Skip to main content

IP Reputation Report

One report covering an IP address: location, network, reverse hostname, threat signals and the abuse contact — in a single lookup.

Enter a public IP address to see location, network and risk signals together.

This tool queries an external service to answer your request. Only the value you enter — such as a domain or IP address — is sent. Your other data stays on your device.

This tool reads public records — DNS, WHOIS and certificate data that registries and servers publish openly. It sends nothing to the host you enter and changes nothing there. