healthy sending comes down to habits: authenticate with SPF, DKIM and DMARC, keep lists clean so that bounces and complaints stay low, keep volume steady, and check the sending address's reputation after each campaign so that a problem is caught before a blocklist catches it. ### Why You Might See This Even If You Did Nothing Wrong IP reputation follows the address, not the person. If your ISP assigns you a dynamic residential IP, you may inherit reputation from the previous user. If you use a VPN, proxy, cloud server, shared hosting plan, or mobile carrier network, many users may appear behind nearby addresses or the same outbound range. That shared context matters. A fraud system may see your IP as risky because the network is associated with automation. A mail provider may distrust a cloud range because many abusive campaigns have used nearby addresses. A blocklist may include a whole range if the abuse is network-level rather than one isolated address. This is why IP blacklisting should be treated as a signal, not a final verdict. Before you block a customer, stop a transaction, or assume your device is infected, compare the IP result with account history, device signals, ISP or ASN, VPN/proxy status, request velocity, and the exact blocklist reason. ### How to Check a Blacklisted IP the Right Way Start by running the IP through a lookup tool that shows reputation, location, ISP, ASN, VPN/proxy context, and blacklist signals together. On Crafzo IP Lookup, check whether the IP appears residential, mobile, hosting, VPN, proxy, or data center. That helps explain whether the listing is expected or suspicious. Next, identify the exact provider or list. A vague message like "your IP is blacklisted" is not enough. Look for the rejection code, bounce message, firewall event, API error, or security dashboard note. For email, the message may mention a provider, a list name, or a delisting portal. For websites, the signal may come from a WAF, fraud engine, or internal denylist. Then record the context: IP address, lookup time, affected service, error message, traffic type, and recent changes. Reputation data changes over time, so notes are more useful than screenshots alone. If you manage the server, check logs for outgoing spam, unusual authentication attempts, suspicious scripts, unexpected cron jobs, and compromised user accounts. ### What to Do Before Requesting Delisting Fix the source of the problem first. If the IP sent spam, stop the sending path. If a website form was abused, add rate limits and bot protection. If a server was compromised, patch it, rotate credentials, remove malicious files, and verify outbound traffic. If email was the issue, review SPF, DKIM, DMARC, PTR records, bounce handling, and complaint rates. After the root cause is handled, use the official delisting process for the exact list or provider. Microsoft, for example, provides an Anti-Spam IP Delist Portal for external senders blocked by Microsoft 365. Spamhaus also provides reputation and list-specific guidance, but the correct action depends on whether the listing is SBL, XBL, CSS, PBL, or another dataset. Avoid paid "instant removal" promises unless they come directly from the authoritative provider. Many blocklists remove an address automatically after abusive traffic stops, while others require a clear request explaining what changed. A rushed request before fixing the issue can fail or lead to relisting. ### How Site Owners Should Use IP Blacklist Data If you run an app, do not use blacklist status as a single automatic ban rule for every workflow. Use it as one risk signal. A blacklisted IP trying to reset passwords, create many accounts, scrape pages, or submit payments deserves more friction than the same IP loading a public article. A fair workflow is simple: log the signal, compare it with user behavior, check VPN/proxy and ASN context, then choose the lightest effective action. That may mean rate limiting, CAPTCHA, email verification, manual review, temporary block, or full deny only when multiple signals agree. This approach reduces false positives while still protecting the product. It also gives your team clear reason codes later: blacklist hit, hosting ASN, country mismatch, velocity spike, failed login cluster, or known proxy. Those reason codes are much easier to tune than a single "bad IP" label. ### FAQ **Does a blacklisted IP mean I am hacked?** Not always. It can mean your device or server was abused, but it can also happen because you use a shared network, VPN, hosting provider, reassigned IP, or ISP range with previous reputation problems. Check the exact list and evidence before assuming compromise. **How do I remove my IP from a blacklist?** First identify the exact blocklist and reason, then fix the root cause such as spam, malware, open relay behavior, poor email authentication, or abusive traffic. After that, use the official removal or delisting form for that list or provider. **Can an IP blacklist affect normal browsing?** Yes, but the impact depends on who uses the list. A blacklisted IP may affect email delivery, signups, login risk checks, payment review, API access, or website firewalls. Some lists are email-specific, so they may not affect ordinary browsing. **Why is my home IP on a blocklist?** Home and mobile IPs can appear on policy or reputation lists because residential ranges are not expected to send direct server email, because another customer used the address before you, or because malware or insecure devices generated abusive traffic. **Can a shared mail IP hurt deliverability?** Yes. Abuse by other senders on the same IP can affect shared reputation. **Does IP lookup prove phishing?** No. It provides context that should be combined with headers, links, and message content. ### Sources - Spamhaus Blocklist (SBL): https://www.spamhaus.org/blocklists/spamhaus-blocklist/ - Spamhaus: The Policy Blocklist explained: https://www.spamhaus.org/resource-hub/dnsbl/the-policy-blocklist-what-is-it-and-why-should-you-be-on-it/ - Microsoft: Remove yourself from the blocked senders list (delist portal): https://learn.microsoft.com/en-us/defender-office-365/external-senders-use-the-delist-portal-to-unblock-yourself - Google: Email sender guidelines: https://support.google.com/mail/answer/81126 ## How to Choose an IP Geolocation API: Three Practical Approaches Canonical: https://ip.crafzo.com/blog/ip-geolocation-api-comparison Published: 2026-05-20 | Updated: 2026-09-22 | 2 min read Three ways to evaluate an IP geolocation API: vendor SDKs, raw HTTP calls and pre-parsed services, compared on accuracy, latency and integration effort. ### Overview When you need to turn an IP address into location information, you’ll encounter many providers offering APIs. Rather than comparing endless feature lists, it helps to think about how you’ll interact with the service. There are three common patterns for working with IP geolocation APIs: using an official SDK, making raw HTTP requests, and relying on a service that returns already-parsed JSON. Each pattern has trade-offs in terms of control, complexity, and reliability. ### Approach 1: Official SDKs (the “codec” way) Many providers ship client libraries for popular languages. You install the package, initialize it with your API key, and call a method like lookup(ip). The library handles request signing, retries, response parsing, and error handling for you. Pros Type-safe return values (if the language supports it) reduce bugs. Updates to the API (new fields, changed endpoints) are often absorbed by library updates. You don’t need to worry about low-level details like HTTP status codes or JSON structure. Cons Adds an external dependency to your project. If you’re working in an environment where adding packages is costly (e.g., serverless functions with strict size limits), the SDK may be overkill. You relinquish visibility into the raw request/response, which can make debugging harder when something goes wrong. ### FAQ **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ### Sources - ip-api.com: Geolocation API documentation: https://ip-api.com/docs - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## How to Choose an IP Location API: Pricing, Performance, and What Really Matters Canonical: https://ip.crafzo.com/blog/ip-location-api-pricing Published: 2026-05-20 | Updated: 2026-09-22 | 3 min read How to compare IP location APIs beyond the price tag: accuracy, uptime, rate limits, hidden costs and integration effort, with a checklist for choosing one. ### Overview When you’re building security tools, VPN/proxy detectors, or blacklist checks, the IP location API you pick can make or break your product. It’s tempting to jump at the lowest-priced plan, but experience from other technical domains shows that price is only one piece of the puzzle. Below is a practical guide that pulls together insights from payment infrastructure, AI-on-device experiments, developer credit programs, and vendor security practices to help you evaluate an IP geolocation service holistically. ### 1. Look Beyond the Sticker Price A cheap per-query rate can still cost you more than a pricier competitor if the API delivers poor accuracy or fails often. Every wrong answer becomes a false positive in a fraud rule or a support ticket from a mislocated user, and every failed call becomes a retry, a timeout or a fallback path that your team has to build and maintain. Price the whole outcome, not the request. When you compare plans, ask: What is the effective cost per successful lookup? Are there hidden charges for bulk retries, premium data fields, or SLA penalties? Does the provider offer a free tier or trial that lets you measure real-world hit-rate before committing? ### 2. Performance Matters as Much as Price Speed and reliability directly affect user experience. In the world of IP geolocation, latency adds up every time you enrich a log entry, challenge a login, or serve geo-targeted content, so a provider that answers in 50 ms is worth more than one that answers in 400 ms at the same price. Consider these performance indicators: Average response time under typical load (look for sub-200 ms for most use cases). Error or timeout rate - a service that fails 2 % of the time will force you to implement retry logic, increasing both latency and operational cost. Throughput guarantees - can the API handle your peak traffic without throttling? Select an API tier that matches your real query volume: overpaying for unused capacity is as common as hitting rate limits on a tier that was chosen from a demo rather than from production numbers. ### 3. Use Free Tiers and Trial Credits for Testing Most IP geolocation providers offer a free tier, trial credits or a sandbox environment. Use them to: Run a side-by-side accuracy test against a known ground-truth dataset (e.g., latency-measured IPs from your own network). Simulate burst traffic to see how the API behaves under stress. Evaluate the quality of documentation, SDKs, and error messages-factors that often determine integration speed. ### Sources - ip-api.com: Geolocation API documentation: https://ip-api.com/docs - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## How to Track Public IP Geolocation Safely and Clearly Canonical: https://ip.crafzo.com/blog/track-public-geolocation Published: 2026-05-20 | Updated: 2026-09-25 | 4 min read What public IP geolocation can and cannot show, how to read the result responsibly, and where it helps in security investigations and troubleshooting. ### Overview Public IP geolocation is useful when you need quick network context. It can help you understand the country, region, city, ISP, or organization associated with a public IP address. That context is helpful for VPN checks, proxy detection, login review, fraud signals, and basic troubleshooting. But IP geolocation is not the same as GPS. It estimates where a network endpoint appears to be located. It should not be treated as a precise physical address, and it should not be the only signal behind a security decision. ### What Public IP Geolocation Can Show A public IP address is the address websites and online services see when a device connects to them. A lookup tool can map that IP to useful network information such as country, region, city, timezone, ISP, ASN, hosting provider, or organization. This is enough for many everyday checks. For example, if you turn on a VPN server in another country, your public IP location should usually change to match that VPN exit region. If a login appears from a country you never use, it may deserve a closer look. If an IP belongs to a cloud provider instead of a residential ISP, that can also change how you interpret the traffic. ### What It Cannot Prove IP geolocation cannot prove a person's exact home, street, or real-time physical position. Many people share public IPs through offices, schools, public Wi-Fi, mobile networks, or carrier-grade NAT. VPNs and proxies can also make traffic appear to come from a different region. That means geolocation should be treated as context, not certainty. If the result looks suspicious, combine it with other signals such as account history, device information, request velocity, [fraud score](https://ip.crafzo.com/ip-fraud-score-checker), blacklist status, and user behavior. ### Safe Ways to Use It Start with a simple lookup of the public IP address. Review the location, ISP, connection type, and risk signals together. If the IP appears to be a VPN, proxy, hosting network, or known abuse source, use that information to decide whether to log, challenge, rate-limit, or manually review the request. For personal checks, compare your normal connection with your VPN or proxy connection. If the public IP or country does not change as expected, the VPN may not be active or the browser may be leaking traffic outside the tunnel. For website owners, avoid blocking solely because a geolocation result looks unusual. A traveler, mobile user, remote worker, or privacy-conscious visitor can appear in a different city or country for legitimate reasons. ### A Practical Review Workflow Use a consistent process whenever you inspect an IP address: Check the public IP and basic location. Review ISP, ASN, and organization details. Check whether the address is associated with a VPN, proxy, Tor, hosting provider, or data center. Look for blacklist or abuse signals. Compare the result with account history or expected user behavior. Decide whether to trust, challenge, rate-limit, or investigate. This keeps the lookup useful without overreacting to one field. ### Common Mistakes to Avoid Do not assume city-level data is always accurate. Mobile carriers and ISPs often route traffic through regional gateways. Do not assume a VPN is always malicious. Many people use VPNs for privacy, work, or travel. Do not expose sensitive user decisions based only on IP location, because the signal can change or be wrong. The best use of public IP geolocation is fast, practical context. It gives you a starting point for understanding traffic quality, privacy status, and security risk. ### Sources - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy - RFC 8805: A Format for Self-Published IP Geolocation Feeds: https://www.rfc-editor.org/rfc/rfc8805 ## Practical Guide to IP Lookup for Security and Geolocation Canonical: https://ip.crafzo.com/blog/ip-lookup Published: 2026-05-20 | Updated: 2026-09-25 | 6 min read What an IP lookup returns, how to read location, ISP, ASN and risk fields together, and how teams use lookups for fraud prevention and compliance. ### Overview Understanding where an IP address originates is a fundamental step in many security workflows. Whether you’re checking a login attempt, verifying a payment source, or investigating suspicious traffic, an IP lookup gives you context that raw numbers alone cannot provide. ### What an IP lookup actually returns When you query an IP address through a lookup service, you typically receive: Geographic data - country, region, city, and sometimes latitude/longitude. Network information - the owning ISP or organization, autonomous system number (ASN), and connection type. Reputation signals - whether the address appears on known blacklists, is associated with a VPN, proxy, Tor exit node, or hosting provider. These pieces of data are not magic; they come from databases that aggregate public routing information, user-submitted reports, and commercial feeds. The accuracy varies, but for most defensive use cases the granularity is sufficient to make informed decisions. ### Why IP lookup matters for security teams Knowing where a request comes from is the first requirement for protecting revenue-related systems: if you cannot trust the provenance of a connection, you cannot reliably apply access controls or fraud rules to it. In payment-focused environments, reducing fraud starts with validating that the IP initiating a transaction matches the expected geographic profile of the user. A sudden login from a high-risk country or a known proxy can trigger step-up authentication or transaction holds. Platforms serving emerging markets often lack local insight into which networks are normal for their users. IP-based checks give them a lightweight way to spot anomalous patterns without heavyweight local integrations, as long as shared carrier addresses are treated as context rather than as red flags. ### 1. Enriching login events When a user authenticates, pull the IP and run a quick lookup: If the country matches the user’s declared location, allow the flow. If the IP is flagged as a VPN or proxy, consider prompting for additional verification (e.g., OTP). If the address appears on a spam or abuse blacklist, block or challenge the request. ### 2. Filtering web traffic For public-facing APIs or websites, you can apply simple rules at the edge: if ip.country in HIGH_RISK_COUNTRIES: throttle_requests() elif ip.is_vpn or ip.is_proxy: require_captcha() elif ip.blacklisted: block() This approach reduces noise before it reaches your application logic, saving compute and limiting exposure. ### 3. Validating payment origins In a payment pipeline, after receiving a transaction request: Compare the IP’s country to the billing address country. A mismatch doesn’t automatically mean fraud, but it raises a risk score that can be fed into your decision engine. Use the ASN to detect traffic coming from known data centers or hosting providers, which are often used in card-testing attacks. ### 4. Monitoring for abuse Set up a scheduled job that scans recent failed login attempts or abusive API calls, enriches them with IP data, and aggregates by ASN or country. Spikes from a particular network can reveal coordinated attacks that single-event alerts might miss. ### When a check is worth running Not every request deserves a lookup. The moments that carry risk are login, signup, payment, password reset, admin access, API token creation and any change to an account's email, phone or payout details. Those are the points where an attacker gains something and where a few hundred milliseconds of extra context is cheap. Ordinary page views are not; running risk checks on every view adds latency and noise without protecting anything. At those moments, read the same fields together rather than any one alone: whether the location has changed for this account, the ISP or organization behind the address, whether it is a hosting range or a known proxy or VPN, the [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) for the address, request velocity, and whether this address has appeared for this account before. The goal is not to identify a person from an IP address, which a lookup cannot do; it is to judge whether the session looks like the account's normal behavior. Act on that judgment in proportion. Risk-based authentication, step-up verification and a review queue protect users without locking out the traveler, the VPN user or the customer whose carrier routes traffic through another city. Reserve hard blocks for patterns that clearly harm the service. ### A workflow for small teams Small sites see spam forms, fake accounts, odd login attempts and bot traffic long before they have anyone whose job is security. A lookup gives quick context: where the traffic appears to come from, and whether it looks like hosting, a proxy or an ordinary ISP connection. Keep the routine short. Check the address, note the country and provider, compare them with where your customers actually are, and look for repeated attempts from the same address or the same range. Then fix the thing the traffic is exploiting: strong passwords and MFA on admin logins, rate limits and a CAPTCHA on the abused form, and updates for the platform and its plugins. Start with admin logins, contact-form abuse, fake signups and repeated failed access attempts; that is where small businesses are hit first. Resist blocking whole countries or large ISPs unless you understand what that costs in real customers. Targeted rules with an expiry are safer, and reviewing them a month later tells you whether they are still earning their place. A lookup is an investigation tool, not a security system; it complements a firewall or a security plugin rather than replacing one. ### Choosing a lookup method You have three main options, each with trade-offs: Public APIs offer free tiers with limited queries per day. They’re ideal for low-volume testing or occasional checks. Remember to read the terms of use and to cache results where you can, so that a traffic spike does not turn into a rate-limit error at the worst moment. Commercial databases and feeds run locally or inside your own infrastructure, answer in microseconds and are licensed for production volume. They cost money and need regular updates to stay accurate, but they are the right choice when every login or transaction has to be enriched. A manual lookup page such as this one belongs in the review step rather than in the request path: an analyst pastes the address that your own rules flagged and reads the location, network and risk context together. It is free, needs no integration and is enough for incident triage, support investigations and small sites that check a handful of addresses a week. ### FAQ **Should every page view trigger IP risk checks?** Usually no. Focus deeper checks on risky actions and suspicious patterns. **Can IP lookup replace MFA?** No. It supports MFA and other controls but should not replace them. **Can IP lookup replace a security plugin?** No. It is an investigation tool, not a complete security system. **What should small businesses check first?** Focus on admin logins, contact form abuse, fake signups, and repeated failed access attempts. ### Sources - RFC 7020: The Internet Numbers Registry System: https://www.rfc-editor.org/rfc/rfc7020 - IANA: IPv4 Address Space Registry: https://www.iana.org/assignments/ipv4-address-space ## IP Location Lookup: How Country, City, and ISP Detection Works Canonical: https://ip.crafzo.com/blog/ip-location-lookup-guide Published: 2025-08-26 | Updated: 2026-09-22 | 2 min read A practical guide to IP geolocation databases, accuracy limits, and how to interpret country, city, latitude, longitude, and ISP fields. ### How IP geolocation works IP geolocation maps IP ranges to location records. These records are built from routing data, ISP allocations, network measurements, and commercial geolocation datasets. The result is an estimate, not a GPS reading. Country-level matches are often strong, while city-level results can vary depending on mobile carriers, VPNs, and ISP routing. ### Fields you should check Country and region help you understand the broad origin of an IP address. City, latitude, and longitude add more context, but they should be treated as approximate. ISP and organization fields are useful for identifying whether the address belongs to a consumer provider, cloud host, business network, or security service. ### When accuracy changes IP location can change when an ISP reassigns ranges, a user turns on a VPN, or traffic exits through a proxy. Mobile networks can also route users through distant gateways. For important decisions, combine IP lookup data with account history, device signals, payment risk, and user behavior instead of relying on location alone. ### FAQ **Why is my IP location wrong?** Your ISP, VPN, proxy, or mobile carrier may route traffic through a different city or region. **Can IP lookup identify an ISP?