Tools

IP Lookup (IP Location & ISP)

Look up any IP address: country, city, internet service provider (ISP), ASN and time zone. Leave the field empty to look up your own IP. The query runs from your browser; nothing is stored on our server.

IPv4 and IPv6 lookupCountry, city, ISP, ASN and time zone
Runs in your browser; nothing is stored on our server.
Leave it empty to look up your own IP. You can paste an address with a port (1.2.3.4:443) or an IPv6 address in brackets as it is. Quick lookup
Internal ranges
  • 10.0.0.0/8Private
  • 172.16.0.0/12Private
  • 192.168.0.0/16Private
  • 100.64.0.0/10CGNAT
  • 127.0.0.0/8Loopback
  • fc00::/7IPv6 ULA

The location is where the IP block is registered, not where a person is: reliable at country level, approximate at city level. Internal addresses are never sent to an outside service; the tool explains them itself.

Result

ResultReady

Type an IP address, or leave the field empty and press Look up. Country, city, ISP, ASN and time zone appear here.

Written by
  • Digital Marketing Expert
  • Google Partner
  • Full Stack Developer
Last updated
Based on
5 sources

How to use the IP Lookup (IP Location & ISP)

  1. Type or paste the IP address

    Enter an IPv4 address such as 8.8.8.8 or an IPv6 address such as 2001:4860:4860::8888. You can also paste an address with a port (1.2.3.4:443) or a bracketed IPv6 address from a log line. The tool strips the extras itself.

  2. Press Look up

    The Enter key does the same. With an empty field, the tool looks up your own public IP. The Quick lookup buttons try Google DNS, Cloudflare DNS or an IPv6 example in one click.

  3. Check the badge

    A green Public IPv4 or Public IPv6 badge means the address routes on the internet. A yellow badge points to an internal or reserved range; in that case the tool never contacts an outside service.

  4. Read the rows

    Country, region and city give the location, while ISP and ASN name the network owner. The time zone row also shows the current local time. When coordinates exist, View on map opens the approximate point on OpenStreetMap.

  5. Share the result

    Copy result puts every row on your clipboard. Copy link creates an address that reopens the same lookup, so you can send it to your team together with your log notes.

How does the tool evaluate an IP address?

The tool does not calculate anything. It first parses and classifies the address in your browser and only asks an outside service about a public address.

Clean upThe tool drops the scheme (http://), path, port (:443), square brackets and the IPv6 zone ID (%en0)
IPv4 ruleFour parts separated by dots, each between 0 and 255; 256.1.1.1 is invalid
IPv6 ruleEight 16-bit groups separated by colons, the :: shortcut at most once; the tool displays the result in RFC 5952 short form
Range checkIf (IP AND mask) = block address, the address sits in that block; example: 172.20.5.4 AND 255.240.0.0 = 172.16.0.0, so it falls inside 172.16.0.0/12. When several blocks match, the longest prefix wins
Block size2^(32 - prefix) for IPv4, 2^(128 - prefix) for IPv6; example: /16 = 2^16 = 65,536 addresses
Lookup orderFirst ipwho.is, then ipapi.co if there is no answer, then ipinfo.io; each service gets a 5 second timeout

Your browser's language data turns the country code into a country name. The tool also calculates local time from the time zone ID (IANA tz). Cities can differ between services, but country and ASN usually stay the same.

Example inputs and what the tool shows

The rows show the tool's parsing and classification rules; for public addresses the location rows depend on the service's database.

InputAddress the tool readsBadgeResult
8.8.8.88.8.8.8Public IPv4Outside lookup; AS15169, Google LLC, United States (US)
[2001:4860:4860::8888]:4432001:4860:4860::8888Public IPv6The tool drops brackets and port; AS15169, Google LLC
192.168.1.10192.168.1.10Internal addressNo lookup; 192.168.0.0/16, RFC 1918, 65,536 addresses
100.72.14.3100.72.14.3Internal addressNo lookup; CGNAT, 100.64.0.0/10, RFC 6598, 4,194,304 addresses
2001:0db8:0000:0000:0000:0000:0000:00012001:db8::1Reserved addressNo lookup; documentation, 2001:db8::/32, RFC 3849, 2⁹⁶ addresses
fe80::1%en0fe80::1Internal addressNo lookup; link-local, fe80::/10, RFC 4291, 2¹¹⁸ addresses
example.comnoneLookup failedDomain name notice with a link to DNS Lookup
256.10.1.1noneLookup failedNotice asking for a valid IPv4 or IPv6 address

ASN and country in the first two rows come from the service at query time; the city can vary from service to service. The tool produces every other row in your browser without any outside request.

