Tools
IP Lookup (IP Location & ISP)
Look up any IP address: country, city, internet service provider (ISP), ASN and time zone. Leave the field empty to look up your own IP. The query runs from your browser; nothing is stored on our server.
Result
Type an IP address, or leave the field empty and press Look up. Country, city, ISP, ASN and time zone appear here.
How to use the IP Lookup (IP Location & ISP)
- Type or paste the IP address
Enter an IPv4 address such as 8.8.8.8 or an IPv6 address such as 2001:4860:4860::8888. You can also paste an address with a port (1.2.3.4:443) or a bracketed IPv6 address from a log line. The tool strips the extras itself.
- Press Look up
The Enter key does the same. With an empty field, the tool looks up your own public IP. The Quick lookup buttons try Google DNS, Cloudflare DNS or an IPv6 example in one click.
- Check the badge
A green Public IPv4 or Public IPv6 badge means the address routes on the internet. A yellow badge points to an internal or reserved range; in that case the tool never contacts an outside service.
- Read the rows
Country, region and city give the location, while ISP and ASN name the network owner. The time zone row also shows the current local time. When coordinates exist, View on map opens the approximate point on OpenStreetMap.
- Share the result
Copy result puts every row on your clipboard. Copy link creates an address that reopens the same lookup, so you can send it to your team together with your log notes.
How does the tool evaluate an IP address?
The tool does not calculate anything. It first parses and classifies the address in your browser and only asks an outside service about a public address.
The tool drops the scheme (http://), path, port (:443), square brackets and the IPv6 zone ID (%en0)Four parts separated by dots, each between 0 and 255; 256.1.1.1 is invalidEight 16-bit groups separated by colons, the :: shortcut at most once; the tool displays the result in RFC 5952 short formIf (IP AND mask) = block address, the address sits in that block; example: 172.20.5.4 AND 255.240.0.0 = 172.16.0.0, so it falls inside 172.16.0.0/12. When several blocks match, the longest prefix wins2^(32 - prefix) for IPv4, 2^(128 - prefix) for IPv6; example: /16 = 2^16 = 65,536 addressesFirst ipwho.is, then ipapi.co if there is no answer, then ipinfo.io; each service gets a 5 second timeoutYour browser's language data turns the country code into a country name. The tool also calculates local time from the time zone ID (IANA tz). Cities can differ between services, but country and ASN usually stay the same.
Example inputs and what the tool shows
The rows show the tool's parsing and classification rules; for public addresses the location rows depend on the service's database.
| Input | Address the tool reads | Badge | Result |
|---|---|---|---|
| 8.8.8.8 | 8.8.8.8 | Public IPv4 | Outside lookup; AS15169, Google LLC, United States (US) |
| [2001:4860:4860::8888]:443 | 2001:4860:4860::8888 | Public IPv6 | The tool drops brackets and port; AS15169, Google LLC |
| 192.168.1.10 | 192.168.1.10 | Internal address | No lookup; 192.168.0.0/16, RFC 1918, 65,536 addresses |
| 100.72.14.3 | 100.72.14.3 | Internal address | No lookup; CGNAT, 100.64.0.0/10, RFC 6598, 4,194,304 addresses |
| 2001:0db8:0000:0000:0000:0000:0000:0001 | 2001:db8::1 | Reserved address | No lookup; documentation, 2001:db8::/32, RFC 3849, 2⁹⁶ addresses |
| fe80::1%en0 | fe80::1 | Internal address | No lookup; link-local, fe80::/10, RFC 4291, 2¹¹⁸ addresses |
| example.com | none | Lookup failed | Domain name notice with a link to DNS Lookup |
| 256.10.1.1 | none | Lookup failed | Notice asking for a valid IPv4 or IPv6 address |
ASN and country in the first two rows come from the service at query time; the city can vary from service to service. The tool produces every other row in your browser without any outside request.