** Yes, many IP lookup databases include the ISP or organization that owns or operates the IP range. ## How to Find the ISP or Organization Behind an IP Address Canonical: https://ip.crafzo.com/blog/isp-lookup-from-ip Published: 2025-09-02 | Updated: 2026-09-22 | 2 min read How to find the ISP or organisation behind an IP address, where that data comes from, and why it matters when you triage traffic or a security alert. ### What ISP lookup reveals ISP lookup identifies the provider or organization associated with an IP range. It can show a broadband carrier, mobile network, university, company, or hosting provider. This context helps explain whether traffic looks like a normal home user, business connection, cloud server, or automated system. ### Why organization data matters A login from a known home ISP may carry different risk than a login from a cloud data center. A signup from an anonymizing network may need extra verification. Organization data also helps developers debug webhook sources, API clients, and server-to-server traffic. ### How to check an IP owner Run the address through Crafzo IP Lookup and review the location and risk panels. The ISP or network context can guide next steps. For legal ownership or abuse reporting, you may also need WHOIS records from the relevant regional internet registry. ### FAQ **Is ISP the same as IP owner?** Not always. The ISP may operate the network, while allocation records can list a parent organization. **Can ISP lookup identify a person?** No. It identifies a network provider or organization, not an individual subscriber. **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ## Public vs Private IP Address: The Simple Difference Canonical: https://ip.crafzo.com/blog/public-vs-private-ip Published: 2025-09-03 | Updated: 2026-09-25 | 6 min read Public addresses are routable on the internet; private ranges such as 192.168.x.x and 10.x.x.x never leave your network. Why a lookup only ever sees the public one. ### Two kinds of address The internet routes packets by destination address, which only works if every address on the public internet is unique. Public addresses are globally unique and routable: every router on the internet knows how to forward a packet toward them. Private addresses come from ranges that RFC 1918 set aside for use inside networks; routers on the public internet drop packets addressed to them, and the same private address is in use in millions of homes at once without conflict, because it never has to be unique beyond the network it belongs to. ### Private IP addresses Private IP addresses are used inside local networks. Common ranges include 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. | Range (RFC 1918) | CIDR | Addresses | Where you usually meet it | | --- | --- | --- | --- | | 10.0.0.0 to 10.255.255.255 | 10.0.0.0/8 | 16,777,216 | Corporate networks, cloud VPCs, large campuses | | 172.16.0.0 to 172.31.255.255 | 172.16.0.0/12 | 1,048,576 | Docker default networks, mid-sized offices | | 192.168.0.0 to 192.168.255.255 | 192.168.0.0/16 | 65,536 | Home and small-office routers | These addresses are not directly reachable from the public internet and are often reused in homes, offices, and internal systems. That reuse is the point: your laptop, printer and television can be 192.168.1.10, .11 and .12, and so can the same devices in every other home on the street. ### Public IP addresses A public IP address is routable on the internet. It is the address websites see when your router, server, VPN, or mobile network sends traffic. Public addresses are allocated by the Regional Internet Registries to ISPs and organizations, which assign them to customers. A home connection normally gets a dynamic address the ISP can change; servers and business lines can pay for a static one. If multiple devices use the same router, they share one public IP while keeping separate private addresses inside the network. ### NAT: one public address for a whole network Your router bridges the two worlds with Network Address Translation, described in RFC 3022. When a device sends a packet to the internet, the router swaps the private source address and port for its own public address and a port it chooses, and records the mapping; when the reply arrives at that public address and port, it forwards the packet to the right device. Every outbound connection gets its own entry, so dozens of devices share one address without confusion. Two consequences follow. Websites see the whole household as one address, which is why lookups from your phone and your laptop on the same Wi-Fi agree. And an unsolicited inbound connection has no mapping to follow, so it is dropped unless you create one by hand, which is what port forwarding does. ### Carrier-grade NAT: when the public address is shared too Many ISPs, and most mobile carriers, add a second layer of NAT inside their own network so that many customers share one public IPv4 address. For the link between their equipment and yours they use 100.64.0.0/10, the shared address space RFC 6598 reserved for exactly this purpose. It is neither private in the RFC 1918 sense nor public: not routable on the internet, and not meant to appear inside your home network either. A router WAN address between 100.64.0.0 and 100.127.255.255 means you are behind carrier-grade NAT; the [CGNAT guide](https://ip.crafzo.com/blog/cgnat-shared-ip-addresses) explains what that changes. ### How to see your private and public addresses The private address is the one your operating system reports: ipconfig on Windows, ifconfig or ip addr on macOS and Linux, the Wi-Fi network's details on a phone. Your router's admin page lists both sides, the LAN address it uses inside your network and the WAN address it received from the ISP. The public address is the one a website receives, so the reliable way to see it is an IP lookup, which shows the address the request arrived from with the ISP and approximate location. Compare it with the router's WAN address: a match means your router holds the public address itself; a WAN address in 100.64.0.0/10 or in a private range means another layer of NAT sits above you. The [guide to checking your own IP address](https://ip.crafzo.com/blog/how-do-i-check-my-own-ip-address) covers the command-line methods. ### Why an external lookup cannot see 192.168.x.x By the time a packet leaves your network, NAT has replaced the private address with the public one. The website's server receives only the public address; the private one never crosses the router, and the site has no way to ask for it. Looking up 192.168.1.1 on a geolocation service therefore returns nothing meaningful: the address exists in almost every home and office on Earth, so it has no ISP, no city and no reputation of its own. IP geolocation tools are most useful for public IP addresses. Private addresses generally do not map to a public city, ISP, or risk profile. Use Crafzo IP Lookup to check the public IP visible to websites or analyze another public address. ### The IPv6 equivalents IPv6 keeps the same split under different names. Global unicast addresses, defined in RFC 4291 and currently allocated from 2000::/3, are the public addresses; the address space is so large that each device normally gets its own instead of sharing through NAT. Unique local addresses, defined in RFC 4193, are the private equivalent: they live in fc00::/7 (in practice fd00::/8), carry a random 40-bit identifier so that two networks rarely collide when they are later joined, and are not routed on the internet. NAT is not part of the normal IPv6 design; the protection people associate with it comes from the firewall, and privacy comes from temporary addresses that rotate on a schedule, covered in the [IPv4 versus IPv6 guide](https://ip.crafzo.com/blog/ipv4-vs-ipv6-what-the-shift-means-for-your-privacy). For the complete list of reserved and special-purpose ranges in both protocols, see [private, reserved and special IP addresses](https://ip.crafzo.com/blog/private-reserved-special-ip-addresses). ### FAQ **Can I look up 192.168.1.1?** That is a private address and normally will not have public geolocation data. It is in use inside countless networks at once, so no ISP, city or reputation can be attached to it. **Why do my devices share one public IP?** Your router uses NAT so many local devices can access the internet through one public address; it maps each outbound connection to its own port and routes the replies back. **Is 100.64.x.x a private IP address?** Not in the RFC 1918 sense. It is the shared address space RFC 6598 reserved for carrier-grade NAT; seeing it on your router's WAN side means your ISP shares one public address among several customers. **Do I need NAT with IPv6?** Normally no. Each device gets a global unicast address of its own, the firewall provides the inbound protection, and unique local addresses exist for traffic that should stay inside the network. ### Sources - RFC 1918: Address Allocation for Private Internets: https://www.rfc-editor.org/rfc/rfc1918 - RFC 3022: Traditional IP Network Address Translator (Traditional NAT): https://www.rfc-editor.org/rfc/rfc3022 - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space: https://www.rfc-editor.org/rfc/rfc6598 - RFC 4291: IP Version 6 Addressing Architecture: https://www.rfc-editor.org/rfc/rfc4291 - RFC 4193: Unique Local IPv6 Unicast Addresses: https://www.rfc-editor.org/rfc/rfc4193 - IANA: IPv4 Special-Purpose Address Registry: https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml ## Reduce Fake Signups With IP Risk Signals Canonical: https://ip.crafzo.com/blog/reduce-fake-signups-with-ip-risk Published: 2025-09-10 | Updated: 2026-09-26 | 7 min read Use IP reputation, velocity, proxy detection, and location context to reduce fake accounts without hurting good users. ### What fake signups are for A fake signup is an account created to be misused rather than used. OWASP's catalogue of automated threats lists it as OAT-019 Account Creation: bulk account creation, sometimes with populated profiles, through the application's own sign-up process, with the accounts then used for content spam, laundering cash and goods, spreading malware, damaging reputation, and skewing search rankings, reviews and surveys. Add promotional abuse, referral fraud, free-tier farming, marketplace scams and scraping under many identities, and the list covers most of what security and trust teams see. The economics explain the pattern. One account is worth little; a thousand are worth a campaign. So the attacker automates, and automation leaves traces in exactly the places IP data can see: how many accounts came from where, how fast, and through what kind of network. ### Signup is not login Keep the two problems separate, because their signals and their remedies differ. Signup risk is about account creation: there is no history for this user, no established device, no known location, and the question is whether a person is creating one account for themselves. Login risk is about access to an account that already exists: there is history to compare against, and the question is whether the person at the door is the owner. OWASP draws the same line, distinguishing Account Creation from Credential Cracking and Credential Stuffing, which use existing accounts. This guide is about the first problem. For the second, the [credential stuffing guide](https://ip.crafzo.com/blog/credential-stuffing-ip-intelligence) and the [login risk guide](https://ip.crafzo.com/blog/ip-intelligence-for-login-risk) cover the account-history signals that signups do not have. ### The IP signals that matter at signup Velocity. Count signups per address, per /24 and per ASN over minutes, hours and days. A household creates one account, occasionally two; an address creating twenty in an hour is running a script or standing in front of many people. Slower farms space their signups out, so the daily and weekly counts per subnet matter as much as the burst. Same IP, same subnet. Accounts created from one address or adjacent addresses that then behave alike (the same referral code, the same product listed, the same review text) are a cluster, and clusters are what account farms look like from the outside. Track the link between accounts and creation addresses even when nothing fires at signup, because it is what you will need when the abuse shows up later. Hosting, proxy and VPN indicators. A signup form is built for people, so an address from a cloud or hosting network is unusual there, and a proxy or VPN exit is worth noting. Neither is disqualifying: privacy tools are legitimate and popular, and a corporate egress can sit in a data center. Treat them as one input to a score rather than a reason to refuse; the [data center versus residential guide](https://ip.crafzo.com/blog/data-center-ip-vs-residential-ip) and the [VPN and proxy checker](https://ip.crafzo.com/vpn-proxy-checker) cover the classification. Disposable email correlation. Throwaway mailbox domains combined with a hosting address or a rotating proxy are a stronger pattern than either alone. A disposable address from a residential connection is often just a privacy-conscious person. Device and account context. A device identifier or browser fingerprint that has already created several accounts, a form completed in under a second, or profile fields filled with the same template are behavioral signals that confirm what the network data only suggests. ### False positives from shared networks The signals above break when many people share one address. Carrier-grade NAT puts thousands of mobile subscribers behind a single public address, using the shared address space that RFC 6598 reserved for it; a university, a hospital or a large employer routes a whole campus through a few egress points; a popular event fills one venue's Wi-Fi with genuine new users. A per-address signup velocity rule fires on all of them, and a hard block turns away every real person behind the address for as long as the rule stands. The [CGNAT guide](https://ip.crafzo.com/blog/cgnat-shared-ip-addresses) explains why one address can mean a crowd. The fix is structural rather than a bigger threshold: recognize mobile and CGNAT ranges from the ASN and treat their velocity limits as soft, prefer friction to refusal, and use device and behavior signals to separate the individuals sharing the address. ### Scoring rather than blocking Combine the signals into a risk score for the signup, weighting behavior and device context alongside the network data, and let the score choose a response. A network-level [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) for the address is one input; it summarizes the address's recent history, not the intent of the person using it now. Log the score and its components with every account created, whether or not anything was triggered, so that when abuse surfaces a week later you can see what the account looked like at birth and tune the weights against real outcomes instead of intuition. ### A friction ladder Match the friction to the score, and start low. A CAPTCHA or an equivalent proof-of-humanity challenge filters simple automation at almost no cost to people. Email verification confirms control of a mailbox and slows bulk creation; it is the reasonable default for a medium score. Phone verification raises the cost per account considerably and belongs where the account can do real damage, such as payouts, marketplace listings or messaging other users; it also excludes people who cannot or will not share a number, so use it where the value justifies that. Step-up review, a manual check or a delay before the account gains sensitive capabilities, is for the highest scores. Two rungs are missing on purpose. Blocking by country turns away every legitimate user in a market over the behavior of a few, and blocking on the IP address alone inherits every shared-address false positive described above. Both belong at the very top of the ladder, for narrow, evidenced, expiring cases. OWASP's guidance on unrestricted access to sensitive business flows, whose examples include scripted registration for referral credit, recommends the same layered approach: device fingerprinting, human detection, and treating non-human request patterns as a trigger for friction. None of this is identity proofing. NIST SP 800-63A describes the assurance levels at which an enrollment verifies who a person is; at the lowest, attributes are self-asserted and nothing is checked, which is where almost every consumer signup sits. The ladder above decides how much automation to tolerate, not whether the name on the form is real. ### Measuring false positives A signup defense that is never measured drifts toward refusing people. Track the share of challenged signups that complete verification, the share that abandon, and the appeals or support tickets that follow. Sample the accounts that were challenged or refused and check how many later turned out to be legitimate; sample the accounts that passed and check how many were abusive. Break both down by network type and country, because the cost of a rule is rarely spread evenly. Travelers, privacy-tool users and mobile users on carrier NAT are the usual casualties, and the numbers are the only argument that will change a threshold. ### FAQ **Can attackers rotate IP addresses?** Yes, through proxies, VPNs, cloud instances and residential proxy networks. Per-address rules alone are easy to evade, so combine IP signals with device, behavior and email context, and track clusters by subnet and ASN. **Should signups from VPNs be blocked?** Usually not automatically. A VPN exit is a signal that raises the score, not a verdict; apply proportionate friction such as email verification and reserve refusal for signups that combine several strong signals. **Is signup risk the same as login risk?** No. Signup risk concerns creating new accounts with no history to compare against; login risk concerns access to existing accounts and relies on that history. The signals overlap but the remedies differ. **What friction should I add first?** A proof-of-humanity challenge, then email verification for medium-risk signups. Add phone verification or manual review only where the account can do real damage, and measure completion and abandonment at each rung. ### Sources - OWASP Automated Threats to Web Applications: OAT-019 Account Creation: https://github.com/OWASP/www-project-automated-threats-to-web-applications/blob/master/assets/oats/EN/OAT-019_Account_Creation.md - OWASP API Security Top 10 2023: API6 Unrestricted Access to Sensitive Business Flows: https://owasp.org/API-Security/editions/2023/en/0xa6-unrestricted-access-to-sensitive-business-flows/ - OWASP Cheat Sheet Series: Credential Stuffing Prevention: https://cheatsheetseries.owasp.org/cheatsheets/Credential_Stuffing_Prevention_Cheat_Sheet.html - NIST SP 800-63A: Digital Identity Guidelines: Enrollment and Identity Proofing: https://csrc.nist.gov/pubs/sp/800/63/a/upd1/final - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space: https://www.rfc-editor.org/rfc/rfc6598 ## Understanding AI-Powered IP Health Analysis Canonical: https://ip.crafzo.com/blog/understand-ip-health-analysis Published: 2025-09-12 | Updated: 2026-09-25 | 2 min read What the AI-generated intelligence summary does with location, risk and reputation data, how to read it as a synthesis rather than a verdict, and when to ignore it. ### Why summaries help Raw IP data can be noisy. Location, ISP, [fraud score](https://ip.crafzo.com/ip-fraud-score-checker), and risk labels are easier to use when summarized in plain language. AI-powered health analysis can explain what the signals mean and suggest reasonable next steps for review. ### What the AI should consider A good IP health summary considers the IP address, fraud score, risk level, location context, and whether the network looks like residential, business, proxy, or hosting traffic. It should avoid treating any single field as absolute proof. ### How to use it Use the summary as analyst assistance. For high-stakes decisions, review the underlying data and your own logs. Crafzo IP Lookup combines the data and summary so you can move from quick lookup to practical judgment. ### FAQ **Can AI determine if an IP is malicious?** It can summarize risk signals, but it should not be treated as final proof by itself. **What is IP health?** IP health describes the trust, risk, reputation, and network context of an IP address. **Can IP geolocation show my exact address?** No. IP geolocation usually estimates a country, region, city, ISP, or network route. Treat it as network context rather than GPS-level location. **Why can my IP location look different from my real location?** VPNs, proxies, mobile carriers, ISP routing, shared networks, and stale databases can all make an IP appear in a different city or country. **What should I compare before trusting an IP lookup result?** Compare the country, region, ISP, ASN, VPN or proxy status, reputation signals, and account activity. One IP field alone is rarely enough for a high-confidence decision. ## Why Does a Website Show the Wrong IP Address? Canonical: https://ip.crafzo.com/blog/troubleshoot-wrong-ip-address Published: 2025-09-13 | Updated: 2026-09-22 | 1 min read Troubleshoot why websites may show a different IP than expected, including VPNs, proxies, NAT, mobile networks, and IPv6. ### Common causes A website may show a different IP because you are using a VPN, proxy, corporate gateway, mobile carrier NAT, or IPv6 connection. Your device's private local IP is also different from the public IP websites see. ### What to compare Check your router, device network settings, VPN app, and a public IP lookup tool. Compare whether IPv4 and IPv6 results differ. If only one website shows a strange result, caching, proxy headers, or security services may be involved. ### Fast troubleshooting steps Turn off VPN or proxy temporarily, refresh the lookup, restart the network connection, and test from another browser or device. Use Crafzo IP Lookup to confirm the public IP and location that external websites can see. ### FAQ **Why is my phone IP different from Wi-Fi?** Mobile data and Wi-Fi use different networks, so they usually have different public IPs. **Can IPv6 make results look different?** Yes. A site may see your IPv6 address while another sees IPv4. ## How to Hide Your IP Address: 5 Methods Explained Canonical: https://ip.crafzo.com/blog/how-to-hide-ip-address Published: 2026-05-02 | Updated: 2026-09-22 | 2 min read Compare VPNs, proxies, Tor, mobile data switching, and public Wi-Fi as methods for changing or masking your visible IP address. ### VPNs, proxies, and Tor A VPN routes your traffic through an encrypted tunnel and makes websites see the VPN server IP instead of your normal connection. It is the most practical option for everyday privacy, but the VPN provider can still see connection metadata and some websites may identify known VPN ranges. A proxy forwards selected traffic through another server, while Tor sends traffic through multiple volunteer relays for stronger anonymity at the cost of speed and compatibility. Proxies are useful for specific apps or testing, while Tor is better when anonymity matters more than convenience. ### Network switching methods Switching from home Wi-Fi to mobile data usually changes your public IP because it moves you to a different carrier network. Restarting a router may also change a dynamic IP, though many ISPs keep the same address until their lease or assignment changes. Public Wi-Fi can also show a different IP, but it is not a privacy solution by itself. The network operator may monitor traffic, and unsecured Wi-Fi adds risks unless your apps use HTTPS and you trust the hotspot. ### Verify the change After changing networks or enabling a privacy tool, check Crafzo before and after to confirm the public IP, ISP, and location changed. If the IP is the same, the tool may not be active for that browser or device. Hiding an IP does not erase browser fingerprints, cookies, account logins, or payment records. For real privacy gains, combine IP masking with careful account separation and browser privacy controls. ### FAQ **Does a VPN completely hide my IP?** A VPN hides your normal public IP from the websites you visit, replacing it with the VPN exit IP. It does not make you invisible to the VPN provider, logged-in services, cookies, or browser fingerprinting. **Can websites still track me if I hide my IP?** Yes. Websites can still use cookies, account logins, device fingerprints, and behavior patterns to recognize you across sessions. **Is hiding your IP address legal?** In most places, using a VPN or proxy for privacy is legal. What you do while using it still matters, and some services restrict VPN use in their terms. ## Why Does Your IP Address Keep Changing? Canonical: https://ip.crafzo.com/blog/why-does-ip-address-change Published: 2026-05-04 | Updated: 2026-09-22 | 2 min read Most home connections use dynamic addresses that ISPs reassign. Why your public IP changes, how static addresses differ, and how to check what you have right now. ### Static versus dynamic IPs A static IP is meant to stay the same for a long period, often because a business, server, camera system, or remote-access setup needs predictable connectivity. A dynamic IP is assigned from an ISP pool and can change when the network renews or reassigns the lease. Most home internet plans use dynamic public IPs because they are easier for ISPs to manage. The address may stay stable for weeks or months, but it is not guaranteed unless the provider explicitly sells a static option. ### Why reassignment happens DHCP lease expiry, router reconnects, maintenance, outages, and ISP pool balancing can all cause a new address to appear. Mobile data changes even more often because carrier routing and tower handoffs can move sessions through different gateways. A VPN, proxy, or workplace network can also make it look like your IP changed even when your home connection stayed the same. The visible address is the network exit point websites see. ### How to check your current address Use Crafzo to check your current public IP before and after restarting a router, switching networks, or enabling a VPN. Compare the ISP and location fields as well as the IP string. If you host services at home, do not rely on a dynamic IP staying fixed. Use dynamic DNS or ask your ISP about a static public IP plan. ### FAQ **How often does an IP address change?