Private and reserved IP ranges

The tool recognises these blocks in your browser, skips the outside lookup and turns the badge yellow.

RangeNameStandardAddressesIn the tool
10.0.0.0/8Private networkRFC 191816,777,216Internal address
172.16.0.0/12Private networkRFC 19181,048,576Internal address
192.168.0.0/16Private networkRFC 191865,536Internal address
100.64.0.0/10Shared address space (CGNAT)RFC 65984,194,304Internal address
127.0.0.0/8LoopbackRFC 112216,777,216Internal address
169.254.0.0/16Link-localRFC 392765,536Internal address
192.0.2.0/24, 198.51.100.0/24, 203.0.113.0/24DocumentationRFC 5737256 (each)Reserved address
224.0.0.0/4MulticastRFC 5771268,435,456Reserved address
fc00::/7Unique local address (ULA)RFC 41932¹²¹Internal address
fe80::/10Link-localRFC 42912¹¹⁸Internal address
2001:db8::/32DocumentationRFC 38492⁹⁶Reserved address

Source: IANA IPv4 and IPv6 special-purpose address registries. The tool also recognises 0.0.0.0/8, 198.18.0.0/15, 240.0.0.0/4 and all IPv6 space outside 2000::/3.

What is an IP lookup and what does this tool show?

An IP lookup reads registration databases to find the country, the provider and the network (ASN) behind an IP address. I check it first whenever I need the source of an ad click, a form submission or a log request. In one query, this tool shows:

  • Location: country, region, city and approximate coordinates.
  • Network: ISP, organization and ASN.
  • Time: time zone and the current local time there.
  • Type: whether the address is public, internal or part of a reserved range.

Your browser runs the query, not our server. The tool asks ipwho.is about a public address first; if it gets no answer, ipapi.co and then ipinfo.io step in. As a result, the address you look up never reaches our server. To see the details of your own connection, leave the field empty or open the What is my IP tool.

How accurate is an IP lookup location?

In short: very good at country level, variable at city level. MaxMind, a geolocation database provider, puts country-level accuracy generally above 99 percent and city-level accuracy between 20 and 75 percent. In other words, the city in the result is an estimate, not the place where a person sits.

These are the most common reasons for a drift:

  • Registration hub: an operator can register an IP block in the city of its head office.
  • Mobile networks: according to MaxMind, mobile IPs often resolve to a broad region, and one address can move between users hundreds of kilometres apart.
  • VPN and proxy: the result shows the VPN server's location, not the person's.
  • Anycast: addresses like 8.8.8.8 answer from many places at once, so the location only reflects the registration.

That is also why services disagree on the city for the same IP. For example, one service may say San Jose for 8.8.8.8 while another says Mountain View; country and ASN still match. Therefore, for ad targeting or fraud checks I base decisions on country and network, never on the city.

What is the difference between a private and a public IP?

Every address that routes on the internet is unique and belongs to an operator; we call it a public IP. Your router at home, however, hands out private addresses such as 192.168.1.x to your devices. RFC 1918 sets aside three blocks for this: 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. Millions of homes reuse the same addresses, so they mean nothing on the internet. The router uses NAT to put them all behind one public IP.

Carriers add one more layer because IPv4 addresses ran short. The 100.64.0.0/10 block from RFC 6598 lets a carrier place many subscribers behind the same public IP, a setup known as CGNAT. If your router shows a WAN address between 100.64 and 100.127, you sit behind CGNAT too. In other words, you share your public IP with other subscribers.

The tool recognises these ranges in your browser and never sends them to an outside service. Instead, it shows the block, its standard, the first and last address and the block size. On the IPv6 side, fc00::/7 (ULA) and fe80::/10 (link-local) play the same role. If you want to know whether your connection supports IPv6, try the IPv6 test as well.

What do ASN and ISP data reveal about ad traffic?

An ASN is a network's ID number on the internet. Five regional internet registries, such as RIPE NCC and ARIN, hand out both IP blocks and ASNs. That is why an IP's ASN often shows at a glance whether traffic comes from a home or a data center.

My order for a wave of suspicious clicks in Google Ads:

  1. I collect the IPs from logs or form records.
  2. I look each one up here and check ASN and ISP. A series of clicks from one hosting network is the first red flag.
  3. I check Google's own filter. According to Google Ads Help, Google removes invalid clicks it detects before month end from your bill. You can see them in the Invalid clicks column of your campaign table.
  4. If the pattern holds, I build an IP exclusion list. You can exclude up to 500 IP addresses per campaign. An account-level list also covers Performance Max and every other campaign type.