Private and reserved IP ranges
The tool recognises these blocks in your browser, skips the outside lookup and turns the badge yellow.
| Range | Name | Standard | Addresses | In the tool |
|---|---|---|---|---|
| 10.0.0.0/8 | Private network | RFC 1918 | 16,777,216 | Internal address |
| 172.16.0.0/12 | Private network | RFC 1918 | 1,048,576 | Internal address |
| 192.168.0.0/16 | Private network | RFC 1918 | 65,536 | Internal address |
| 100.64.0.0/10 | Shared address space (CGNAT) | RFC 6598 | 4,194,304 | Internal address |
| 127.0.0.0/8 | Loopback | RFC 1122 | 16,777,216 | Internal address |
| 169.254.0.0/16 | Link-local | RFC 3927 | 65,536 | Internal address |
| 192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24 | Documentation | RFC 5737 | 256 (each) | Reserved address |
| 224.0.0.0/4 | Multicast | RFC 5771 | 268,435,456 | Reserved address |
| fc00::/7 | Unique local address (ULA) | RFC 4193 | 2¹²¹ | Internal address |
| fe80::/10 | Link-local | RFC 4291 | 2¹¹⁸ | Internal address |
| 2001:db8::/32 | Documentation | RFC 3849 | 2⁹⁶ | Reserved address |
Source: IANA IPv4 and IPv6 special-purpose address registries. The tool also recognises 0.0.0.0/8, 198.18.0.0/15, 240.0.0.0/4 and all IPv6 space outside 2000::/3.
What is an IP lookup and what does this tool show?
An IP lookup reads registration databases to find the country, the provider and the network (ASN) behind an IP address. I check it first whenever I need the source of an ad click, a form submission or a log request. In one query, this tool shows:
- Location: country, region, city and approximate coordinates.
- Network: ISP, organization and ASN.
- Time: time zone and the current local time there.
- Type: whether the address is public, internal or part of a reserved range.
Your browser runs the query, not our server. The tool asks ipwho.is about a public address first; if it gets no answer, ipapi.co and then ipinfo.io step in. As a result, the address you look up never reaches our server. To see the details of your own connection, leave the field empty or open the What is my IP tool.
How accurate is an IP lookup location?
In short: very good at country level, variable at city level. MaxMind, a geolocation database provider, puts country-level accuracy generally above 99 percent and city-level accuracy between 20 and 75 percent. In other words, the city in the result is an estimate, not the place where a person sits.
These are the most common reasons for a drift:
- Registration hub: an operator can register an IP block in the city of its head office.
- Mobile networks: according to MaxMind, mobile IPs often resolve to a broad region, and one address can move between users hundreds of kilometres apart.
- VPN and proxy: the result shows the VPN server's location, not the person's.
- Anycast: addresses like 8.8.8.8 answer from many places at once, so the location only reflects the registration.
That is also why services disagree on the city for the same IP. For example, one service may say San Jose for 8.8.8.8 while another says Mountain View; country and ASN still match. Therefore, for ad targeting or fraud checks I base decisions on country and network, never on the city.
What is the difference between a private and a public IP?
Every address that routes on the internet is unique and belongs to an operator; we call it a public IP. Your router at home, however, hands out private addresses such as 192.168.1.x to your devices. RFC 1918 sets aside three blocks for this: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Millions of homes reuse the same addresses, so they mean nothing on the internet. The router uses NAT to put them all behind one public IP.
Carriers add one more layer because IPv4 addresses ran short. The 100.64.0.0/10 block from RFC 6598 lets a carrier place many subscribers behind the same public IP, a setup known as CGNAT. If your router shows a WAN address between 100.64 and 100.127, you sit behind CGNAT too. In other words, you share your public IP with other subscribers.
The tool recognises these ranges in your browser and never sends them to an outside service. Instead, it shows the block, its standard, the first and last address and the block size. On the IPv6 side, fc00::/7 (ULA) and fe80::/10 (link-local) play the same role. If you want to know whether your connection supports IPv6, try the IPv6 test as well.
What do ASN and ISP data reveal about ad traffic?
An ASN is a network's ID number on the internet. Five regional internet registries, such as RIPE NCC and ARIN, hand out both IP blocks and ASNs. That is why an IP's ASN often shows at a glance whether traffic comes from a home or a data center.
My order for a wave of suspicious clicks in Google Ads:
- I collect the IPs from logs or form records.
- I look each one up here and check ASN and ISP. A series of clicks from one hosting network is the first red flag.
- I check Google's own filter. According to Google Ads Help, Google removes invalid clicks it detects before month end from your bill. You can see them in the Invalid clicks column of your campaign table.