** It depends on the ISP, plan, router behavior, and connection type. Some dynamic IPs change after a restart, while others stay the same for long periods. **Can I get a static IP for free?** Usually no. Some providers include static addressing on business plans, but many charge extra or do not offer it on residential plans. **Does restarting my router change my IP?** Sometimes. If your ISP assigns a new lease after reconnecting, the public IP may change, but many providers reassign the same address. ## IP Fraud Score: What the Numbers Actually Mean Canonical: https://ip.crafzo.com/blog/ip-fraud-score-explained Published: 2026-05-05 | Updated: 2026-09-25 | 3 min read A plain-language guide to reading IP fraud scores — what the 0–100 scale means, what triggers a high score, and how to use it without over-blocking. ### Reading the score bands Crafzo shows the Scamalytics band next to the score, and the bands are the provider's documented ones: 0-19 low, 20-59 medium, 60-89 high, 90-100 very high. The score comes from Scamalytics, which describes it as the approximate share of users seen from that address who were linked to fraudulent activity: a score of 70 means roughly 7 in 10. Crafzo shows the provider's band with the score (0-19 low, 20-59 medium, 60-89 high, 90-100 very high). The band is a triage signal, not a verified probability for your traffic, and the provider recommends adjusting thresholds to your own fraud data. Other providers cut their 0-100 scales differently, so a 30 from one service and a 30 from another are not the same statement. Always read a score together with the provider that produced it. A low score does not prove a user is safe, and a high score does not prove a user is malicious. It is a triage signal that should change how much verification or review you apply. ### Signals that raise risk Proxy and VPN usage, data center ownership, recent abuse history, blacklist appearances, unusual country changes, and high request velocity can all push a score upward. Some systems also weigh bot behavior, disposable infrastructure, and known credential attack patterns. Legitimate users can inherit risk from shared networks, mobile gateways, public Wi-Fi, or a reused IP that previously belonged to someone else. That is why [fraud scores](https://ip.crafzo.com/ip-fraud-score-checker) work best with account history and behavior logs. ### How to act on scores Use low scores for normal flow, medium scores for logging or light friction, and high scores for step-up verification, rate limits, or manual review. Hard blocks should be reserved for strong score plus strong behavior evidence. Crafzo helps make scores readable by showing the IP context next to location and network signals. That broader view reduces the risk of over-blocking good users. ### FAQ **What is a good IP fraud score?** Lower is generally better, and a score under 25 is often treated as low risk. You should still compare it with the action, account history, and business impact. **Should I block all high score IPs?** Not automatically. High scores should usually trigger verification, throttling, or review before a permanent block. **Can a legitimate user have a high fraud score?** Yes. Shared networks, VPNs, public Wi-Fi, mobile gateways, and previously abused IPs can create false positives. ## How to Check if an IP Address Is Blacklisted (Step by Step) Canonical: https://ip.crafzo.com/blog/how-to-check-ip-blacklist Published: 2026-05-06 | Updated: 2026-09-25 | 5 min read A practical guide to finding out whether an IP is on a blacklist, what it means, and what to do about it. ### What IP blacklists are An IP blacklist, sometimes called a denylist, is a list of addresses associated with spam, malware, abuse, open proxies, bot traffic, or policy violations. Email providers, firewalls, anti-fraud systems, and security products use these lists to decide when to reject or challenge traffic. A listing does not always mean you personally did something wrong. Shared hosting, dynamic ISP assignments, compromised devices, public Wi-Fi, and old abuse history can all cause innocent users to inherit reputation problems. Most blocklists are DNS zones, which is why they are called DNSBLs. A checker reverses the address's octets, appends the list's zone (1.2.3.4 becomes 4.3.2.1.zen.spamhaus.org) and asks DNS: an answer in 127.0.0.0/8 means listed, no answer means not listed on that zone. Every list runs its own zone with its own criteria, so an address can sit on one list and be absent from ten others, which is why multi-list checkers such as MXToolbox or MultiRBL query dozens of zones in one pass. Most of these zones cover IPv4 only; if your traffic leaves over IPv6, use a checker that also queries IPv6 lists. ### Step-by-step checking process First, find the exact public IP you want to test, then run it through Crafzo for location, network, and risk context. Next, check one or more blacklist lookup tools, record which lists show a hit, and note the timestamp because listings can change. Which checker to use depends on the symptom. For email delivery problems, query Spamhaus directly at check.spamhaus.org: it tells you whether the address is on SBL (spam sources), XBL (compromised or infected hosts), PBL (end-user ranges that should not send mail directly) or CSS, and why. MXToolbox's blacklist check queries dozens of DNS-based lists in one pass and is the quickest way to see how widespread a listing is. Crafzo's own Blacklist signal reports the external lists its risk provider consults; it is a starting point, not a substitute for the list operators' own lookups. If the issue affects email, inspect mail server logs and authentication records such as SPF, DKIM, and DMARC. If it affects website access, compare the blacklist result with WAF logs, [fraud scores](https://ip.crafzo.com/ip-fraud-score-checker), and recent request patterns. ### What to do after a listing Fix the root cause before requesting delisting: remove malware, close open relays, stop spam, rotate compromised credentials, or reduce abusive traffic. Delisting without remediation often leads to relisting. Most reputable lists publish a delisting process or contact path. Provide the IP, the fix performed, and evidence that the abuse has stopped. A worked example: a small business finds its mail server address on Spamhaus XBL after a staff laptop was infected. Cleaning the laptop comes first; the listing exists because the infected machine was sending spam. Then the address is looked up again at check.spamhaus.org, which offers a self-service removal for XBL and CSS listings once the traffic has stopped. A PBL listing is different: it is a policy statement that the range is dynamic or residential, so the fix is to send through the ISP's or a provider's authenticated relay, or to request a PBL exception for a static mail server. Re-check a day later, because some lists refresh on a delay, and keep the timestamps of the listing, the fix and the removal request in case a customer asks. ### FAQ **Does being blacklisted affect my internet?** It can affect specific services such as email delivery, login access, or websites with strict security rules. It usually does not mean your entire internet connection stops working. **How long do IP blacklists last?** Some listings expire automatically after the abuse stops, while others require a delisting request. Duration depends on the list, severity, and whether bad traffic continues. **Can my IP be blacklisted without me knowing?** Yes. Malware, shared hosting neighbors, old assignments, or other users behind the same public IP can create a listing before you notice symptoms. **What does it mean if my IP is on a blacklist?** It means that one or more DNS-based blacklists have identified your IP as a source of spam, malware, or other abusive activity, which can cause emails to be rejected or services to block connections from that address. **How often should I check my IP for blacklist listings?** If you run a mail server, VPN, or any service that sends email, check at least weekly. For general users, a monthly check or after noticing delivery problems is sufficient. **Can I remove my IP from a blacklist myself?** Most blacklists offer a self-service delisting form or request process. You must first resolve the underlying issue (e.g., stop spamming, secure compromised devices) then submit a removal request following the list’s specific guidelines. **Does one blacklist mean an IP is dangerous?** Not always. Check the list type, timing, and related behavior. **Can blacklists be outdated?** Yes. IP reputation can lag behind real-world changes and reassignment. ### Sources - Spamhaus: IP and Domain Reputation Checker (Blocklist Removal Center): https://check.spamhaus.org/ - MXToolbox: Blacklist Check: https://mxtoolbox.com/blacklists.aspx - Spamhaus Blocklist (SBL): https://www.spamhaus.org/blocklists/spamhaus-blocklist/ - MultiRBL.valli.org: multi-DNSBL check: https://multirbl.valli.org/ ## How to Tell if an IP Address Is a VPN or Real User (Checklist) Canonical: https://ip.crafzo.com/blog/how-to-tell-if-ip-is-vpn Published: 2026-05-07 | Updated: 2026-09-25 | 2 min read A checklist of signals that help identify whether traffic is coming from a VPN, proxy, or genuine consumer ISP connection. ### Checklist: provider and ASN clues Check the ISP or organization name first. Consumer broadband and mobile carriers usually look different from hosting providers, cloud networks, VPN brands, privacy services, and companies that operate large data center ranges. Review the ASN and network owner next. A residential-looking IP in a normal consumer ASN is less suspicious than an address announced by a cloud provider, proxy operator, or infrastructure company used for automation. ### Checklist: risk and behavior clues Compare proxy flags, [fraud score](https://ip.crafzo.com/ip-fraud-score-checker), abuse history, country mismatch, and whether the IP appears in known VPN or data center ranges. A single flag is helpful, but multiple matching signals are much stronger. Look at behavior before enforcement: request velocity, login failures, signup bursts, payment attempts, endpoint mix, and account age. Real users can use VPNs, while attackers can sometimes use residential networks. ### Checklist: decision path For low-risk browsing, log the signal and keep the user moving. For account recovery, checkout, admin actions, or repeated automation, require MFA, throttle requests, or route the session to review. Use Crafzo to inspect the IP quickly, then compare the visible network with your own logs. The goal is to decide whether the session needs more proof, not to punish privacy tools automatically. ### FAQ **Can all VPNs be detected?** No. Many well-known VPN exits are detectable, but smaller providers and residential proxy networks can be harder to classify. **Do VPN IPs have different fraud scores?** Often they do, especially if the IP is shared, abused, or hosted in a data center. A VPN flag may raise risk, but behavior and account context still matter. **What does a VPN IP look like in logs?** It may show a hosting provider, VPN organization, unusual country, high reuse across many accounts, or a known proxy classification. Some workplace VPNs may simply look like a company network. **Are all VPN users bad?** No. VPNs are often used for privacy, work, and travel. Treat them as a risk signal, not automatic proof. **What is a data center IP?** It is an IP address assigned to a hosting, cloud, or server provider instead of a typical home ISP. ## My IP Lookup Shows the Wrong Location — Here Is Why Canonical: https://ip.crafzo.com/blog/ip-lookup-wrong-location-reasons Published: 2026-05-08 | Updated: 2026-09-22 | 2 min read Seven common reasons why an IP address lookup returns an unexpected city, country, or ISP — and how to interpret the result correctly. ### VPNs, proxies, and ISP gateways Reason one is a VPN: the lookup sees the VPN exit server, not your normal network. Reason two is a proxy, workplace gateway, or security service that forwards traffic through a different city or organization. Reason three is your ISP gateway. Many broadband providers route traffic through regional hubs, so the city in the lookup may be where the network exits rather than where your device sits. ### Shared networks and database lag Reason four is CGNAT or another shared-IP setup where many customers appear behind one public address. Reason five is mobile routing, because carriers often send traffic through gateways far from the handset. Reason six is stale geolocation data. IP ranges move between providers and locations, and lookup databases may update on different schedules. ### CDNs, satellite links, and interpretation Reason seven is infrastructure such as a CDN, satellite provider, or enterprise network that makes location less direct. These systems optimize routing and coverage, not perfect city labels. When a result looks wrong, compare the IP, ISP, ASN, VPN status, and country before assuming a problem. Crafzo gives a fast view of those fields so you can separate privacy tools from normal routing quirks. ### FAQ **How do I get my IP location corrected?** You can report the correction to major geolocation database providers or ask your ISP whether the allocation data is current. Updates may take time because each database maintains its own records. **Is a wrong IP location a security issue?** Not usually by itself. It can be a clue to check VPNs, proxies, or account activity, but routing and database lag are common explanations. **Why does my IP show a different country?** A VPN, proxy, satellite provider, mobile carrier, or outdated database can make an IP appear in another country. Check the ISP and network fields before assuming the lookup is tracking your physical location. ## How to Get the User IP Address in Next.js App Router Canonical: https://ip.crafzo.com/blog/get-user-ip-nextjs-app-router Published: 2026-05-09 | Updated: 2026-09-22 | 2 min read A developer guide to reading the real client IP in Next.js 14 App Router using headers(), middleware, and edge runtime considerations. ### Read proxy headers on the server In the App Router, read request headers from server components, route handlers, or server actions when the runtime provides them. A simple helper can start with `const list = headers().get("x-forwarded-for"); const ip = list?.split(",")[0]?.trim();` and fall back to `x-real-ip` or platform-specific headers. Do not expect browser-side code to know the real public IP without calling a server or lookup service. The client sees its network APIs, while the server sees the connection metadata and proxy headers. ### Middleware and route handlers Middleware can inspect `request.headers.get("x-forwarded-for")`, `request.headers.get("x-real-ip")`, or provider headers before rewriting, redirecting, or adding request context. Keep middleware light because it runs on every matched request. In an App Router API route, use `export async function GET(request: Request) { const forwarded = request.headers.get("x-forwarded-for"); return Response.json({ ip: forwarded?.split(",")[0]?.trim() ?? null }); }`. Validate and normalize the value before storing or enforcing rules. ### Platform differences Vercel, Cloudflare, load balancers, and reverse proxies may set different headers such as `x-forwarded-for`, `x-real-ip`, `cf-connecting-ip`, or vendor-specific equivalents. Document which proxy you trust and which header wins. If you deploy behind multiple proxies, only trust forwarded headers from infrastructure you control. For manual verification, compare the captured IP with Crafzo and confirm the location and ISP match expectations. ### FAQ **Why does headers() return undefined for IP?** Next.js does not create a universal IP field for every environment. You usually need to read proxy headers, and local development may not include them. **How do I get IP in an API route with App Router?** Use the `Request` object inside `app/api/.../route.ts` and read headers such as `x-forwarded-for` or `x-real-ip`. Split `x-forwarded-for` carefully and trust it only behind known proxies. **Does Vercel add a real IP header?** Vercel commonly forwards client IP information through standard proxy headers. Check your current deployment headers because edge, serverless, and custom proxy setups can differ. ## X-Forwarded-For Header: How to Get the Real Client IP Behind a Proxy Canonical: https://ip.crafzo.com/blog/x-forwarded-for-real-client-ip Published: 2026-05-10 | Updated: 2026-09-25 | 3 min read X-Forwarded-For carries the client address through proxies and CDNs, and anyone can forge it. How to read it safely from a trusted hop and get the real client IP. ### Header format and order The `X-Forwarded-For` header is a comma-separated list of IPs added by proxies, often shaped like `client, proxy1, proxy2`. Many apps use the leftmost value as the original client IP, but that is safe only when the header chain is controlled by trusted infrastructure. If any public client can send requests directly to your app, it can also send a fake `X-Forwarded-For` header. Your server must know which proxy added or sanitized the header before using it for rate limits, logging, or security decisions. ### Trusted proxy pattern A safer pattern is to maintain a trusted proxy list and walk the forwarded chain from right to left until you reach the first untrusted address. In TypeScript, that means parsing the header into IP strings, validating each item, and comparing proxy hops against your known load balancer or CDN ranges. Cloudflare users should prefer `CF-Connecting-IP` when requests are guaranteed to come through Cloudflare. Vercel and many load balancers expose `x-real-ip` or normalized forwarded headers, but you should still confirm the deployment behavior. ### Use the result responsibly Once extracted, normalize the IP and store the original header only if you have a clear debugging or security need. Be careful with private, loopback, malformed, or reserved addresses because they should not be treated as public user locations. For high-risk decisions, combine the extracted client IP with account history, request velocity, authentication state, and lookup results. Crafzo is useful for checking whether the chosen IP belongs to the expected country, ISP, or proxy type. Validate the value before you look it up or store it. Accept both address families: a growing share of real clients, especially on mobile carriers, arrive over IPv6, and a check that only understands dotted-decimal IPv4 will reject or mishandle them. Normalize the address (IPv6 has several equivalent spellings) and treat empty, malformed, and private-only inputs as errors when a public location is what you need. ### FAQ **Can X-Forwarded-For be faked?** Yes. Any client can send that header unless your trusted proxy strips or rewrites it before traffic reaches the app. **Which IP in X-Forwarded-For is real?** The original client is often the leftmost IP, but that rule is only safe when the entire proxy chain is trusted. In more complex setups, validate from the trusted edge inward. **How do I validate the forwarded IP?** Parse each value as IPv4 or IPv6, reject malformed entries, and trust only headers delivered by your own proxy or CDN. Then compare proxy hops against a maintained trusted range list. **Do I need IPv6 validation?** Yes. Modern users and carriers increasingly use IPv6. ## 7 Signs Your IP Address Has Been Flagged as Suspicious Canonical: https://ip.crafzo.com/blog/signs-ip-flagged-suspicious Published: 2026-05-11 | Updated: 2026-09-22 | 2 min read Recognise the signs that your IP has been flagged by fraud systems, email filters, or security tools — and what to do about it. ### User-facing warning signs Repeated captchas, login challenges, blocked account actions, and messages saying access is restricted can all indicate that an IP has poor reputation or looks automated. These signs are especially meaningful when they happen across multiple unrelated websites. Email delivery problems are another clue. If messages from your server land in spam, bounce unexpectedly, or get rejected, the sending IP may have reputation or blacklist issues. ### Technical and traffic signs Slow page loads or repeated challenge pages from WAFs may mean security systems are inspecting your IP more aggressively. Ads, pricing, or availability can also behave differently when systems classify a network as risky or anonymized. A lookup showing high risk, proxy status, blacklist hits, or abuse history is a stronger signal. Compare those results with recent device infections, router changes, public Wi-Fi use, VPN exits, or shared hosting activity. ### What to do next First, confirm the public IP with Crafzo, then check whether the issue follows that IP across browsers and devices. If it does, review malware, email sending, router security, VPN choice, and any services hosted on the connection. If the IP belongs to your ISP, restarting the router or asking for support may help, but do not ignore the root cause. If you run a server, fix abusive traffic before requesting delisting or reputation review. ### FAQ **How do I unflag my IP?** Fix the cause first, such as malware, spam, open proxies, compromised accounts, or abusive traffic. Then request review or delisting from the affected service or blacklist. **Can a flagged IP affect others on my network?** Yes. If many users share one public IP through NAT, CGNAT, public Wi-Fi, or an office gateway, one reputation problem can affect everyone behind it. **Does changing IP fix reputation problems?** It can help if the old address inherited bad history, but it will not fix malware or abusive behavior that continues from your devices. Treat it as a temporary relief, not the whole solution. ## Free vs Paid IP Lookup Tools: What the Difference Actually Is Canonical: https://ip.crafzo.com/blog/free-vs-paid-ip-lookup-tools Published: 2026-05-12 | Updated: 2026-09-24 | 3 min read An honest comparison of free and paid IP lookup tools — covering data freshness, API access, rate limits, and when free is genuinely enough. ### What free tools do well Free IP lookup tools are excellent for manual checks, support conversations, developer testing, VPN verification, and one-off investigations. They can quickly show public IP, approximate location, ISP, network type, and basic risk context. For human-readable results, a good free tool is often enough. Crafzo is built for that workflow: paste an IP, read the result, and understand the network without building an API integration. ### What paid tools add Paid IP intelligence services usually add bulk APIs, higher rate limits, fresher datasets, commercial support, SLAs, export options, and deeper fraud or proxy classifications. They are useful when IP decisions happen automatically at scale. Paid access can also improve operational reliability. If your login, checkout, firewall, or compliance pipeline depends on IP enrichment, you may need uptime guarantees and predictable quotas. ### Choosing the right level | | Free lookup tools | Paid IP intelligence APIs | | --- | --- | --- | | How you use them | Paste an address, read a page | Call an API from your own code | | Volume | One address at a time; rate limits on any API | Bulk enrichment with contractual quotas | | Location data | Country reliable, city an estimate | Same fields, often with a confidence radius and fresher updates | | Risk signals | Proxy, VPN, hosting and blocklist flags | Scored risk, velocity and history, custom rules | | Guarantees | None; a tool can change or disappear | Uptime SLA, support, data-processing agreement | | Best for | Support, debugging, spot checks, learning | Login, checkout and abuse decisions made automatically | Use free tools when humans are reviewing individual IPs, when volume is low, or when you are validating a new workflow. Upgrade when you need automated checks, bulk enrichment, contractual guarantees, or specialized risk fields. Many teams use both: a paid API in production and Crafzo as the readable verification layer for support, debugging, and spot checks. That combination keeps systems automated while making individual results easier to explain. ### FAQ **Is a free IP lookup accurate enough?