Blocking IPs alone rarely solves the problem; measurement and campaign structure do the real work. You can read how my team and I run this analysis on the Google Ads management page.

How do you find the real visitor IP in server logs?

Behind a CDN such as Cloudflare or a load balancer, the IP in your log usually belongs to that server. When you look it up, the ASN points to the CDN's network, which is your first hint. The real address travels in a header the proxy adds:

  • X-Forwarded-For: a comma-separated list. The leftmost value is the client; the rightmost is the most recent proxy.
  • CF-Connecting-IP: the visitor address that Cloudflare passes as a single value.
  • Forwarded: the standardized header for the same job; less common in practice.

Be careful here: MDN warns that any value your trusted proxy did not add may be spoofed. For security decisions such as rate limits or IP blocks, use only the value your own proxy writes. Addresses with a port (203.0.113.7:51234) or IPv6 in brackets from a log line are fine; the tool cleans them up.

If you have a domain instead of an address, find its IP with the DNS lookup first. I also describe the tools I use to read logs in my article on website traffic analysis tools.

IP lookup and GDPR: is an IP address personal data?

In most cases yes, or at least you should treat it that way. The GDPR defines personal data as any information relating to an identified or identifiable natural person. Recital 30 explicitly lists internet protocol addresses among online identifiers. An IP alone does not name anyone. However, combined with carrier records or user accounts on your site, it can make a person identifiable.

In practice that has two consequences:

  • Logs and form records: mention collected IPs in your privacy notice. Define a retention period and delete them once it ends.
  • Analytics: Google Analytics 4 does not log or store IP addresses. So GA4 no longer needs the IP masking setting of Universal Analytics.

This tool does not process any IP on our server. However, the public address you look up goes to the outside service that answers. Internal addresses never leave your browser at all. If you plan to analyse customer IPs in bulk, do it on your own legal basis and check current legislation for critical decisions. I collected the technical side of a compliant site in my guide on building a GDPR compliant website.

What changes between an IPv4 and an IPv6 lookup?

An IPv4 address consists of four numbers separated by dots, each between 0 and 255. IPv6, on the other hand, uses eight 16-bit groups separated by colons. You may shorten consecutive zero groups once with ::. The tool accepts both formats and displays IPv6 results in the short form that RFC 5952 recommends. For example, if you type 2001:0db8:0000:0000:0000:0000:0000:0001, the result reads 2001:db8::1.

It is also normal to see an IPv6 address when you look up your own IP. If your connection supports both protocols, the browser usually prefers IPv6. Moreover, many devices create temporary IPv6 addresses for privacy and rotate them regularly, so the address you see today may differ tomorrow.

This has a practical consequence for ads. Carriers often give a home connection not a single IPv6 address but a large block such as a /56 or a /48. Consequently, blocking one IPv6 address may not stop the next click from the same household. That is why I recommend looking at the network and the ASN, not the single address, when traffic looks suspicious.

Common IP lookup mistakes

  • MistakeTreating the city in the result as the visitor's real addressDo this insteadThe city is where the IP block is registered; on mobile networks and VPNs it can be hundreds of kilometres off. Make location decisions at country and network level.
  • MistakeTaking the CDN or proxy IP in your server log for the visitorDo this insteadIf the ASN points to a CDN, read the header your own proxy adds. Never use the leftmost value of that header for security decisions without verifying it.
  • MistakeSearching the internet for an internal address like 192.168.x.xDo this insteadThese addresses repeat in every home and office and mean nothing on the internet. Press My IP to see your public address instead.
  • MistakeBlocking one suspicious IP and calling it doneDo this insteadLook at clicks from the same ASN as a group. Google Ads allows 500 excluded IPs per campaign, so find the pattern first and build the list after that.
  • MistakeStoring a dynamic home IP as a permanent identityDo this insteadHome IPs change, and behind CGNAT many subscribers share one address. Do not use an IP on its own to match a person.

Frequently Asked Questions

Suspicious clicks in your ad traffic?

My team and I analyse bot traffic, click fraud and conversion loss with data. Let's make sure your Google Ads budget reaches real customers.

Explore Google Ads Management

Related Tools

All Tools (91)
IPv6 TestCheck a site's IPv6 (AAAA) support with a clear report card.
DNS LookupSee A, AAAA, MX, TXT, NS, CNAME and SOA records instantly.
Image ResizerResize + compress photos and cut the KB; never leaves your device.
Website ValueEstimated site value from traffic and niche; transparent method, honest range.
Domain ValueDomain score from length, TLD and demand + a value range with factor breakdown.
Schema MarkupGenerate rich-result JSON-LD for Article, Product, FAQ, Local Business.