IP Address Lookup: ISP, ASN, Location & Cloud Provider
Look up one IPv4 or IPv6 address for its ISP, ASN, organization, approximate location, time zone, and reverse DNS—or check an entire list against cloud, hosting, CDN, service, and crawler ranges.
Your IP addresses
What can I paste?
One address per line, comma-separated lists, or text with addresses. IPv4-mapped IPv6 addresses are grouped with their IPv4 equivalent. IPs are extracted as written; hostnames and CIDR ranges are not expanded.
Supports up to 200,000 lines and 20,000 unique IPs. You can also reopen an exported Bug Days report JSON file here.
Open an address for optional ISP, ASN, approximate geolocation, and reverse-DNS details. Only that selected IP is checked with IPWhois.io and Cloudflare DNS; the rest of your list is not sent to those services.
Every address has more to tell.
Identify the network, provider, approximate location, reverse DNS, and published cloud or crawler ranges. Start with one IP, paste a list, or try the example.
No account or API key needed. Bulk matching sends only extracted IPs; optional live enrichment checks one selected address.
Network mix
Address breakdown
IPv4 + IPv6Address explorer
| IP address | Network / classification | Region / evidence | Count | Details |
|---|
Take the findings with you.
Sources, coverage & parsing details
Matches describe published IP ranges, not the identity or intent of a visitor. Live geolocation is an approximate network location—not a home, street address, or proof of where a person is. Cloudflare ranges can identify an intermediary; use correctly configured client-IP logs to investigate the original visitor.
When you inspect one public IP, your browser requests live network context from IPWhois.io and a PTR record from Cloudflare DNS. Results are reused for the current page session and are not written to the IP range database.
Find the ISP, ASN, location, and reverse DNS
Look up one public IP to see its network organization, ISP, ASN, domain, approximate country and city, time zone, coordinates, and PTR hostname. Learn how those clues differ in our guide to IP ownership, ASN, geolocation, and reverse DNS.
Check cloud, datacenter, VPS, and crawler IPs in bulk
Compare a complete list with AWS, Azure, GCP, Oracle, DigitalOcean, Hetzner, OVHcloud, Hostinger, CDN, corporate proxy (Zscaler), privacy relay (iCloud Private Relay, Tor), satellite ISP (Starlink), service, and published crawler ranges. Inspect the matching CIDR, evidence method, service, and provider region where available.
Share or export useful network evidence
Live details and published-range evidence stay distinct. Share one selected IP or a filtered report, or export CSV, Excel, JSON, and printable PDF. For request behavior, open the access-log analyzer and follow the hosting-IP investigation guide.
IP address, ISP, ASN, location, and cloud lookup questions
What information does an IP address lookup show?
For a selected public IPv4 or IPv6 address, Bug Days can show the ASN, network organization, ISP, network domain, approximate country, region and city, time zone, coordinates, reverse DNS hostname, and any matching cloud, hosting, CDN, service, or crawler ranges.
Can an IP lookup find an exact physical address?
No. IP geolocation estimates the network location and may identify an ISP gateway, datacenter, VPN endpoint, or regional allocation. It cannot reveal a home, street address, exact device location, or the identity of the person using an IP.
How do I check whether an IP belongs to a cloud or hosting provider?
Paste one IPv4 or IPv6 address—or a complete list—into the lookup. Bug Days checks official cloud feeds and current BGP-origin prefixes, then shows the provider, matching CIDR, evidence, service, and any published region.
Which cloud, VPS, CDN, and crawler networks are checked?
Coverage includes AWS, Azure, Google Cloud, Oracle, DigitalOcean, Hetzner, OVHcloud, Vultr, Linode, Hostinger, Contabo, Scaleway, UpCloud, IONOS, Leaseweb, Rackspace, Cloudflare, Fastly, GitHub, Zscaler corporate proxy egress nodes, iCloud Private Relay exits, Tor exit nodes, Starlink, Google and Bing crawlers, plus published OpenAI crawler and user-triggered ranges.
What does a Zscaler match on an IP address mean?
Zscaler is a corporate secure web gateway, so its Cloud Enforcement Node ranges are the addresses an employer’s traffic leaves from after inspection. A match means the request reached you through that proxy, and the real client sits behind it: the address identifies the company’s egress node and its city, not an individual user or a datacenter bot. Bug Days checks the published ranges for every Zscaler cloud (zscaler.net, zscalerone.net, zscalertwo.net, zscalerthree.net, zscloud.net, zscalerten.net, zscalerbeta.net, and zscalergov.net), because each customer is assigned to one of them.
Why do some visitors show up as iCloud Private Relay, Tor, or Starlink?
These are addresses that sit in front of the real client. An iCloud Private Relay match means an Apple device browsing through Apple’s relay, so the address reflects the relay exit country rather than the person. A Tor exit node means the request left the Tor network at that address, and the origin is unknowable by design. Starlink is a satellite ISP using carrier-grade NAT, so many subscribers share an address. None of these is a datacenter, and none of them on its own indicates abuse, so treat them as context for request behavior rather than as a reason to block.
Can a datacenter IP match prove that traffic is a bot?
No. A cloud, hosting, or VPS match identifies network infrastructure, not intent. Combine it with request volume, paths, timing, status codes, authentication context, and crawler verification before blocking traffic.
Are the hosting provider IP ranges current?
Official feeds are labeled separately from hosting ranges derived from current BGP origins. Every report includes the dataset timestamp and the evidence used for each match.
What IP data is sent to external lookup services?
Bulk provider matching sends normalized IP addresses only to Bug Days. When you open one public address, that selected IP is checked with IPWhois.io for live ASN, ISP and approximate geolocation and with Cloudflare DNS for its PTR record. Raw logs, paths, headers, query strings and user agents are not sent.