** For manual location, ISP, and basic troubleshooting, yes in many cases. For automated fraud decisions or compliance workflows, compare data sources and monitor false positives. **When do I need a paid IP intelligence service?** You need paid service when you require API volume, bulk processing, SLAs, support, fresher data, or advanced proxy and fraud signals. Occasional manual lookups usually do not require that overhead. **What is the most accurate free IP lookup?** Accuracy varies by country, ISP, and database freshness. The best free choice is the one that clearly explains limits and gives enough context to verify the result. ## Rate Limiting by IP in Node.js: What You Need to Know First Canonical: https://ip.crafzo.com/blog/rate-limiting-ip-nodejs-guide Published: 2026-05-14 | Updated: 2026-09-22 | 2 min read A practical guide to IP-based rate limiting in Node.js — covering express-rate-limit, proxy trust, shared IPs, and when IP limits are not enough. ### Basic Express setup A simple TypeScript setup with `express-rate-limit` can protect public endpoints quickly: `app.use(rateLimit({ windowMs: 60_000, limit: 100, standardHeaders: true, legacyHeaders: false }));`. Start with conservative limits and monitor real traffic before tightening them. Rate limits should match endpoint cost. A login endpoint, password reset flow, search API, and static page do not need the same threshold or response behavior. ### Proxy trust and shared IPs If your Node.js app sits behind a proxy, configure Express with the correct trust setting, such as `app.set("trust proxy", 1)` when there is exactly one trusted proxy hop. Without this, `req.ip` may show the load balancer instead of the client. Be careful with CGNAT, offices, schools, and public Wi-Fi because many legitimate users can share one IP. A strict IP-only limit can accidentally block unrelated people. ### Beyond IP-only limits Combine IP limits with account, API token, session, device, route, and organization limits. Authenticated APIs often work better with token or account limits, while anonymous endpoints still benefit from IP throttling. Choose a fixed window for simple protection or a sliding window/token bucket for smoother behavior. Use Crafzo during investigations to understand whether a noisy IP is residential, mobile, hosting, VPN, or already risky. ### FAQ **How do I rate limit by IP in Express?** Use middleware such as `express-rate-limit`, then make sure `req.ip` reflects the real client behind your proxy. Configure `trust proxy` carefully before relying on the value. **What happens if many users share one IP?** They can all hit the same limit even if only one user is active or abusive. For shared networks, combine IP limits with account, session, or token-level limits. **Should I use IP rate limits for authenticated APIs?** Yes, but not as the only control. Authenticated APIs usually need token, account, and organization quotas in addition to IP-based throttles. ## ASN Lookup Explained: How to Find the Network Behind an IP Canonical: https://ip.crafzo.com/blog/asn-lookup-explained Published: 2025-09-16 | Updated: 2026-09-26 | 7 min read An Autonomous System Number identifies the network that announces an IP range. What an ASN lookup tells you about ownership, and why it explains traffic quality. ### What an ASN is The internet is a network of networks, and each independently operated network is an autonomous system. RFC 1930 defines an AS as a connected group of IP prefixes run by one or more operators under a single, clearly defined routing policy. An Autonomous System Number, the ASN, is the identifier that network uses when it exchanges routes with its neighbors. Large ISPs, mobile carriers, cloud providers, universities, content networks and many enterprises each operate one or more. IANA allocates blocks of AS numbers to the five regional internet registries, which assign them to operators, and IANA's AS numbers registry records the allocations. Numbers were originally 16-bit, giving 65,536 values; RFC 6793 extended BGP to carry 32-bit numbers, so an ASN today can be as large as 4,294,967,295. The size of the number says nothing about the network; it only reflects when the number was assigned. ### Routing context: how an ASN relates to an IP address Networks announce the prefixes they are responsible for to their neighbors using the Border Gateway Protocol, defined in RFC 4271, and each announcement carries the path of AS numbers it traveled through. When a lookup tool says an address 'belongs to AS15169', it means that AS15169 is currently announcing the prefix containing that address to the global routing system. The origin AS is a fact about routing right now, gathered from route collectors such as RIPE's Routing Information Service and the University of Oregon's Route Views project, not a fact about who is registered as the address holder. The two usually coincide and sometimes do not. An operator can announce space it leases from another registrant, a company can have its addresses announced by a transit provider, and a hijacked prefix is announced by an AS that has no right to it. Registration data answers 'who holds this range'; the origin AS answers 'whose network is carrying it'. The [WHOIS and RDAP guide](https://ip.crafzo.com/blog/ip-whois-rdap-lookup) covers the registration side. ### Looking up an ASN with RDAP RDAP, the registration data protocol that replaced WHOIS, has a query type for autonomous system numbers: RFC 9082 defines the path segment autnum, so a request for /autnum/15169 returns the registration record for AS15169. Finding the right registry uses the bootstrap procedure in RFC 9224: IANA publishes asn.json, a file listing which ranges of AS numbers each RIR serves, and a client picks the base URL that covers the number. For 15169 that is ARIN, and a request to rdap.arin.net/registry/autnum/15169 returns a record with the handle AS15169, the name GOOGLE, a start and end number of 15169 (a single-number block), the registrant entity and a technical contact, plus registration and last-changed dates. Larger operators hold ranges of consecutive numbers, and the record for any one of them shows the whole range. An [ASN lookup tool](https://ip.crafzo.com/asn-lookup) performs the same steps and adds the prefixes currently announced by that AS. ### ASN versus ISP The ISP is the company a customer pays; the ASN is a routing identifier. They are often the same organization, but one company may run several autonomous systems, for its consumer broadband, its mobile network and its hosting arm, and a small ISP may have no AS of its own and use its upstream's number. A lookup that reports an ASN name and an ISP name is therefore reporting two different things, and when they differ it is usually a wholesale, reseller or leasing relationship rather than an error. The [ISP lookup guide](https://ip.crafzo.com/blog/isp-lookup-from-ip) covers the consumer-facing side of the question. ### Hosting, mobile, residential and business networks The most useful thing an ASN tells you is the kind of network an address lives in. Operators are known: this AS is a cable provider, that one a mobile carrier, that one a cloud platform. Lookup providers label the AS and apply the label to its prefixes, which is how a result comes to say 'hosting' or 'residential' before anything about the individual address is known. The [data center versus residential guide](https://ip.crafzo.com/blog/data-center-ip-vs-residential-ip) covers what the labels do and do not mean. Two addresses in the same city can carry very different expectations. One announced by a residential ISP is most likely a household; one announced by a hosting AS is most likely a server, a VPN exit or an automated client. Neither expectation is a conclusion about the visitor. ### How ASN information is used Security. Rate limits and WAF rules can be scoped to an AS when abuse comes from one hosting network, and login alerts can weigh a change of AS more heavily than a change of city, since a real user changing ISP is rarer than a real user changing town. Fraud review. Network type from the AS, combined with velocity, account history and a [fraud score](https://ip.crafzo.com/ip-fraud-score-checker), separates a customer on a home connection from automation on a cloud server far better than location alone. The AS is one input to that picture. Networking. Operators use ASNs to set peering and transit policy, to filter routes, and to trace where a path goes wrong; the AS path on a route is the map of who carried it. Troubleshooting and support. When a customer reports being blocked or seeing the wrong location, the AS says which network they are on, which often explains both: a mobile carrier AS accounts for a city mismatch, a corporate AS for an unexpected country, a hosting AS for a VPN. The [abuse contact guide](https://ip.crafzo.com/blog/find-abuse-contact-from-ip) covers reaching the operator when the traffic needs reporting. ### Limits of ASN-based conclusions An ASN describes a network, not a person or a device. A large residential AS contains millions of subscribers, so an AS-level rule affects all of them; a hosting AS contains legitimate integrations alongside abusive ones. The label attached to an AS is an inference by the lookup provider and can lag when a network changes its business or leases space. The origin AS can be wrong during a hijack or a misconfiguration. And a change of AS between two sessions is a signal that the network changed, which happens whenever a phone leaves Wi-Fi, a laptop joins a VPN or a company reroutes its egress. Use ASN data as one layer of evidence about the network behind an address. Pair it with reverse DNS, request behavior, velocity and account history before making a decision, and keep the decision reversible. ### FAQ **Is ASN the same as ISP?** Not always. An ASN identifies a network that announces routes; an ISP is the company a customer pays. One company can run several autonomous systems, and a small ISP may use its upstream's number. **Can ASN lookup detect bots?** It can show that an address sits in a hosting or automation-friendly network, which raises the odds of a bot on a consumer-facing page. Confirming one still needs behavior signals such as request pattern and velocity. **How do I find the ASN of an IP address?** Query the registry's RDAP service for the address to see its registered holder, and check a route collector or ASN lookup tool for the AS currently announcing its prefix. The two can differ when space is leased or announced by a transit provider. **What is the difference between a 16-bit and 32-bit ASN?** Only the range. The original numbers fit in 16 bits (up to 65,535); RFC 6793 extended BGP to 32-bit numbers. A large number just means it was assigned after the extension, not that the network is different in kind. ### Sources - RFC 1930: Guidelines for creation, selection, and registration of an Autonomous System (AS): https://www.rfc-editor.org/rfc/rfc1930 - RFC 4271: A Border Gateway Protocol 4 (BGP-4): https://www.rfc-editor.org/rfc/rfc4271 - RFC 6793: BGP Support for Four-Octet Autonomous System (AS) Number Space: https://www.rfc-editor.org/rfc/rfc6793 - IANA: Autonomous System (AS) Numbers registry: https://www.iana.org/assignments/as-numbers/as-numbers.xhtml - RFC 9082: Registration Data Access Protocol (RDAP) Query Format: https://www.rfc-editor.org/rfc/rfc9082 - RFC 9224: Finding the Authoritative Registration Data Access Protocol (RDAP) Service: https://www.rfc-editor.org/rfc/rfc9224 - IANA: RDAP bootstrap file for AS numbers (asn.json): https://data.iana.org/rdap/asn.json - ARIN RDAP: autnum record for AS15169: https://rdap.arin.net/registry/autnum/15169 - RIPE NCC: Routing Information Service (RIS): https://www.ripe.net/analyse/internet-measurements/routing-information-service-ris/ - University of Oregon Route Views Project: https://www.routeviews.org/routeviews/ ## IP WHOIS and RDAP Lookup: What They Show and When to Use Them Canonical: https://ip.crafzo.com/blog/ip-whois-rdap-lookup Published: 2025-09-17 | Updated: 2026-09-25 | 8 min read Geolocation estimates where an IP is used; WHOIS and RDAP record who holds it and whom to contact about abuse. When to use each during an investigation. ### Two questions, two systems An IP geolocation lookup answers 'where does this address appear to be used?'. WHOIS and RDAP answer a different question: 'who holds this address block, and whom do I contact about it?'. The first is an estimate assembled by a database vendor; the second is a record kept by the registry that allocated the block. Investigations need both, and confusing them is the most common mistake in reading either. Registration data lives with the five Regional Internet Registries that manage address space under the framework of RFC 7020: AFRINIC (Africa), APNIC (Asia-Pacific), ARIN (North America and parts of the Caribbean), LACNIC (Latin America and the Caribbean) and the RIPE NCC (Europe, the Middle East and Central Asia). Each publishes its records over both WHOIS and RDAP. ### WHOIS: the original protocol WHOIS is a plain-text query service on TCP port 43, specified in RFC 3912. You send a query string, the server returns human-readable text, and the connection closes. Its simplicity is why every operating system still ships a whois client. Its weaknesses are the reasons RDAP exists. RFC 3912 defines no format for the response, so every registry answers in its own layout and a parser written for ARIN breaks on RIPE. There is no standard way to find which server is authoritative for an address, no authentication, no encryption on the wire and no support for internationalized text. Scripts that scrape WHOIS output are brittle by design. ### RDAP: the replacement The Registration Data Access Protocol delivers the same registration data over HTTPS as JSON. Four RFCs define it: RFC 7480 covers how RDAP uses HTTP, RFC 7481 the security services (TLS, authentication and access control), RFC 9082 the query format, for example '/ip/192.0.2.1' or '/autnum/64496', and RFC 9083 the JSON responses. Structured responses mean a program reads the network range, registrant, contacts and events from named fields instead of guessing at text. HTTPS means the answer is encrypted and can be authenticated, so a registry can return more detail to an authenticated abuse handler than to an anonymous query. Internationalized names and addresses are supported natively. ### Finding the right registry RFC 9224 solves the 'which server?' problem. IANA publishes bootstrap files that map address space to the RDAP base URL of the registry responsible for it: ipv4.json, ipv6.json and asn.json under https://data.iana.org/rdap/. A client matches the address against the prefixes in the file and sends its query to that base URL. The IPv4 file maps, for instance, 1.0.0.0/8 to APNIC, 8.0.0.0/8 to ARIN and 41.0.0.0/8 to AFRINIC. The registries' base URLs are https://rdap.arin.net/registry/ (ARIN), https://rdap.db.ripe.net/ (RIPE NCC), https://rdap.apnic.net/ (APNIC), https://rdap.lacnic.net/rdap/ (LACNIC) and https://rdap.afrinic.net/rdap/ (AFRINIC); append ip/ and the address to query one. Each also still answers WHOIS on port 43, and an RDAP response names its legacy server in a port43 field. ### The fields you will read Network range. RDAP returns a startAddress and an endAddress (WHOIS shows NetRange at ARIN and inetnum at the RIPE NCC, APNIC and AFRINIC), a handle and a name for the block, and its type: a direct allocation from the registry, or an assignment to a customer. Organization. The registrant entity, with its name and often a postal address. This is the holder of the block, an ISP, hosting company, university or enterprise; it is not necessarily the operator of the server behind one address inside the block. Contacts. Entities with roles such as administrative, technical and abuse. The abuse contact is the one investigators need; RDAP marks it with the role 'abuse' and it normally carries an email address. ASN, where relevant. Registration data for an autonomous system lives at /autnum/ followed by the number and names the holder of the AS number. Which AS actually announces a range is routing data from BGP route collectors, not registration data; the [ASN guide](https://ip.crafzo.com/blog/asn-lookup-explained) covers the difference. Registry country. A country code attached to the block or its holder. It records where the resource was registered, and the RIPE Database documentation states that it has never been specified what this country represents (the head office of a multinational, the server center or the end user's home) and that it cannot be used in any reliable way to map IP addresses to countries. Events and remarks. Registration and last-changed dates, plus free-text remarks that sometimes carry abuse-reporting instructions. ### A worked example: 8.8.8.8 The IPv4 bootstrap file places 8.0.0.0/8 with ARIN, so the query is https://rdap.arin.net/registry/ip/8.8.8.8. At the time of writing the response describes the block 8.8.8.0 to 8.8.8.255 with the handle NET-8-8-8-0-2 and the name GOGL, a direct allocation whose parent is NET-8-0-0-0-0, registered and last changed on 28 December 2023. The registrant entity is Google LLC; nested under it are an administrative and technical contact and an abuse contact, ABUSE5250-ARIN, with the address network-abuse@google.com. The port43 field points at whois.arin.net, the legacy server for the same record. Put that next to a geolocation lookup of the same address and the split is obvious. Registration says who is responsible and whom to email about abuse; it says nothing about where the machine answering 8.8.8.8 is, and for an anycast service like Google Public DNS there is no single place. The reverse holds too: the city a database assigns to a cloud address says nothing about which of the provider's customers runs the server. ### Comparing the three The table sets the two registration systems against geolocation on the questions that come up in practice. | | WHOIS | RDAP | IP geolocation | | --- | --- | --- | --- | | Question answered | Who holds the block | Who holds the block | Where the address appears to be used | | Source | Registry database | Registry database | Vendor database inferred from registry data, feeds and measurements | | Transport and format | TCP port 43, free text that differs by registry | HTTPS, JSON defined by RFC 9083 | Vendor API or downloadable database | | Finding the server | No standard; referrals and guesswork | IANA bootstrap files (RFC 9224) | Not applicable | | Location data | Registry country only | Registry country only | Country, region, city estimate and coordinates | | Best for | A quick manual check from a terminal | Automation, abuse reporting, reliable contacts | Fraud context, localization, troubleshooting | ### Limitations to keep in mind Redaction. Registries increasingly withhold personal data. Contact records show a role or an organization rather than a person, and RDAP lets a registry return less to anonymous clients than to authenticated ones. Referrals and nesting. A large allocation can contain more specific assignments to customers, and a registry that transferred a block may answer with a referral to another server. The most specific record describes the actual user of a range; follow the chain instead of stopping at the first answer. Rate limits. Registries limit anonymous query volume and refuse or slow a script that hammers them. For bulk enrichment, use the data the registries publish for download or a licensed dataset rather than live queries. Country is not location. A block registered to an organization in one country can be used in another, and a multinational's entire address space can carry its head-office country. Staleness. A record describes the holder as last reported to the registry; reassignments to customers are not always recorded, and nothing in it says who was using an address at a given moment. Keep the observation time with every piece of evidence. ### Using both in an investigation Start with a geolocation and risk lookup for the quick picture: country, network type, proxy or hosting flags, reputation. Then query RDAP for the block: confirm who holds the range, capture the abuse contact, and note whether the block is a direct allocation to an ISP or an assignment to a specific customer. If routing matters, check which AS announces the prefix, and record the query time alongside the evidence. When the address has to be reported, the [abuse-contact guide](https://ip.crafzo.com/blog/find-abuse-contact-from-ip) covers what a usable report contains, and the [ISP lookup guide](https://ip.crafzo.com/blog/isp-lookup-from-ip) explains how the provider name in a geolocation result relates to the registrant in the RDAP record. ### FAQ **Does WHOIS show a person's name?** For IP addresses it shows the organization that holds the block and role contacts. Registries redact personal data, and the subscriber using an address is not in the record at all. **When should I use RDAP?** Whenever a program needs to read the data, whenever you need the abuse contact reliably, and whenever the query has to be encrypted or authenticated. WHOIS is still fine for a quick look from a terminal. **Is RDAP free to use?** Yes. The Regional Internet Registries answer anonymous RDAP queries without charge, subject to rate limits; bulk access and access to personal data may require registering with the registry. **Can RDAP tell me where an IP address is located?** No. It returns the registry country of the holder, which the RIPE NCC's own documentation describes as unreliable for mapping addresses to countries. Use a geolocation lookup for location and RDAP for ownership. ### Sources - RFC 7020: The Internet Numbers Registry System: https://www.rfc-editor.org/rfc/rfc7020 - RFC 3912: WHOIS Protocol Specification: https://www.rfc-editor.org/rfc/rfc3912 - RFC 7480: HTTP Usage in the Registration Data Access Protocol (RDAP): https://www.rfc-editor.org/rfc/rfc7480 - RFC 7481: Security Services for the Registration Data Access Protocol (RDAP): https://www.rfc-editor.org/rfc/rfc7481 - RFC 9082: Registration Data Access Protocol (RDAP) Query Format: https://www.rfc-editor.org/rfc/rfc9082 - RFC 9083: JSON Responses for the Registration Data Access Protocol (RDAP): https://www.rfc-editor.org/rfc/rfc9083 - RFC 9224: Finding the Authoritative Registration Data Access Protocol (RDAP) Service: https://www.rfc-editor.org/rfc/rfc9224 - IANA: RDAP bootstrap file for IPv4 address space: https://data.iana.org/rdap/ipv4.json - ARIN: Registration Data Access Protocol (RDAP): https://www.arin.net/resources/registry/whois/rdap/ - ARIN RDAP record for 8.8.8.0/24: https://rdap.arin.net/registry/ip/8.8.8.8 - RIPE Database documentation: descriptions of primary objects (the country attribute): https://docs.db.ripe.net/RPSL-Object-Types/Descriptions-of-Primary-Objects/ ## How to Find the Abuse Contact for an IP Address Canonical: https://ip.crafzo.com/blog/find-abuse-contact-from-ip Published: 2025-09-18 | Updated: 2026-09-22 | 2 min read A practical guide to finding the right abuse contact when an IP is involved in spam, scanning, fraud, or attacks. ### When abuse contact lookup helps Abuse contacts are useful when an IP is involved in spam, credential attacks, port scanning, scraping, malware callbacks, or policy violations. The goal is to reach the network operator or provider responsible for the address range, not to identify a private person from the IP alone. ### Information to collect first Before reporting abuse, collect the IP address, timestamps with timezone, request IDs, URLs, headers, logs, and a short description of the behavior. Good reports are specific. A provider can act faster when you show what happened and when it happened. ### How to find the contact Use IP lookup for quick context, then check RDAP or WHOIS for abuse, technical, or network operations contacts. Large providers may also have a web abuse form. If registry data points to another regional registry, follow the referral and search there. IP blocks are managed across multiple regional internet registries. ### FAQ **Should I send screenshots only?** No. Include raw logs and timestamps whenever possible, because screenshots are harder to verify. **Can I report a VPN IP?