- If the pattern holds, I build an IP exclusion list. You can exclude up to 500 IP addresses per campaign. An account-level list also covers Performance Max and every other campaign type.
Blocking IPs alone rarely solves the problem; measurement and campaign structure do the real work. You can read how my team and I run this analysis on the Google Ads management page.
How do you find the real visitor IP in server logs?
Behind a CDN such as Cloudflare or a load balancer, the IP in your log usually belongs to that server. When you look it up, the ASN points to the CDN's network, which is your first hint. The real address travels in a header the proxy adds:
X-Forwarded-For: a comma-separated list. The leftmost value is the client; the rightmost is the most recent proxy.CF-Connecting-IP: the visitor address that Cloudflare passes as a single value.Forwarded: the standardized header for the same job; less common in practice.
Be careful here: MDN warns that any value your trusted proxy did not add may be spoofed. For security decisions such as rate limits or IP blocks, use only the value your own proxy writes. Addresses with a port (203.0.113.7:51234) or IPv6 in brackets from a log line are fine; the tool cleans them up.
If you have a domain instead of an address, find its IP with the DNS lookup first. I also describe the tools I use to read logs in my article on website traffic analysis tools.
IP lookup and GDPR: is an IP address personal data?
In most cases yes, or at least you should treat it that way. The GDPR defines personal data as any information relating to an identified or identifiable natural person. Recital 30 explicitly lists internet protocol addresses among online identifiers. An IP alone does not name anyone. However, combined with carrier records or user accounts on your site, it can make a person identifiable.
In practice that has two consequences:
- Logs and form records: mention collected IPs in your privacy notice. Define a retention period and delete them once it ends.
- Analytics: Google Analytics 4 does not log or store IP addresses. So GA4 no longer needs the IP masking setting of Universal Analytics.
This tool does not process any IP on our server. However, the public address you look up goes to the outside service that answers. Internal addresses never leave your browser at all. If you plan to analyse customer IPs in bulk, do it on your own legal basis and check current legislation for critical decisions. I collected the technical side of a compliant site in my guide on building a GDPR compliant website.
What changes between an IPv4 and an IPv6 lookup?
An IPv4 address consists of four numbers separated by dots, each between 0 and 255. IPv6, on the other hand, uses eight 16-bit groups separated by colons. You may shorten consecutive zero groups once with ::. The tool accepts both formats and displays IPv6 results in the short form that RFC 5952 recommends. For example, if you type 2001:0db8:0000:0000:0000:0000:0000:0001, the result reads 2001:db8::1.
It is also normal to see an IPv6 address when you look up your own IP. If your connection supports both protocols, the browser usually prefers IPv6. Moreover, many devices create temporary IPv6 addresses for privacy and rotate them regularly, so the address you see today may differ tomorrow.
This has a practical consequence for ads. Carriers often give a home connection not a single IPv6 address but a large block such as a /56 or a /48. Consequently, blocking one IPv6 address may not stop the next click from the same household. That is why I recommend looking at the network and the ASN, not the single address, when traffic looks suspicious.
Common IP lookup mistakes
- ✕MistakeTreating the city in the result as the visitor's real address✓Do this insteadThe city is where the IP block is registered; on mobile networks and VPNs it can be hundreds of kilometres off. Make location decisions at country and network level.
- ✕MistakeTaking the CDN or proxy IP in your server log for the visitor✓Do this insteadIf the ASN points to a CDN, read the header your own proxy adds. Never use the leftmost value of that header for security decisions without verifying it.
- ✕MistakeSearching the internet for an internal address like 192.168.x.x✓Do this insteadThese addresses repeat in every home and office and mean nothing on the internet. Press My IP to see your public address instead.
- ✕MistakeBlocking one suspicious IP and calling it done✓Do this insteadLook at clicks from the same ASN as a group. Google Ads allows 500 excluded IPs per campaign, so find the pattern first and build the list after that.
- ✕MistakeStoring a dynamic home IP as a permanent identity✓Do this insteadHome IPs change, and behind CGNAT many subscribers share one address. Do not use an IP on its own to match a person.
Frequently Asked Questions
Suspicious clicks in your ad traffic?
My team and I analyse bot traffic, click fraud and conversion loss with data. Let's make sure your Google Ads budget reaches real customers.