** Yes, but the VPN provider may only be able to enforce its own terms and may not identify a user publicly. ## CGNAT and Shared IP Addresses: Why One IP Can Represent Many Users Canonical: https://ip.crafzo.com/blog/cgnat-shared-ip-addresses Published: 2025-09-19 | Updated: 2026-09-25 | 7 min read Carrier-grade NAT lets hundreds of customers share one public IP. How it works, why it breaks per-IP bans, and how to account for it in fraud checks. ### What carrier-grade NAT is Carrier-grade NAT lets an ISP or mobile carrier place many subscribers behind a smaller pool of public IPv4 addresses. It is common because IPv4 space is limited. Your home router already translates your devices' private addresses to the one address it holds. Carrier-grade NAT adds a second translation inside the ISP's network: a large NAT device, whose common requirements RFC 6888 describes, maps the traffic of hundreds or thousands of customer routers onto a much smaller set of public addresses, using port numbers to keep the customers apart. To a website, many unrelated users may appear to come from the same public IP address even though they are on different devices, in different homes, with different accounts. ### Why ISPs use it The reason is arithmetic. IPv4 has about 4.3 billion addresses; IANA handed out the last of its free blocks in February 2011, and the regional registries' pools followed over the next few years. New addresses now come from a transfer market at a price per address, so a carrier with millions of subscribers cannot give each one a public IPv4 address without an enormous outlay. Sharing lets it serve them with a fraction of the addresses, and lets a fixed-line ISP keep growing after its allocation is spent. It was meant as a bridge: IPv6 removes the shortage, but as long as some destinations are reachable only over IPv4, subscribers need an IPv4 path, and sharing is the cheapest way to provide one. ### 100.64.0.0/10: the shared address space The link between the carrier's NAT and your router needs addresses too, and neither private nor public space fits: RFC 1918 ranges are already in use inside customers' homes, so reusing them on the carrier side risks collisions, and public space is exactly what the carrier is short of. RFC 6598 reserved 100.64.0.0/10, the range 100.64.0.0 to 100.127.255.255, as shared address space for this one purpose. IANA lists it in the IPv4 special-purpose registry; it is not routable on the public internet and should never appear inside a home network. That makes it a fingerprint. An address in 100.64.0.0/10 on the WAN side of your router means a carrier-grade NAT sits between you and the internet. ### How to tell you are behind CGNAT Compare two addresses. Your router's admin page shows the WAN address it received from the ISP; an IP lookup shows the address websites actually see. If they match, your router holds the public address and there is no carrier NAT. If the WAN address is in 100.64.0.0/10, you are behind CGNAT almost certainly. If it is in a private range such as 10.x.x.x, another layer of translation sits above you, which may be the ISP's gateway or its CGNAT. Other signs point the same way: a traceroute shows a hop in shared or private space before public addresses appear; the ISP sells a 'public' or 'static' IP as an add-on; port forwarding rules on your router have no effect from outside. Satellite and mobile services make heavy use of it; [Starlink satellite internet](https://ip.crafzo.com/blog/starlink-ip-addresses-geolocation), for example, serves its standard plans through carrier-grade NAT. ### What breaks Port forwarding and self-hosting. An inbound connection arrives at the shared public address, and the carrier's NAT has no mapping that leads to your router, so it is dropped before your own forwarding rules can act. Game servers, cameras, remote desktop and anything else that expects to be reachable from outside stop working. RFC 7021 assessed the impact of carrier-grade NAT on applications and found this pattern: some fail, others degrade. The ways around it are IPv6, a public IPv4 address from the ISP, or a relay or tunnel service that terminates on a public address. IP bans. A block aimed at one abusive subscriber lands on everyone who shares the address, which can be hundreds of households. RFC 6269, on the issues with IP address sharing, spells out the consequences: reputation, blacklisting, geolocation and logging all assume that an address is one party, and sharing breaks that assumption. Fraud and risk systems. A shared address accumulates the behavior of everyone behind it. A [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) for such an address describes the crowd, not the person, and a velocity counter that sees many accounts from one address is measuring how many people the carrier put behind it. Rate limits and CAPTCHAs. Per-address rate limits are consumed by the aggregate traffic of every subscriber on the address, so ordinary users hit them without doing anything unusual, and challenge systems that weigh address reputation and velocity show mobile users more CAPTCHAs for the same reason. Logging and investigations. A timestamp and an address no longer identify a subscriber; that takes the source port as well, plus the carrier's translation logs. RFC 6888 devotes a section to the logging these devices need so that a mapping can be traced back to a subscriber, and RFC 6269 explains why investigators depend on it. ### What site operators should do Blocking one shared IP can accidentally affect legitimate users. This is especially risky for mobile networks, public Wi-Fi, schools, offices, and large residential ISPs. Fraud systems should treat shared-IP behavior differently from a dedicated server IP that sends automated traffic. Use IP reputation with account, device, session, and behavior signals. Apply rate limits carefully, and prefer step-up verification over broad IP blocks when users may be sharing an address. When a lookup shows a consumer or mobile network, widen the unit of analysis from the address to the account and device, give mobile networks more generous per-address limits, and if a block is unavoidable keep it short and revisit it; the [firewall blocking guide](https://ip.crafzo.com/blog/firewall-block-ip-best-practices) covers scoping and expiring such rules. Crafzo IP Lookup helps you identify when an IP looks like consumer or carrier traffic so you can avoid overreacting. ### IPv6: the way out IPv6 removes the reason for sharing. Its address space is large enough for every device to hold a globally reachable address, so there is nothing to translate and no pool to ration. Many carriers already run IPv6 alongside their carrier-grade NAT for IPv4, and some mobile networks are IPv6-only internally, translating only for the IPv4 destinations that remain. When both ends of a connection speak IPv6, the connection bypasses the carrier's NAT: inbound connections work again, and the address identifies one connection rather than a crowd. The [IPv6 lookup](https://ip.crafzo.com/ipv6-lookup) shows whether your connection has a public IPv6 address of its own, and the [IPv4 versus IPv6 guide](https://ip.crafzo.com/blog/ipv4-vs-ipv6-what-the-shift-means-for-your-privacy) covers what that changes for privacy and geolocation. ### FAQ **Can many people share one public IP?** Yes. NAT and CGNAT can make many devices or subscribers appear behind one public IP: a home router shares one address among a household, a carrier-grade NAT shares one address among many households. **Should shared IPs be blocked?** Only for clear abuse patterns, and briefly. Safer options include rate limits, MFA, and account-level review, because a block on a shared address lands on every subscriber behind it. **Is 100.64.x.x my public IP?** No. It is the shared address space RFC 6598 reserved for the link between a carrier's NAT and customer equipment. Websites see a different, public address that you share with other subscribers. **Can I get out of CGNAT?** Sometimes. Some ISPs sell a public or static IPv4 address as an add-on, IPv6 bypasses the carrier NAT when both ends support it, and a tunnel or relay service can provide an inbound path for self-hosting. ### Sources - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space: https://www.rfc-editor.org/rfc/rfc6598 - RFC 6888: Common Requirements for Carrier-Grade NATs (CGNs): https://www.rfc-editor.org/rfc/rfc6888 - RFC 6269: Issues with IP Address Sharing: https://www.rfc-editor.org/rfc/rfc6269 - RFC 7021: Assessing the Impact of Carrier-Grade NAT on Network Applications: https://www.rfc-editor.org/rfc/rfc7021 - Number Resource Organization: IPv4 free pool depleted (3 February 2011): https://www.nro.net/ipv4-free-pool-depleted - IANA: IPv4 Special-Purpose Address Registry: https://www.iana.org/assignments/iana-ipv4-special-registry/iana-ipv4-special-registry.xhtml ## How to Check If Your VPN Is Working With an IP Lookup Canonical: https://ip.crafzo.com/blog/check-vpn-working-ip-lookup Published: 2025-09-21 | Updated: 2026-09-25 | 8 min read Use public IP lookup, location checks, and DNS tests to verify whether your VPN is actually changing your visible network identity. ### What a working VPN changes A VPN opens an encrypted tunnel from your device to one of the provider's servers and sends your traffic through it. When it works, every website sees the exit server's public address, ISP and location instead of yours, your DNS lookups travel inside the tunnel, and both your IPv4 and your IPv6 traffic are covered. Each of those is a separate promise that can fail on its own, which is why checking a VPN is a sequence of small tests rather than one glance at a map. ### Step 1: record your address before connecting Before connecting to a VPN, check your public IP and note the country, city, and ISP. Note the IPv6 address as well if your connection has one; the [guide to checking your own IP address](https://ip.crafzo.com/blog/how-do-i-check-my-own-ip-address) covers the command-line ways to see both. This is the baseline everything else is compared against. ### Steps 2 and 3: connect, then check the new public IP Connect the VPN and run the lookup again. A working VPN should usually show the VPN provider or exit network instead of your normal home, office, or mobile ISP. The address must differ from the baseline, and the ISP or organization should be the VPN provider or a hosting company. If your normal ISP still appears, the tunnel is not carrying this traffic. The usual causes are a browser extension that proxies only that browser, split tunneling that excludes the app you tested with, or a connection that reported success but never came up. ### Step 4: check the country The country should be the one you selected. Country is the level at which geolocation is reliable, so a mismatch here is meaningful: either you connected to a different server than you intended, or the provider's address for that server is registered elsewhere. ### Step 5: why the city can be wrong VPN city labels and IP geolocation databases can disagree. A server marketed as one city may appear in a nearby metro or at a hosting provider location. There are three ordinary reasons. Databases map an exit address to the network that registered it or the facility that hosts it, which may be a different city from the server's label. Providers move and announce address space faster than databases update, so a recently added server can carry a stale location for weeks. And some servers are 'virtual locations': the machine sits in one country while its addresses are registered and geolocated to another, a practice providers use for countries where they will not run hardware. If location matters to you, test several servers from the same provider and pick the one the databases agree on. But the test of a working VPN is not the city. Focus on whether your original public IP and ISP are hidden, not whether every database agrees on the exact city. The [accuracy guide](https://ip.crafzo.com/blog/how-accurate-are-ip-address-location-lookups) and the guide to [wrong lookup locations](https://ip.crafzo.com/blog/ip-lookup-wrong-location-reasons) explain how far city results can be trusted for any address. ### Step 6: check IPv4 and IPv6 separately Many connections are dual-stack, carrying an IPv4 and an IPv6 address at the same time. A VPN that tunnels only IPv4 leaves the IPv6 path untouched, so a website that supports IPv6 connects to you over it and sees your real address while an IPv4-only site sees the VPN. Check the [IPv6 lookup](https://ip.crafzo.com/ipv6-lookup) with the VPN connected: it should show the provider's IPv6 address or none at all. Your own IPv6 address from the baseline is a leak. The fix is a client that tunnels IPv6 or blocks it while connected; failing that, disable IPv6 on the device. The [IPv4 versus IPv6 guide](https://ip.crafzo.com/blog/ipv4-vs-ipv6-what-the-shift-means-for-your-privacy) explains why the IPv6 address identifies your device more precisely than a shared IPv4 address does. ### Step 7: DNS leak versus IP leak An IP leak happens when a website sees your real public IP instead of the VPN, proxy, or protected network address you expected. If your real IP appears, websites can often estimate your country, region, ISP, and connection type. That is what steps 3 and 6 test. A DNS leak is different. Before your browser connects to a site, it asks a DNS resolver for the site's address, and the resolver learns which sites you visit. A DNS leak happens when those lookups go outside the tunnel, typically to your ISP's resolver, while the web traffic itself goes through the VPN: the website sees the VPN address and looks protected, while another network path still sees your browsing intent. RFC 9076 describes this exposure in general terms: the resolver, and anyone able to observe the path to it, can see the names you resolve. Test them separately. A DNS leak test reports which resolver networks answered your queries; with the VPN connected, they should belong to the VPN provider, not your ISP. Encrypted DNS over TLS (RFC 7858) or HTTPS (RFC 8484) hides your queries from the ISP and the local network, but it does not hide your public IP from websites, and a VPN does not protect DNS unless the client routes it through the tunnel. The two protections answer different questions. ### Step 8: WebRTC Browsers use WebRTC for calls and peer-to-peer connections, and to set those up they gather the addresses your device can be reached at. Older implementations exposed local and public addresses to any page that asked, which let a website learn your real address while a VPN was active. RFC 8828 sets out the requirements browsers now follow to limit that exposure, and current browsers by default reveal only the address of the route your traffic actually uses and hide local addresses behind generated names. A browser WebRTC leak test shows what yours gives up; if it still exposes your real address, use the VPN client's browser protection or the browser setting that disables WebRTC. ### Step 9: test the kill switch A kill switch blocks all traffic when the tunnel drops, so that your device does not silently fall back to the bare connection. Test it deliberately: with the VPN connected, switch Wi-Fi off and on or end the VPN process, then run the lookup immediately. The right result is no connection at all until the tunnel is back; the wrong result is your real address appearing for the seconds before the client reconnects. Test the wake-from-sleep case too, since that is when tunnels most often come back later than the network does. ### Step 10: reading the result The VPN is working when all of the following hold: the public IP differs from the baseline; the ISP is the VPN provider or a hosting network, not your own ISP; the country is the one you chose; the IPv6 lookup shows the provider's address or nothing; the DNS test shows only the provider's resolvers; WebRTC does not expose the baseline address; and traffic stops when the tunnel drops. A wrong city on its own is not a failure. Your real address showing on any of the checks is. Hiding your address is also not the same as hiding that you use a VPN: websites can recognize exit addresses from known ranges, hosting ASNs and reputation data. The [VPN and proxy checker](https://ip.crafzo.com/vpn-proxy-checker) shows what a site sees when it looks at your exit, and the [VPN detection checklist](https://ip.crafzo.com/blog/how-to-tell-if-ip-is-vpn) describes those signals from the site's side. ### FAQ **Why does my VPN show the wrong city?** Geolocation databases map VPN IPs to nearby or registered network locations instead of the app label, providers move address space faster than databases update, and some servers are virtual locations registered to a country other than where the hardware sits. **Should my ISP name disappear?** Usually yes. If your normal ISP still appears, the VPN may not be protecting that connection: check for a browser-only extension, split tunneling, or a tunnel that never came up. **Can websites know I use a VPN?** Some can infer it from known VPN ranges, data center ownership, or reputation signals. Hiding your address and hiding the fact that you use a VPN are different things. **Can my IP be hidden while DNS still leaks?** Yes. A VPN may mask your public IP while DNS queries still go to an unexpected resolver, usually your ISP's, which then sees the sites you resolve. **Does private DNS hide my public IP?** No. Private or encrypted DNS protects DNS queries, but it does not automatically hide your public IP from websites. **How do I test a VPN kill switch?** With the VPN connected, break the connection deliberately by toggling Wi-Fi or ending the VPN process, then run an IP lookup at once. Traffic should be blocked until the tunnel is back; if your real address appears, the kill switch is not working. ### Sources - RFC 8828: WebRTC IP Address Handling Requirements: https://www.rfc-editor.org/rfc/rfc8828 - RFC 9076: DNS Privacy Considerations: https://www.rfc-editor.org/rfc/rfc9076 - RFC 7858: Specification for DNS over Transport Layer Security (TLS): https://www.rfc-editor.org/rfc/rfc7858 - RFC 8484: DNS Queries over HTTPS (DoH): https://www.rfc-editor.org/rfc/rfc8484 - RFC 8981: Temporary Address Extensions for Stateless Address Autoconfiguration in IPv6: https://www.rfc-editor.org/rfc/rfc8981 - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## Tor Exit Node IP Risk: How Websites Should Interpret It Canonical: https://ip.crafzo.com/blog/tor-exit-node-ip-risk Published: 2025-09-22 | Updated: 2026-09-22 | 2 min read Tor exit nodes show up in risk checks because many users share them. What the flag really means, and how to handle Tor traffic without punishing privacy users. ### Why Tor changes visible IP Tor routes traffic through multiple relays and exits to the public internet from an exit node. Websites usually see the exit node IP, not the user's original connection. This makes Tor useful for privacy, but it also means many unrelated users may share the same exit IP. ### Why risk systems flag Tor Tor exit nodes are public, shared, and sometimes abused for automated signups, spam, scraping, and evasion. That can lead to high reputation risk. At the same time, Tor is used by journalists, researchers, activists, and privacy-conscious users. The right response depends on the action being attempted. ### Balanced handling For browsing, allow access when possible. For login, payment, admin changes, or abuse-prone actions, require stronger verification or rate limits. Use IP lookup and risk scoring to decide when Tor is simply a privacy signal and when behavior shows abuse. ### FAQ **Is Tor traffic always malicious?** No. Tor is a privacy tool, but shared exit nodes can also be abused. **Should I block all Tor IPs?** Only if your risk model requires it. Many sites use step-up verification instead of a blanket block. ## Data Center IP vs Residential IP: How to Tell the Difference Canonical: https://ip.crafzo.com/blog/data-center-ip-vs-residential-ip Published: 2025-09-24 | Updated: 2026-09-26 | 6 min read Compare data center and residential IP addresses, including risk signals, common use cases, and safe enforcement strategies. ### What each type means A residential IP address is one an internet service provider assigns to a home connection: cable, fiber, DSL, or a fixed-wireless link. The traffic behind it is mostly people using browsers and apps on their own devices. A data center or hosting IP address belongs to a network built to run servers: a cloud platform, a hosting company, a CDN, a VPN provider or a colocation facility. The traffic behind it is mostly software talking to software. Neither label is a judgement. The same lookup result that reads 'hosting' for a scraper reads 'hosting' for your payment processor's webhook, your monitoring service and a customer's corporate VPN. The label describes the network the address is announced from, and the meaning depends on what the visitor is doing there. ### How providers classify a network Classification starts with the autonomous system. Every address is announced by an AS, and RFC 1930 describes an AS as a set of prefixes under one routing policy, which in practice means one operator. Operators are known quantities: a consumer ISP, a mobile carrier, a hosting company or an enterprise. Lookup providers label the AS and inherit that label for its prefixes, then refine it where an operator runs several kinds of network. The [ASN lookup guide](https://ip.crafzo.com/blog/asn-lookup-explained) explains how to read the AS behind an address. Large clouds publish their address ranges directly. AWS publishes ip-ranges.json with the service and region of each prefix, Google Cloud publishes cloud.json, and Cloudflare publishes the ranges its proxies use, so an address in those files is a data-center address by the operator's own declaration. Commercial databases add connection-type data; MaxMind's connection type product, for example, distinguishes cellular, cable/DSL, corporate and satellite connections. Reverse DNS names, latency patterns and observed traffic behavior fill the remaining gaps. The classification is an inference about a block, refreshed on the provider's schedule. Ranges change hands, an ISP can lease space from a hosting company, and a hosting company can serve business customers with office connections, so a label is a strong signal about the network and a weaker one about any single address. ### Why a hosting IP is not automatically malicious Hosting networks carry an enormous amount of legitimate automated traffic. Server-to-server API calls, webhook deliveries, uptime monitors, search-engine crawlers, backup jobs and CI pipelines all arrive from cloud addresses, and so do people. Corporate networks often route staff traffic through a cloud-hosted security gateway or a virtual desktop, so an employee at a desk appears from a data center. Commercial VPN services and privacy relays run their exits on hosting infrastructure by necessity; Apple publishes the egress ranges of iCloud Private Relay so that network operators can recognize that traffic for what it is. The [VPN detection checklist](https://ip.crafzo.com/blog/how-to-tell-if-ip-is-vpn) covers how to tell an exit from an ordinary server. What a hosting label does tell you is that the traffic is unlikely to be a person on a home connection. For a checkout page, a signup form or a consumer login, that is unusual enough to justify a closer look or a challenge. For an API endpoint it is the expected case. ### Why a residential IP is not automatically trustworthy Residential addresses are what attackers want to look like, and there is a market that sells them. Residential proxy networks route traffic through consumer devices whose owners installed an app or SDK, sometimes knowingly, sometimes not, so that a scraper or a credential-stuffing tool appears to come from thousands of ordinary homes. Rotating residential networks change the exit address every request or every few minutes, which defeats per-address rate limits and blocklists at once. Malware-infected home devices serve the same purpose without any market at all. The [residential proxy detection guide](https://ip.crafzo.com/blog/residential-proxy-detection-for-login-risk) covers the behavioral signals that expose them. A residential label therefore lowers the prior that the visitor is a server, and nothing more. A home address exhibiting server behavior, such as hundreds of logins a minute or a request pattern no browser produces, is more suspicious than a data-center address doing the same, not less. ### Reading the two together The useful question is whether the network type fits the action. Fill in the comparison for the surface you are protecting, then treat a mismatch as a reason to look harder, not as a verdict. | | Residential IP | Data center / hosting IP | | --- | --- | --- | | Typical traffic | People on browsers and apps | Servers, integrations, crawlers, VPN exits | | Consumer login or checkout | Expected | Unusual; worth a challenge or review | | API or webhook endpoint | Unusual for a production integration | Expected | | Rate limiting | Shared by a household, sometimes a whole carrier pool | Usually one host; cheap to rotate | | Blocking | Collateral damage to the people behind it | Narrow, but attacker moves easily | | Main weakness | Residential proxies and infected devices | Legitimate automation and corporate egress | ### Policy considerations Decide per surface, not globally. Allow hosting traffic to the endpoints built for software and challenge it on the ones built for people; do the reverse for residential traffic only when behavior demands it. Weight the network type alongside velocity, account history, device consistency and a [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) rather than acting on it alone, and keep the resulting action proportionate: a challenge or a step-up rather than a block, unless the pattern is clear and repeated. Expect exceptions and build a path for them: a customer whose office exits through a cloud gateway, a partner whose integration runs from a home lab, a privacy relay user. Log the decisions and measure how often the exception path is used; it is the best indicator of whether the policy is protecting users or turning them away. ### FAQ **Is a data center IP bad?** No. It means the address is announced by a hosting or cloud network, which is normal for integrations, monitors, crawlers and VPN exits. It deserves context on consumer-facing actions, not automatic rejection. **Can IP lookup identify network type?** It can usually tell hosting, residential, mobile and business networks apart from the announcing AS, published cloud ranges and connection-type data. The label describes the network, not the intent of any single visitor. **Is a residential IP always a real person?** No. Residential proxy networks and infected home devices let automated traffic appear from ordinary households, so a residential label lowers the chance of a server without ruling one out. **How do lookup tools decide an IP is a data center?** From the autonomous system that announces it, the ranges cloud providers publish about themselves, reverse DNS naming and connection-type data. The result is an inference about the address block, refreshed on the provider's schedule. ### Sources - RFC 1930: Guidelines for creation, selection, and registration of an Autonomous System (AS): https://www.rfc-editor.org/rfc/rfc1930 - AWS: Amazon Web Services IP address ranges: https://docs.aws.amazon.com/vpc/latest/userguide/aws-ip-ranges.html - Google Cloud: published IP ranges (cloud.json): https://www.gstatic.com/ipranges/cloud.json - Cloudflare: IP Ranges: https://www.cloudflare.com/ips/ - Apple: Prepare your network or web server for iCloud Private Relay: https://developer.apple.com/icloud/prepare-your-network-for-icloud-private-relay/ - MaxMind: GeoIP Connection Type databases: https://dev.maxmind.com/geoip/docs/databases/connection-type/ ## Why a Website Shows Cloudflare IP Addresses Instead of the Origin Server Canonical: https://ip.crafzo.com/blog/cloudflare-proxy-ip-addresses Published: 2025-09-25 | Updated: 2026-09-25 | 5 min read A site behind Cloudflare or another CDN resolves to the CDN's addresses, not its own server. What that hides, what it does not, and how to read the lookup. ### Why proxy IPs appear When a site uses a reverse proxy or CDN, DNS may return the proxy network's IP address instead of the origin server IP. This is intentional. The proxy handles public traffic, absorbs attacks, caches content, and can hide the origin infrastructure. Cloudflare is the most common example. When a hostname is proxied through Cloudflare, its DNS records answer with addresses from Cloudflare's anycast network. Your browser connects to the nearest Cloudflare data center, and Cloudflare opens a separate connection to the site's origin server to fetch what it does not already have cached. The origin's address never appears in DNS for that hostname, which is the whole point of the arrangement. ### Recognizing a Cloudflare address Cloudflare publishes the IPv4 and IPv6 ranges its proxy uses at cloudflare.com/ips, with plain-text lists at /ips-v4 and /ips-v6 that scripts can fetch. Its main network is AS13335, registered in ARIN's records under the name CLOUDFLARENET to Cloudflare, Inc. A lookup that shows that ASN, or an address inside those ranges, is telling you that you have reached the edge network, not the server that runs the site. A domain that resolves to several addresses is normal for the same reason: anycast networks and load-balanced services return more than one address for performance and resilience, and each of them leads to the same edge. ### What lookup results mean If an IP lookup shows a CDN or proxy provider, it does not mean the website is hosted in that city or by that company directly. It means your request is reaching an edge or proxy network that fronts the real application. Read each field with that in mind. The ISP or organization tells you the site uses Cloudflare, and that is reliable. The city is where a geolocation database placed an anycast range, often the registrant's headquarters or one of many points of presence, and says nothing about where the site's server is. Risk flags on a CDN range reflect the behavior of every tenant sharing the edge, not the site you looked up. What you cannot learn from the address is the hosting provider, the server's country, or whether the site itself is trustworthy; those need other evidence. ### How the real visitor IP reaches the origin Because the connection to the origin comes from Cloudflare, the origin's own logs and rate limits see Cloudflare addresses unless the application reads the headers Cloudflare adds. CF-Connecting-IP carries the visitor's address as a single value on every proxied request, and Cloudflare also appends the visitor to X-Forwarded-For, the widely used but never formally standardized header whose standards-track alternative is the Forwarded header of RFC 7239. Cloudflare's documentation on restoring original visitor IPs shows how to make a web server log the visitor rather than the proxy, and the [X-Forwarded-For guide](https://ip.crafzo.com/blog/x-forwarded-for-real-client-ip) covers how to read forwarded headers safely in application code. One warning belongs here. Anyone who can reach the origin directly can send a request with any CF-Connecting-IP or X-Forwarded-For value they like. Trust those headers only when the connection itself arrives from Cloudflare's published ranges, and better still when the origin accepts connections from nowhere else. Otherwise an attacker chooses the address that appears in your logs, your rate limits and your allowlists. ### Security impact Origin hiding can reduce direct attack surface, but origin IPs may still leak through old DNS records, email headers, certificates, or misconfigured services. The usual leaks are mundane. A DNS record for the same server that is not proxied, such as ftp, mail, cpanel or direct, hands out the origin address. An MX record or an SPF record that names the origin does the same, and so does the Received header of any email the server sends. Historical DNS data records what the hostname pointed at before Cloudflare was switched on. Cloudflare's guidance on protecting the origin server is to restrict inbound connections to its published IP ranges, to use authenticated origin pulls so that the origin accepts only Cloudflare's certificate, or to connect the origin through Cloudflare Tunnel so that it needs no public inbound address at all. Use IP lookup to confirm what the public internet sees, then audit your infrastructure for accidental origin exposure. ### FAQ **Does a CDN IP reveal the origin server?** Usually no. It reveals the proxy or edge network handling public traffic. The origin's address only shows up through misconfiguration: an unproxied DNS record, a mail record, an email header or DNS history. **Why does my domain show many IPs?** CDNs and load-balanced services often return multiple addresses for performance and reliability. With an anycast network, each of them leads to the same edge. **Does Cloudflare hide my visitors' IPs from my server?** No. The connection to your origin comes from Cloudflare, but the visitor's address is passed in the CF-Connecting-IP header and appended to X-Forwarded-For; your server has to read it, and should only trust it on connections that come from Cloudflare's ranges. ### Sources - Cloudflare: IP Ranges: https://www.cloudflare.com/ips/ - Cloudflare docs: How Cloudflare works: https://developers.cloudflare.com/fundamentals/concepts/how-cloudflare-works/ - Cloudflare docs: HTTP request headers (CF-Connecting-IP, X-Forwarded-For): https://developers.cloudflare.com/fundamentals/reference/http-headers/ - Cloudflare docs: Restoring original visitor IPs: https://developers.cloudflare.com/support/troubleshooting/restoring-visitor-ips/restoring-original-visitor-ips/ - Cloudflare docs: Protect your origin server: https://developers.cloudflare.com/fundamentals/security/protect-your-origin-server/ - ARIN RDAP record for AS13335 (CLOUDFLARENET): https://rdap.arin.net/registry/autnum/13335 - RFC 7239: Forwarded HTTP Extension: https://www.rfc-editor.org/rfc/rfc7239 ## Reverse DNS Lookup and IP Reputation: What rDNS Can Tell You Canonical: https://ip.crafzo.com/blog/reverse-dns-lookup-ip-reputation Published: 2025-09-26 | Updated: 2026-09-22 | 2 min read Use reverse DNS as one clue in IP reputation analysis for mail servers, crawlers, hosting networks, and suspicious traffic. ### What reverse DNS is Reverse DNS maps an IP address back to a hostname using a PTR record. It is commonly used in email, server operations, and traffic analysis. An rDNS name can reveal clues such as hosting provider, mail server naming, crawler identity, or dynamic residential assignment. ### How to interpret it A meaningful PTR record can support a legitimate server identity. A missing or generic record is not automatically suspicious, but it may reduce confidence for email or API traffic. Attackers can use misleading names, so reverse DNS should not be trusted alone. ### Best use cases Use rDNS with forward DNS checks, ASN data, IP reputation, TLS certificates, request behavior, and authentication status. For manual review, IP lookup plus reverse DNS can quickly explain whether traffic looks like consumer, cloud, crawler, or mail infrastructure. ### FAQ **Can reverse DNS be faked?** PTR records are controlled by the IP owner or delegate, so they can be misleading if not verified with forward DNS. **Does every IP have reverse DNS?** No. Many IPs have no useful PTR record or only a generic provider hostname. ## Traceroute vs IP Geolocation: Why They Do Not Always Agree Canonical: https://ip.crafzo.com/blog/traceroute-vs-ip-geolocation Published: 2025-09-27 | Updated: 2026-09-22 | 2 min read Traceroute shows the path packets take; geolocation estimates where an address is registered. Why the two disagree and which one answers which question. ### What traceroute measures Traceroute shows the network path packets take toward a destination, including intermediate hops that respond along the route. It is useful for latency, routing loops, packet loss clues, and seeing which networks traffic crosses. ### What geolocation estimates IP geolocation estimates where an IP address is associated geographically. It does not trace the path from your device to the destination. A router hop can appear in one place while the final IP geolocation shows another, especially with anycast, CDNs, mobile networks, and provider gateways. ### How to troubleshoot Use IP lookup for identity and approximate location. Use traceroute for path and latency. Use both when diagnosing VPN exits, CDN routing, or strange regional performance. Do not assume disagreement means one tool is broken. They answer different questions. ### FAQ **Can traceroute show exact location?** No. Hop names and IPs can suggest locations, but traceroute is not a precise geolocation tool. **Why does a route go through another country?** Routing follows provider policy and network efficiency, not always geographic shortest paths. ## Subnet and CIDR Basics for IP Range Lookups Canonical: https://ip.crafzo.com/blog/subnet-cidr-ip-range-basics Published: 2025-09-28 | Updated: 2026-09-22 | 2 min read CIDR notation such as 203.0.113.0/24 describes a range of addresses. How to read it, and why security teams block or allow networks rather than single IPs. ### What CIDR notation means CIDR notation describes a block of IP addresses using a prefix, such as 203.0.113.0/24. The number after the slash indicates how much of the address is fixed. Smaller prefix numbers usually represent larger ranges. This is why a single rule can cover many addresses. ### Why ranges matter Attackers, crawlers, and cloud providers often use many IPs in the same range. Looking at only one address can miss a broader pattern. At the same time, broad range blocks can create false positives if the network is shared by many legitimate customers. ### Safe range policies Start with narrow rules and expand only when evidence shows the whole range is involved. Keep notes about why each range was blocked or allowed. Use IP lookup, ASN data, and logs to understand whether a CIDR belongs to a single source or a large shared provider. ### FAQ **What does /24 mean?** For IPv4, a /24 usually contains 256 addresses, though usable host counts depend on context. **Should I block a whole subnet?** Only when the evidence supports it. Broad blocks can affect legitimate users. ## Private, Reserved, and Special IP Addresses: What They Mean Canonical: https://ip.crafzo.com/blog/private-reserved-special-ip-addresses Published: 2025-09-29 | Updated: 2026-09-24 | 2 min read Addresses such as 10.0.0.1, 192.168.1.1 and 127.0.0.1 are private, loopback or reserved. What each range is for and why a public lookup returns nothing for them. ### Private addresses Private IP ranges are used inside local networks and are not routed on the public internet. Common examples include 10.0.0.0/8 and 192.168.0.0/16. Many homes and offices reuse the same private ranges because they are only meaningful inside each local network. ### Special-use addresses Some IP ranges are reserved for loopback, link-local, benchmarking, documentation, multicast, and other special purposes. | Range | Purpose | What a public lookup returns | | --- | --- | --- | | 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 | Private networks (RFC 1918) | Nothing: never routed on the internet | | 100.64.0.0/10 | Shared address space for carrier-grade NAT (RFC 6598) | Nothing: lives between the subscriber and the ISP | | 127.0.0.0/8 and ::1 | Loopback: the device talking to itself | Nothing | | 169.254.0.0/16 and fe80::/10 | Link-local: a single network segment, often when DHCP failed | Nothing | | 192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24, 2001:db8::/32 | Documentation and examples | Nothing: reserved so examples never hit a real host | | fc00::/7 | IPv6 unique local addresses (the IPv6 counterpart of private ranges) | Nothing | | 224.0.0.0/4 and ff00::/8 | Multicast | Nothing: not a single host | | 0.0.0.0/8, 240.0.0.0/4, 255.255.255.255 | "This network", reserved, limited broadcast | Nothing | These addresses usually should not be treated like ordinary public visitor IPs in fraud, geolocation, or analytics systems. ### How tools should handle them A good IP lookup tool validates the address and explains when the IP is private or special-use instead of pretending it has a normal public location. For public geolocation, check the public IP that websites see, not the private address assigned inside your Wi-Fi or LAN. ### FAQ **Can 192.168.1.1 be geolocated?** No. It is a private local address and does not map to a public internet location. **What is 127.0.0.1?** It is loopback, commonly called localhost, and refers to the same machine. ## Mobile Carrier IP Geolocation: Why Phone Locations Often Look Wrong Canonical: https://ip.crafzo.com/blog/mobile-carrier-ip-geolocation Published: 2025-10-01 | Updated: 2026-09-26 | 6 min read Phones exit the internet through carrier gateways, often in another city. Why mobile IP geolocation looks wrong and what it can and cannot tell you. ### Why a phone's IP shows the wrong city A phone on mobile data does not reach the internet from where it is standing. Its traffic travels inside the carrier's network to a gateway, and only there does it get a public IP address and leave for the wider internet. A geolocation lookup sees that gateway's address, and the database places the address wherever the gateway, or the block it belongs to, was recorded. The result can be the right city, a regional hub two hundred kilometers away, or the carrier's headquarters in another part of the country. That is the whole explanation for most 'my phone shows another city' cases. It is not a compromised device, a broken tool, or a location the phone has revealed. The [wrong-location troubleshooting guide](https://ip.crafzo.com/blog/ip-lookup-wrong-location-reasons) covers the other causes that apply to any connection; this guide is only about the mobile one. ### Carrier gateways: APN, PGW and UPF When a phone attaches to a mobile network it opens a data session to an Access Point Name, the APN, which selects the network the session should reach, usually the public internet. On 4G, the 3GPP architecture (TS 23.401) terminates that session at the PDN Gateway, the PGW, which hands out the phone's IP address and connects it to the external network. On 5G (TS 23.501) the same job belongs to the User Plane Function, the UPF, with the address anchored there. Whichever generation, the address a website sees is the one issued at the gateway, not one tied to the cell tower. Carriers run a limited number of these gateways and place them where it is efficient: in a few regional data centers, sometimes in one national site. A subscriber in a small town may be anchored at a gateway in the nearest major city, and a subscriber near a border may be anchored in a different region altogether. The distance between phone and gateway is invisible to the phone and to the website; it is only visible as a geolocation error. ### Carrier NAT and shared address pools Mobile networks have far more subscribers than public IPv4 addresses, so most run carrier-grade NAT: many phones share one public address, drawn from a pool at the gateway, with the private side often using the 100.64.0.0/10 shared address space that RFC 6598 reserved for exactly this. Two consequences follow for geolocation. The address a phone uses today may have been used by a subscriber in another town yesterday, so any location learned from past traffic is stale. And a database can only place the pool, not the people behind it; the [CGNAT guide](https://ip.crafzo.com/blog/cgnat-shared-ip-addresses) covers what else sharing changes. ### Where the database puts the address Geolocation providers estimate the location of an address block from registry records, from feeds the operator publishes (the format in RFC 8805 exists for this), from latency measurements and from user corrections. For a fixed-line block that method converges on a neighborhood. For a mobile gateway block it converges on the gateway, or on the carrier's registered address, because that is where the block genuinely sits. MaxMind's accuracy notes say the same thing from the provider's side: accuracy varies with the type of address, cellular versus broadband among them, addresses used in mobile networks may be used by phones across a large distance, and where an address cannot be placed with confidence they publish only the country or region and omit the city. That is the expected outcome of measuring a gateway rather than a handset. Some carriers publish geolocation feeds that map pools to the regions they serve, which improves results to the regional level. None can publish anything finer, because the pool is shared across the region by design. ### Wi-Fi versus cellular The same phone gives two different answers within a minute. On home Wi-Fi it uses the household's broadband address, which databases usually place in the right town. Switch to mobile data and it uses a carrier gateway address, placed at the gateway. A phone that walks out of Wi-Fi range appears to jump cities, which is also why login-risk systems see mobile users as constant travelers; see the [impossible travel guide](https://ip.crafzo.com/blog/impossible-travel-detection-ip). ### IPv4 and IPv6 on mobile Most modern mobile networks are dual-stack or IPv6-first. RFC 6459 and RFC 7066 describe how a 3GPP device receives a /64 IPv6 prefix for each data session, so IPv6 traffic carries an address unique to the phone while IPv4 traffic still goes through carrier NAT. Geolocation databases hold far less history for IPv6 blocks, so an IPv6 lookup of the same phone can land in a different city from the IPv4 one, or only at country level. Checking both addresses with the [IPv6 lookup tool](https://ip.crafzo.com/ipv6-lookup) makes the difference visible. ### Which location level to trust Country is the reliable level for a mobile address: gateways sit inside the carrier's own country, with rare exceptions for roaming, where traffic can be routed home through the subscriber's own carrier and appear in the home country. Region is reliable only if the carrier has regional gateways and publishes them. City is an estimate of the gateway, not the handset, and coordinates are the center of an area. The [accuracy guide](https://ip.crafzo.com/blog/how-accurate-are-ip-address-location-lookups) explains the general error budget; for mobile addresses, assume the city is wrong until something else confirms it. ### What this means for login and fraud systems Treat a mobile address as a signal about the network, not about the person's whereabouts. A city mismatch from a cellular ASN is expected and should not by itself trigger a lockout, a step-up or an alarming message to the user. Use country and network type from the address, and get location certainty from the account's own history and device rather than from the gateway. Where a decision needs the user's position, ask the device for it with consent; the IP address cannot supply it. In user-facing wording, avoid claiming to know where the person is when the address only says which gateway they used. ### FAQ **Why does my phone IP show another city?** Your traffic leaves the carrier's network at a gateway that can be far from you, and the lookup places the gateway's address. It is normal and does not mean your phone or the tool is at fault. **Can IP lookup track a phone exactly?** No. A mobile IP identifies a shared carrier gateway pool, not a handset. It gives country and network type reliably, region sometimes, and city only as an estimate of the gateway. **Why does my phone show a different city on Wi-Fi and mobile data?** On Wi-Fi it uses your home broadband address, usually placed near you; on mobile data it uses a carrier gateway address placed at the gateway. The phone has not moved; the exit point has. **Is the country from a mobile IP reliable?** Usually yes, because gateways sit in the carrier's own country. Roaming is the exception: traffic can be routed through the home carrier and appear there instead of where you are. ### Sources - 3GPP TS 23.401: GPRS enhancements for E-UTRAN access (PDN Gateway): https://www.3gpp.org/dynareport/23401.htm - 3GPP TS 23.501: System architecture for the 5G System (User Plane Function): https://www.3gpp.org/dynareport/23501.htm - RFC 6459: IPv6 in 3rd Generation Partnership Project (3GPP) Evolved Packet System (EPS): https://www.rfc-editor.org/rfc/rfc6459 - RFC 7066: IPv6 for Third Generation Partnership Project (3GPP) Cellular Hosts: https://www.rfc-editor.org/rfc/rfc7066 - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space: https://www.rfc-editor.org/rfc/rfc6598 - RFC 8805: A Format for Self-Published IP Geolocation Feeds: https://www.rfc-editor.org/rfc/rfc8805 - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## Impossible Travel Detection With IP Location: A Practical Guide Canonical: https://ip.crafzo.com/blog/impossible-travel-detection-ip Published: 2025-10-02 | Updated: 2026-09-25 | 7 min read Use IP geolocation carefully to detect suspicious account logins that appear too far apart in too little time. ### What impossible travel means Impossible-travel detection compares two authentication events for the same account and asks one question: could a person have moved from where the first login appears to have come from to where the second appears to have come from, in the time between them? If the implied speed is beyond anything a commercial flight can do, at least one of the two sessions was not the account holder in that place. Identity providers ship a version of this under different names. Microsoft Entra ID Protection calls it 'atypical travel': two sign-ins from geographically distant locations, at least one of them unusual for that user given past behavior. Microsoft Defender for Cloud Apps has an 'impossible travel' anomaly policy, and Okta's Behavior Detection evaluates 'velocity', the distance and time elapsed between two consecutive sign-in attempts. Underneath, the mechanism is the same: an estimated location for each IP address, a distance, a clock and a threshold. ### The distance and time logic The calculation has three steps. Look up the estimated coordinates of the address behind each login. Compute the great-circle distance between the two points (the haversine formula is the usual choice). Divide by the time between the events to get an implied speed, and compare it with a threshold that stands for the fastest plausible travel. The threshold is a design choice. Long-haul airliners cruise at roughly 900 km/h, so an implied speed far above that cannot be a person carrying a laptop. Implementations add a margin for the error in the location estimates, and most ignore pairs that are close together: two estimates 80 km apart inside one metro area say nothing about travel and everything about database noise. ### A worked example An account authenticates at 09:00 UTC from an address whose estimated location is central London (about 51.5 N, 0.1 W). At 09:40 UTC the same account authenticates from an address placed in Manhattan (about 40.7 N, 74.0 W). The great-circle distance between those points is roughly 5,570 km. Covering it in 40 minutes implies a speed of about 8,350 km/h, around nine times the cruising speed of an airliner. Nobody made that trip, so the pair is flagged. Change one number and the picture changes. Had the second login come at 17:00 UTC, eight hours later, the implied speed would be about 700 km/h, which a direct flight can manage, so the pair should not fire on its own. Had it come from Birmingham, 160 km from London, the 40-minute gap would imply 240 km/h: a train, and within the error of city-level geolocation anyway. ### Why IP geolocation is an approximation Geolocation databases do not measure devices. They infer where an address block is used from registry records, ISP-published feeds, latency measurements and corrections, and publish the result as an area with a center point. Country is usually right; city is an estimate often wrong by tens or hundreds of kilometers; the coordinates mark the center of the chosen area, not a building. MaxMind, whose data many tools use, publishes accuracy figures that vary widely by country and network type, and the [accuracy guide](https://ip.crafzo.com/blog/how-accurate-are-ip-address-location-lookups) goes through the reasons. For impossible-travel logic the consequence is direct: the distance you compute carries the error of both endpoints. Two estimates each off by 200 km can produce a 400 km 'trip' between logins made in the same room. ### Where false positives come from VPN exits. A user who connects to a VPN between two logins appears to jump to the exit server's country in seconds, and jumps back on disconnecting. The [VPN detection checklist](https://ip.crafzo.com/blog/how-to-tell-if-ip-is-vpn) covers the signals that identify an exit address. Mobile carrier gateways. A phone's traffic leaves the carrier network through a gateway that can be hundreds of kilometers from the handset, so a phone that moves between gateways, or switches from Wi-Fi to mobile data, appears to teleport. [Mobile carrier geolocation](https://ip.crafzo.com/blog/mobile-carrier-ip-geolocation) explains why. Carrier-grade NAT. Many subscribers share one public address, and the address a subscriber gets can change between sessions, so consecutive logins from one household can carry two addresses with two estimated locations. See [CGNAT and shared addresses](https://ip.crafzo.com/blog/cgnat-shared-ip-addresses). Corporate networks. Branch offices, remote workers and cloud desktops often exit through a headquarters or data-center address registered somewhere else, so a user in one city appears wherever the company's egress lives. IPv6 and address rotation. Dual-stack devices present an IPv4 and an IPv6 address that databases place in different cities, and IPv6 privacy extensions rotate the device half of the address on a schedule, so a login over IPv4 compared with a later one over IPv6 can show a distance that is pure database artifact; see the [IPv4 versus IPv6 guide](https://ip.crafzo.com/blog/ipv4-vs-ipv6-what-the-shift-means-for-your-privacy). ### Respond to risk, not to the alert The alert is a probability, so the response should scale with it rather than snapping to a lock. NIST's Digital Identity Guidelines (SP 800-63B) frame authentication in assurance levels and authenticator strength, so the translation for a suspicious sign-in is to require a stronger authenticator before the session gets anything valuable. NIST's Zero Trust Architecture (SP 800-207) adds that access decisions are made continuously from context, the user, device, location and behavior together, never from one attribute. Step-up authentication is the natural first response: ask for a second factor, preferably a phishing-resistant one, and let the session continue if it passes. Until it does, limit what the session can do; reading is safer than changing an email address or a payout account. Notify the user through a channel the attacker does not control, and reserve termination and lockout for the cases where the step-up fails or other signals confirm compromise. ### Context that separates travel from takeover Device consistency. The same browser fingerprint, device identifier or push-registered phone across both logins points to one person whose network changed; a new device on the distant login points the other way. Login history. If the account has appeared from both locations before, or from the same VPN provider or corporate egress, the pattern is normal for this user; Microsoft's and Okta's detections both compare against the user's own past sign-ins for this reason. Session and account context. Was the first session still active when the second began? Did the second go straight for recovery details, a new payment method or a data export, or follow a fresh password reset? Those actions are what account takeover is for, and they matter more than the kilometers. Network type. An address classified as hosting, VPN, proxy or Tor on the distant login is a stronger signal than a residential ISP address in an unfamiliar city; the [VPN and proxy checker](https://ip.crafzo.com/vpn-proxy-checker) shows which applies. ### When an alert deserves investigation Escalate when the implied speed is impossible even after allowing for geolocation error and the distant login arrived on a new device or went straight for sensitive actions; when the address is a hosting or anonymizer range rather than a residential ISP; when the step-up challenge failed or was abandoned; when the same distant address appears across several accounts at once, the signature of credential stuffing; and when the user, asked through a trusted channel, does not recognize the activity. Treat it as noise when both sessions share a device, when one address belongs to a VPN or corporate egress the account uses routinely, when the distance is within the expected error of city-level geolocation, or when the account has a history at both locations. Log the alert either way; a pattern of near-misses is itself worth knowing about. ### FAQ **Should impossible travel always lock an account?** No. It is a probabilistic signal. The proportionate response is step-up authentication with restricted actions until it passes; lock the account only when the step-up fails or other evidence confirms compromise. **Can VPNs trigger impossible travel?** Yes. Connecting or disconnecting a VPN between two logins moves the apparent location to or from the exit server's country in seconds, which is why login history and device consistency have to be read alongside the distance. **What speed threshold should I use?** There is no standard number. Airliners cruise at roughly 900 km/h, so treat speeds far above that as impossible, add a margin for geolocation error, and ignore pairs closer together than the error you expect from city-level data. ### Sources - NIST SP 800-63B: Digital Identity Guidelines, Authentication and Lifecycle Management: https://csrc.nist.gov/pubs/sp/800/63/b/upd2/final - NIST SP 800-207: Zero Trust Architecture: https://csrc.nist.gov/pubs/sp/800/207/final - Microsoft Entra ID Protection: risk detections (atypical travel): https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks - Microsoft Defender for Cloud Apps: anomaly detection policies (impossible travel): https://learn.microsoft.com/en-us/defender-cloud-apps/anomaly-detection-policy - Okta: About Behavior Detection (velocity): https://help.okta.com/en-us/content/topics/security/behavior-detection/about-behavior-detection.htm - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## API Rate Limiting by IP: Benefits, Limits, and Safer Rules Canonical: https://ip.crafzo.com/blog/api-rate-limiting-by-ip Published: 2025-10-07 | Updated: 2026-09-26 | 9 min read Design better API limits by combining IP, token, account, and organization-level controls. ### What IP-based rate limiting is IP-based rate limiting counts the requests arriving from one source address inside a time window and slows or refuses the address once it passes a threshold. The counter can be a fixed window (so many requests per minute), a sliding window, or a token bucket that refills at a steady rate and allows short bursts. Whichever algorithm you pick, the key is the same: the client's address, which is why the technique works before a request has been authenticated and why it breaks down when one address stands for many people. It is usually applied at the edge: an API gateway, a WAF, a reverse proxy or a CDN rule. It can also live in the application, which is the right place once a limit depends on who the caller is rather than where the packets came from. This guide is about designing the limits; the [Node.js rate limiting guide](https://ip.crafzo.com/blog/rate-limiting-ip-nodejs-guide) covers the implementation. ### Why it is useful An IP limit needs no account, no API key and no knowledge of the caller, so it protects the endpoints that exist before authentication: login, signup, password reset, search, and anything that costs more to serve than to request. It absorbs accidental client loops, blunt scrapers and brute-force scripts before they reach the database, and it does so cheaply, because the check runs on a counter rather than on business logic. OWASP lists unrestricted resource consumption among the top API security risks and names rate limiting, per-client quotas and response-size limits as the controls that address it. An IP limit is the simplest of those controls to switch on, which is a reason to have one and also a reason not to stop there. ### The 429 response and Retry-After The status code for a rejected request is 429 Too Many Requests, defined in RFC 6585. The RFC says the response should explain the condition and may carry a Retry-After header telling the client how long to wait. RFC 9110, the current HTTP semantics specification, defines Retry-After as either an HTTP date or a number of seconds. Send it: a well-behaved client will back off exactly as long as you ask, and a client that ignores it has told you something about itself. Beyond the standard, an IETF working group is drafting RateLimit header fields that let a server advertise the quota, what remains of it and when the window resets, so clients can pace themselves before hitting 429. The draft is still work in progress, but its field names are already widely copied. Whatever headers you choose, keep the response body short and consistent, and log every 429 with the address, the limit that tripped and the endpoint, because those logs are where abuse patterns first show up. ### Limits at more than one level A per-IP limit answers one question: is this address sending too much? It says nothing about whether one customer is consuming more than they paid for or whether a stolen key is being used from a hundred addresses at once. Those need limits attached to identity. In practice a well-designed API has several concentric limits: a generous per-IP limit that mainly catches unauthenticated abuse; a per-key or per-user quota that enforces the plan the caller signed up for; an organization or tenant quota so that one customer with many keys cannot starve the others; and endpoint-specific or cost-weighted limits for the operations that are expensive to serve. Combining IP with identity is where the real value lies. One key used from many addresses in a short time suggests a leaked credential. Many keys used from one address suggests either a legitimate shared integration server or an account farm; the request pattern tells you which. A per-IP limit that is looser than the per-key quota lets those combinations surface as anomalies instead of hiding them behind a wall of 429s. ### Shared addresses: CGNAT, corporate NAT and IPv6 Many people share one public IPv4 address. Mobile carriers and some fixed-line ISPs place customers behind carrier-grade NAT, using the 100.64.0.0/10 shared address space that RFC 6598 set aside for it, and one public address can stand for thousands of subscribers. Offices, universities and hospitals route everyone through a handful of egress addresses. A strict per-address limit hits all of them at once, and the people it hits have no idea why. The [CGNAT guide](https://ip.crafzo.com/blog/cgnat-shared-ip-addresses) explains how large the pool behind one address can be. IPv6 has the opposite problem. A single device can hold many addresses inside its /64, and privacy extensions rotate them, so a limit keyed on the full 128-bit address is trivial to sidestep. Count IPv6 traffic by prefix instead: the /64 is the smallest sensible unit, and because RFC 6177 describes end-site assignments in the range of /48 to /56, a determined client can rotate across many /64s, which argues for a second, looser counter at the /56 or /48 level. The [IPv4 versus IPv6 guide](https://ip.crafzo.com/blog/ipv4-vs-ipv6-what-the-shift-means-for-your-privacy) covers why addresses rotate. The design consequence is the same for both: treat the IP limit as coarse protection with a high threshold, prefer throttling to blocking when an address is shared, and put the precise quota on the identity layer. ### Behind proxies and load balancers If your API sits behind a load balancer, a CDN or a reverse proxy, the address on the socket is the proxy's, and a per-IP limit keyed on it will throttle your own infrastructure. The real client address arrives in a header: X-Forwarded-For by convention, or the Forwarded header standardized in RFC 7239. Read it only when the connection comes from a proxy you control, and take the address your proxy appended rather than the first one in the list, because anything a client can put in a header, an attacker can forge. A forged header either lets the attacker evade the limit or gets an innocent address throttled. The [X-Forwarded-For guide](https://ip.crafzo.com/blog/x-forwarded-for-real-client-ip) covers the trust rules in detail, and the [Cloudflare proxy guide](https://ip.crafzo.com/blog/cloudflare-proxy-ip-addresses) covers the CDN case. ### API abuse signals beyond the counter A request count is one signal. APIs receive a great deal of automated traffic, so the useful question is not whether a client is automated but whether its behavior matches a legitimate integration. Several IP-level signals help separate the two, and none of them is a verdict on its own. Hosting ASN. Requests from cloud and hosting networks are normal for server-to-server integrations and abnormal for endpoints only a browser should call. Bots favor cloud servers because they are easy to automate, scale and replace; a checkout or signup endpoint seeing a burst from a hosting range deserves a closer look. The [data center versus residential guide](https://ip.crafzo.com/blog/data-center-ip-vs-residential-ip) explains the classification. Reputation. An address with recent abuse reports or a high [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) is a reason to apply a tighter bucket to it, not a reason to reject its traffic outright; shared addresses inherit the reputation of whoever last misbehaved behind them. Velocity and request pattern. Authentication failures per address, the ratio of errors to successes, an endpoint mix that no real client produces, and sequences such as walking through object IDs in order are the tells of scrapers and credential attacks. A sudden change in the country or ASN behind an established key is worth an alert even when the count is within limits. Account and IP combinations. Many accounts created or authenticated from one address, one account appearing from many addresses in minutes, or several keys sharing an address they never shared before are patterns that a per-IP counter alone never sees. Location and ISP context also helps support teams explain an unexpected request source to a customer. ### Risk-based throttling instead of blocking The response to a signal should scale with it. Throttle first: give a suspicious address a smaller bucket rather than none. Then require authentication, or a stronger form of it, for the actions that matter, so that abuse has to spend a credential to continue. Reserve outright blocks for clear, repeated abuse, give them an expiry, and record why they were added, because a block on a shared address is a block on people who did nothing. Measure the outcome. Track how many 429s reach clients that later authenticate successfully, how often support hears from customers behind carrier NAT, and how quickly abusive patterns stop when throttled. Those numbers tell you whether the thresholds are protecting the API or just its metrics, and they are the argument for changing them. ### FAQ **Should authenticated APIs use IP limits?** Yes, as an outer layer. The primary quota for an authenticated API belongs on the API key, user or organization; the IP limit catches unauthenticated abuse and anomalies such as one address driving many keys. **What happens with shared IPs?** A strict per-address limit can throttle many unrelated users behind one carrier or office address. Keep IP limits generous, attach identity-based quotas for the real allocation, and prefer throttling to blocking when an address is shared. **What should a 429 response include?** A short explanation and a Retry-After header saying when to try again, as RFC 6585 and RFC 9110 describe. Clients that honor it back off on their own; clients that ignore it are worth watching. **Should I rate limit IPv6 by address or by prefix?** By prefix. One device can use many addresses inside its /64, so count at the /64 at least, and consider a looser counter at the /56 or /48 level for clients that rotate across prefixes. **How do I rate limit behind a proxy or CDN?** Key the limit on the client address your trusted proxy appended to X-Forwarded-For or Forwarded, never on the socket address of the proxy and never on a header value a client could have written itself. **Why do bots use cloud IPs?** Cloud servers are easy to automate, scale, and replace. ### Sources - RFC 6585: Additional HTTP Status Codes (429 Too Many Requests): https://www.rfc-editor.org/rfc/rfc6585 - RFC 9110: HTTP Semantics (Retry-After): https://www.rfc-editor.org/rfc/rfc9110 - IETF Internet-Draft: RateLimit header fields for HTTP: https://datatracker.ietf.org/doc/draft-ietf-httpapi-ratelimit-headers/ - OWASP API Security Top 10 2023: API4 Unrestricted Resource Consumption: https://owasp.org/API-Security/editions/2023/en/0xa4-unrestricted-resource-consumption/ - RFC 7239: Forwarded HTTP Extension: https://www.rfc-editor.org/rfc/rfc7239 - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space: https://www.rfc-editor.org/rfc/rfc6598 - RFC 6177: IPv6 Address Assignment to End Sites: https://www.rfc-editor.org/rfc/rfc6177 ## Webhook IP Allowlisting: Security Benefits and Common Mistakes Canonical: https://ip.crafzo.com/blog/webhook-allowlist-ip-security Published: 2025-10-08 | Updated: 2026-09-22 | 1 min read Use IP allowlists safely for webhooks while avoiding brittle rules, stale provider ranges, and false confidence. ### Why allowlisting helps Webhook IP allowlisting restricts accepted requests to provider network ranges. It can reduce random internet traffic and basic spoofing attempts. It works best when combined with signature verification and replay protection. ### Common mistakes Teams often forget to update provider IP ranges, allow too broad a network, or rely on IP allowlisting without validating webhook signatures. Cloud providers and SaaS platforms may change ranges, so static rules need maintenance. ### Safe implementation Verify signatures first, check timestamp tolerance, log request IPs, and monitor rejected events. Use provider-published ranges when available. Use IP lookup when debugging unexpected webhook sources or investigating failed allowlist matches. ### FAQ **Is IP allowlisting enough for webhooks?** No. Always verify webhook signatures when the provider supports them. **Why did a valid webhook get blocked?** The provider may have changed IP ranges, or traffic may be coming through a different delivery path. ## Blocking IP Addresses in a Firewall: Best Practices Canonical: https://ip.crafzo.com/blog/firewall-block-ip-best-practices Published: 2025-10-09 | Updated: 2026-09-26 | 7 min read How to block abusive IP addresses in a firewall without sweeping up shared networks, and how to keep the block list from turning into a maintenance burden. ### When blocking makes sense Blocking is appropriate for clear abuse from infrastructure that exists to produce it: repeated scanning, brute-force attempts, exploit traffic, or unwanted automation from a dedicated server. It is far less safe for residential, mobile, school, office and carrier addresses, because many people stand behind each of those and none of them can see your firewall rule. NIST's firewall guidance (SP 800-41 Rev. 1) recommends a default-deny posture, rules derived from a written policy and risk analysis, and regular review of the rule set. IP blocking fits inside that: each rule should answer to a reason, an owner and a review date, not to the mood of the moment an alert fired. ### Single IP, CIDR range or ASN Start with the single address. Widen to a CIDR range, written in the notation RFC 4632 defines, only when your logs show the abuse spread across that range rather than one host inside it; a /24 holds up to 254 other machines, and a /16 holds tens of thousands. Widen to an autonomous system only when the whole network is one you never expect to serve, such as a hosting provider sending traffic to a consumer login page, and never for a residential or mobile network, where an ASN block is a block on a city. Before widening, check what else lives in the range: reverse DNS, the RDAP registration and a sample of the addresses' reputation. If the range belongs to a provider with an abuse desk, a report to that desk removes the source; a firewall rule only removes your view of it. ### Temporary or permanent Make rules temporary by default. The address an attacker used this week returns to a pool and is handed to a customer next week; a permanent rule then punishes that customer for someone else's history. Attach an expiry to every block created during an incident, keep the permanent list short and deliberate, and review it on a schedule. A rule nobody can explain should be removed, not kept out of caution. Record a reason code, the incident reference and the author with each rule. The record is what lets the next person decide whether the rule still earns its place. ### Collateral damage on shared addresses One public IPv4 address rarely equals one person. Carriers and some ISPs place subscribers behind carrier-grade NAT in the 100.64.0.0/10 space that RFC 6598 reserved for it, so a single address can represent thousands of mobile or broadband customers; the [CGNAT guide](https://ip.crafzo.com/blog/cgnat-shared-ip-addresses) explains the mechanics. Phones exit through regional carrier gateways far from the handset, covered in the [mobile carrier guide](https://ip.crafzo.com/blog/mobile-carrier-ip-geolocation). Companies route entire offices through a few egress addresses, and VPN exits carry legitimate users alongside whoever abused the same exit an hour earlier. For those addresses a hard block is a blunt tool. Prefer a rate limit, a challenge or an account-level control, and if a block is unavoidable, make it short and monitor support channels for the people it caught. ### Country blocking and its limits Geo blocking uses IP location to allow, deny or alter access by country or region. It has legitimate uses in licensing, regulatory compliance, fraud controls and content delivery, and it works well enough at the country level to be worth having for those purposes. It is weak as a security control on its own, because location is an estimate and an attacker chooses where to appear from. The estimate is imperfect in predictable ways. Travelers and expatriates appear where they are, not where their account was opened. VPN and proxy users appear at the exit server. Businesses that route traffic through a central office or a cloud region appear there. Databases lag behind address reassignments, and some ranges are placed at a registry country that has nothing to do with the users; operators can publish corrections in the geolocation feed format described in RFC 8805, and MaxMind's own accuracy statements show how much the city-level figure varies by country and network. The [accuracy guide](https://ip.crafzo.com/blog/how-accurate-are-ip-address-location-lookups) goes through each cause. Over-blocking has a cost that rarely appears in the security dashboard: lost customers, frustrated travelers and support tickets that a single verification step would have avoided. Use country for broad routing and as one input to risk scoring, combine it with account and transaction context before enforcing anything, and give blocked users an appeal or fallback path where access matters. The [geolocation service guide](https://ip.crafzo.com/blog/ip-geolocation-service) describes how the underlying data is produced. ### Step-up controls and allowlists A block is the last rung of a ladder, not the first. Rate limits cap what an address can do without denying it. Challenges such as a CAPTCHA or an email confirmation filter automation while letting people through. Multi-factor authentication and step-up prompts protect the accounts an attacker actually wants. Read-only or reduced-function modes let a suspicious session continue without doing harm. Each of these fails more gracefully than a firewall rule when the address turns out to be shared. Allowlists invert the problem for the surfaces that should never be public. Administrative panels, deployment endpoints, database ports and webhook receivers can be restricted to known addresses, an office range, a VPN concentrator or a partner's published egress, so that the question is no longer who to block but who is permitted. Keep allowlists as tightly documented as blocklists; a forgotten entry is an open door. ### Logging, review and threat feeds Log the hits on every block rule. A rule that never matches is dead weight; a rule that matches thousands of times a day from a residential range is probably hurting customers. Review the logs alongside support tickets, and treat a spike in tickets from one region as evidence about a rule, not only about the region. Curated threat feeds can replace hand-built lists for the worst infrastructure. Spamhaus's DROP list, for example, names netblocks that its analysts assess as controlled by spam and cybercrime operations and recommends that they not be routed at all. Feeds age like every other list: automate their refresh, log what they block, and be ready to explain an entry that catches a legitimate customer. ### When not to block Do not block on a single event, on a shared address, on a partner's or your own scanner, or when the evidence is still developing and a narrower control would hold the line. Do not block a country to solve a fraud problem that account controls would solve. Do not add a rule you would not be able to justify to the customer it eventually catches. The [incident response triage guide](https://ip.crafzo.com/blog/incident-response-ip-triage) covers the decision sequence for a live incident, and the [IP reputation checker](https://ip.crafzo.com/ip-reputation-check) shows the current signals for an address before a rule is written. ### FAQ **Should firewall blocks expire?** For most incidents, yes. Addresses are reassigned and attackers move on within hours, so an expiring block ends the activity without punishing the next holder of the address. **Is blocking a whole country recommended?** Only for specific licensing, compliance or business reasons, with an appeal path. As a security control it over-blocks travelers, VPN users and routed business traffic while an attacker simply chooses another exit. **Should I block a single IP, a range or a whole ASN?** Start with the address. Widen to a range only when logs show abuse across it, and to an ASN only for a hosting network your surface never expects to serve; never block a residential or mobile ASN over one incident. **What is an allowlist and when should I use one?** A list of addresses permitted to reach a surface, with everything else denied. Use it for administrative panels, database ports and webhook receivers that should never be public, and document every entry as carefully as a block. **Is geo blocking always accurate?** No. VPNs, proxies, routing, and database lag can affect location results. **Can users bypass geo blocking?** Some can use VPNs or proxies, so geo blocking should not be your only security control. ### Sources - NIST SP 800-41 Rev. 1: Guidelines on Firewalls and Firewall Policy: https://csrc.nist.gov/pubs/sp/800/41/r1/final - RFC 4632: Classless Inter-domain Routing (CIDR): https://www.rfc-editor.org/rfc/rfc4632 - RFC 6598: IANA-Reserved IPv4 Prefix for Shared Address Space: https://www.rfc-editor.org/rfc/rfc6598 - RFC 8805: A Format for Self-Published IP Geolocation Feeds: https://www.rfc-editor.org/rfc/rfc8805 - Spamhaus: Don't Route Or Peer (DROP) lists: https://www.spamhaus.org/blocklists/do-not-route-or-peer/ - MaxMind: Geolocation accuracy: https://support.maxmind.com/knowledge-base/articles/maxmind-geolocation-accuracy ## Privacy-Safe IP Logging: What Product Teams Should Consider Canonical: https://ip.crafzo.com/blog/privacy-safe-ip-logging Published: 2025-10-13 | Updated: 2026-09-26 | 7 min read Build safer IP logging practices with retention limits, access controls, minimization, and security-focused use cases. ### Why teams log IPs IP addresses in logs serve security investigations, fraud review, abuse prevention, account recovery, rate limiting and operational troubleshooting. They are often the only link between an event and a network, which is why incident responders want them kept. They are also sensitive: an address reveals a provider and an approximate location, and combined with other records it can point at a person. Logging them well means serving the first set of needs without ignoring the second. ### When an IP address is personal data Under the EU's General Data Protection Regulation, personal data is any information relating to an identified or identifiable natural person, and Recital 30 names internet protocol addresses among the online identifiers that, combined with other information, may be used to identify people. The European Commission's own explainer lists an IP address among its examples of personal data. In the United Kingdom, the Information Commissioner's Office says the same: what identifies an individual could be an IP address or a cookie identifier as much as a name. The Court of Justice of the EU addressed the hardest case in Breyer (C-582/14, 19 October 2016): a dynamic IP address that a website operator stores constitutes personal data with respect to that operator where it has the legal means to identify the visitor with the help of additional information held by the internet service provider. The same judgment recognized that an operator may have a legitimate interest in storing such data to protect itself against cyberattacks, which is the legal shape of the security use case. In the United States the picture is set by state law. California's CCPA, as amended by the CPRA, defines 'personal information' to include identifiers such as an Internet Protocol address where the information identifies, relates to, or could reasonably be linked with a particular consumer or household. NIST's guide to protecting the confidentiality of personally identifiable information (SP 800-122) lists an IP or MAC address as PII when it consistently links to a particular person or small, well-defined group of people. The common thread is that whether an IP address is personal data depends on context and on what else you hold; in many practical settings it will be, and the safe design assumption is to treat it as such. This guide describes engineering practices, not legal advice; the obligations that apply to a specific service depend on jurisdiction and purpose, and qualified counsel should confirm them. ### Collect only what the purpose needs Minimization is both a GDPR principle (Article 5 requires data to be limited to what is necessary for the purpose) and good engineering. Decide, per log stream, whether the full address is needed. Security and abuse logs usually need it, because investigations reconstruct who did what from which network. Product analytics usually do not: country, region or a coarse network type answers the analytic question, and the address itself can be dropped at ingestion. Debug logs that happen to include request headers often carry addresses nobody intended to keep; find them and remove the field. A useful security log entry records the timestamp in UTC, the normalized address, the action attempted and, where appropriate, the account and the lookup result at that moment: country, ISP, network type, risk label. That is enough to reconstruct a decision later. Anything beyond it should have a stated purpose. ### Retention is a policy choice No single legal number says how long IP logs may be kept. The GDPR's storage-limitation principle asks that data be kept in identifiable form no longer than necessary for the purpose, which makes the retention period something you must justify rather than look up. Security teams need logs long enough to detect and investigate incidents that surface late; sector rules, contracts and litigation holds can extend that. Analytics rarely needs raw addresses beyond the aggregation step. Write the periods down per log type, state the reason for each, enforce them automatically with lifecycle rules rather than manual cleanup, and review them when the purpose changes. Indefinite storage without a purpose is the state to avoid; it accumulates risk and offers nothing in return. ### Truncation, hashing and aggregation Where the full address is not needed, reduce it at the point of collection. Truncating the last octet of an IPv4 address, or the interface half of an IPv6 address, keeps the network-level signal for analytics while removing the part that distinguishes one household or device from the next. Replacing the address with a keyed hash lets you count and correlate without storing the value, provided the key is protected and rotated; an unkeyed hash of an IPv4 address is reversible by enumerating the whole address space, so it does not anonymize anything. Aggregating to counts per country, ASN or network type is the strongest option when individual events are not needed. None of these techniques turns personal data into something else by itself: whether the result is anonymous or merely pseudonymous depends on what other data you hold and how easily the original could be recovered. Treat truncated and hashed values as reduced-risk, not risk-free, and document which transformation each log stream applies. ### Access controls and audit logging Logs that contain addresses are themselves a dataset to protect. NIST's log management guidance (SP 800-92) covers the essentials: restrict who can read and export logs, protect their integrity so an intruder cannot edit the record of their own activity, keep the clocks synchronized, and secure the transport and storage. Grant access by role, review it periodically, and record every read of the raw logs in an audit log that the same people cannot alter, so that access to personal data is itself accountable. IP lookups during an investigation also leave traces: which addresses were looked up, by whom and when. Keep that inside the same access model rather than in a browser history or a chat thread. ### Deletion and documentation Retention policies need a deletion process that actually runs: lifecycle rules on the log store, backups and archives included, and a way to verify that expired data is gone. Where individuals have rights to access or erasure, know how an address in a log maps to a request, and what security exceptions apply and why. Document the purpose of each log stream, its fields, its retention period, its transformation, who can access it and where it lives. That record is what an auditor, a regulator or a new engineer will ask for, and it is what keeps the privacy policy aligned with what the systems actually do. The [incident response triage guide](https://ip.crafzo.com/blog/incident-response-ip-triage) covers preserving specific log evidence when an investigation needs to hold it beyond the normal period. ### FAQ **Is an IP address personal data?** In many contexts, yes. GDPR Recital 30 names IP addresses among online identifiers, the CJEU's Breyer judgment held a stored dynamic address to be personal data for an operator able to identify the visitor, and California's CCPA lists Internet Protocol address among its identifiers. Treat it as personal data by default and confirm the specifics with counsel. **Should logs keep exact IPs forever?** No. Retention should match a stated security, operational or legal need and be enforced automatically. Indefinite storage of exact addresses without a purpose adds risk and no value. **How long should we keep IP logs?** There is no universal legal number. Set a period per log type that you can justify by purpose (incident detection windows, contractual or sector requirements), write it down, and enforce it with lifecycle rules. **Does truncating an IP address anonymize it?** It reduces identifiability; it does not guarantee anonymity. Whether a truncated or hashed value is anonymous depends on the other data you hold, and an unkeyed hash of an IPv4 address can be reversed by enumeration. ### Sources - Regulation (EU) 2016/679 (GDPR), Recital 30 and Article 4: https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng - Court of Justice of the European Union, press release on Case C-582/14 Breyer (19 October 2016): https://curia.europa.eu/jcms/upload/docs/application/pdf/2016-10/cp160112en.pdf - European Commission: What is personal data?: https://commission.europa.eu/law/law-topic/data-protection/reform/what-personal-data_en - ICO: What is personal information: a guide: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-information-what-is-it/what-is-personal-information-a-guide/ - California Civil Code section 1798.140 (CCPA definitions): https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?sectionNum=1798.140.&lawCode=CIV - NIST SP 800-122: Guide to Protecting the Confidentiality of Personally Identifiable Information (PII): https://csrc.nist.gov/pubs/sp/800/122/final - NIST SP 800-92: Guide to Computer Security Log Management: https://csrc.nist.gov/pubs/sp/800/92/final ## Incident Response IP Triage: A Fast Checklist Canonical: https://ip.crafzo.com/blog/incident-response-ip-triage Published: 2025-10-14 | Updated: 2026-09-26 | 9 min read A practical checklist for investigating suspicious IP addresses during security incidents. ### Start with the event, not the address An IP address on its own is the least informative part of an alert. Before enriching it, read the event that produced it: the WAF rule or detection that fired, the endpoint and method, the user agent, the headers, the payload category and the exact time. The same address can appear in harmless and harmful events within the same minute, so the address only means something in the context of what it did. NIST's incident response guidance (SP 800-61 Rev. 3) frames response as a cycle that runs from preparation through detection and analysis to containment, eradication, recovery and lessons learned. IP triage sits in the analysis step: its job is to turn an alert into a decision about scope and action, quickly and reversibly, while preserving what a later investigation will need. ### Capture the basics first Record the timestamp in UTC using the RFC 3339 format, and note the timezone of any log you copied it from; incidents that span systems in different zones lose hours to conversion mistakes. Record the request ID or correlation ID, the full headers, the endpoint, the account or session involved, the user agent and the observed behavior. Record the source IP together with how it was determined. If the request passed through a load balancer, CDN or proxy, the socket address is the proxy and the client address came from a forwarded header; the [X-Forwarded-For guide](https://ip.crafzo.com/blog/x-forwarded-for-real-client-ip) explains which value to trust. An investigation built on the wrong address blocks the wrong thing. Preserve the raw logs before you enrich anything. NIST SP 800-86, on integrating forensic techniques into incident response, describes the sequence as collection, examination, analysis and reporting, and stresses keeping the original data unaltered and documenting who handled it and when. Copy the relevant log segments to a location where retention and access are controlled, hash the copies, and work from the copies. ### Enrich the address Ownership and abuse contact. An RDAP query returns the registered network range, the organization and the abuse contact for the address, in the JSON format defined in RFC 9083. The [WHOIS and RDAP guide](https://ip.crafzo.com/blog/ip-whois-rdap-lookup) walks through a query, and the [abuse contact guide](https://ip.crafzo.com/blog/find-abuse-contact-from-ip) covers what to send. ASN. The autonomous system tells you what kind of network the address sits in: a consumer ISP, a mobile carrier, a hosting provider, a corporate network. That shapes both the likely explanation and the blast radius of a block; see the [ASN lookup guide](https://ip.crafzo.com/blog/asn-lookup-explained). Geolocation. Country is usually right, city is an estimate, and the coordinates are the center of an area, not a building. Treat location as context for whether the traffic is plausible for the account, and read the [accuracy guide](https://ip.crafzo.com/blog/how-accurate-are-ip-address-location-lookups) before quoting a city in a report. Reputation. Blocklist hits, recent abuse reports and a high [fraud score](https://ip.crafzo.com/ip-fraud-score-checker) raise the prior that the traffic is hostile. They are indicators about the address's recent history, not evidence about the request in front of you, and a shared address inherits whatever its last occupant did. Reverse DNS. The PTR record for the address, from the in-addr.arpa or ip6.arpa tree defined in RFC 1035, often names the provider or the host role. A hostname that says the address is a residential pool, a mail server or a cloud instance is useful context; the [reverse DNS guide](https://ip.crafzo.com/blog/reverse-dns-lookup-ip-reputation) explains how to read it and why it can be missing or misleading. Tor, VPN and proxy indicators. The Tor Project publishes a list of current exit relay addresses, and commercial data flags VPN exits and open proxies. Anonymized traffic is not itself an attack, but it changes what a block would achieve: the person behind it will be on a different address in a minute. The [VPN and proxy checker](https://ip.crafzo.com/vpn-proxy-checker) shows which flags apply. History. Search your own logs for the address, its /24 and its ASN over the preceding weeks. Clusters, such as the same ASN, the same endpoint, the same payload, or repeated targeting of one account, are what turn a single alert into a pattern worth acting on. ### Read the WAF context carefully A WAF alert records that a request matched a rule, not that the request was malicious. Rules that inspect for SQL injection or path traversal fire on legitimate input all the time: a customer pasting a code snippet into a support form, a search for a product name that contains a quote character, a security scanner you hired. Check the rule's history in your environment before treating a match as hostile, and look at what the same address did around it. The contrast that matters is between a hosting address probing administrative URLs it was never linked to, and a logged-in customer who triggered one rule once in a normal session. The first is a pattern; the second is a tuning item. Keep examples of both, with the request details, so the next analyst can tell them apart faster. ### Add the user and account context If the request touched an account, the account is where the answer is. Was there an authenticated session, and how old is the account? Did the activity follow a password reset, a new device or a change of recovery email? Did it go straight for the things account takeover is for: payout details, data export, API key creation? Compare the address with the account's own history; an unfamiliar country is a weak signal on its own and a strong one alongside a new device and a recovery-email change. The [impossible travel guide](https://ip.crafzo.com/blog/impossible-travel-detection-ip) covers how to weigh distance against those signals. ### Decide what to block, and for how long The options run from doing nothing, through monitoring, challenging the traffic and tuning the rule, to blocking one address, blocking a range, blocking an autonomous system, and escalating to legal or abuse reporting. Choose the narrowest control the evidence supports. One IP is right when the abuse is coming from a single dedicated host. A CIDR range is right only when your logs show the abuse spread across the range; blocking a /24 because one address in it misbehaved takes out up to 254 unrelated hosts. An ASN block removes every customer of that network and belongs to consumer-only surfaces facing a hosting provider whose traffic you never expect, never to a residential or mobile ASN. The [firewall blocking guide](https://ip.crafzo.com/blog/firewall-block-ip-best-practices) goes deeper on scope. Make the block temporary by default. Attackers move addresses within hours, while the address you blocked returns to an ISP pool and is handed to someone else. Set an expiry, put the rule on a review list, and record the reason code and the incident reference with it, so that a rule nobody remembers cannot outlive the incident that created it. For shared addresses, mobile gateways and carrier NAT ranges, prefer a challenge or a rate limit to a block; the [CGNAT guide](https://ip.crafzo.com/blog/cgnat-shared-ip-addresses) explains how many people one address can represent. ### Document and preserve evidence For every action, write down what was observed, what was decided, who decided it, when it takes effect and when it expires. Store the preserved log copies, their hashes and the enrichment results at the time of the decision, because RDAP records, reputation scores and geolocation data all change, and a review months later needs to know what you saw, not what a lookup says now. NIST SP 800-92 covers protecting the logs themselves: restricted access, integrity checks and a retention period that matches how long incidents take to surface. If the incident may involve law enforcement or a dispute, keep a chain of custody for the evidence from the start; it is far easier to maintain than to reconstruct. ### Watch for false positives The commonest false positives are structural rather than malicious: a carrier NAT address shared by thousands of subscribers, a corporate egress point, a partner's integration server that changed address, a monitoring service you forgot about, a mobile gateway that places a customer in the wrong city, or a penetration test someone else in the company commissioned. Each looks alarming in isolation and obvious in context. Build the reversal path before you need it: a way for a blocked customer to reach support, a review of expiring rules, and a habit of checking what else lives behind an address before acting. A narrow, reversible control applied quickly is almost always better than a broad one applied with certainty you do not have. ### FAQ **What should I save before blocking?** The raw log segments with timestamps in UTC, request IDs, headers, the account involved and how the source address was determined, plus the enrichment results at the time and the reason for the action. **Should I block during an active attack?** Yes when needed, but choose the narrowest reversible control the evidence supports, give it an expiry, and prefer a challenge or rate limit over a block when the address is shared. **Should I block a single IP, a range or an ASN?** A single address for a dedicated host, a range only when your logs show abuse across it, and an ASN only for a hosting network whose traffic your surface never expects. Never block a residential or mobile ASN over one incident. **How long should an incident block last?** Long enough to end the activity and no longer. Attackers change addresses within hours and the blocked address is soon reassigned, so set an expiry, review it, and extend only if the abuse returns. **Should WAF alerts be blocked automatically?** Some can be, but many environments need tuning to avoid false positives. **What IP data is most useful for WAF review?** Network type, ASN, country, risk score, and history across prior events are especially useful. ### Sources - NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management: https://csrc.nist.gov/pubs/sp/800/61/r3/final - NIST SP 800-86: Guide to Integrating Forensic Techniques into Incident Response: https://csrc.nist.gov/pubs/sp/800/86/final - NIST SP 800-92: Guide to Computer Security Log Management: https://csrc.nist.gov/pubs/sp/800/92/final - RFC 3339: Date and Time on the Internet: Timestamps: https://www.rfc-editor.org/rfc/rfc3339 - RFC 1035: Domain Names - Implementation and Specification (PTR records): https://www.rfc-editor.org/rfc/rfc1035 - RFC 9083: JSON Responses for the Registration Data Access Protocol (RDAP): https://www.rfc-editor.org/rfc/rfc9083 - Tor Project: bulk exit list: https://check.torproject.org/torbulkexitlist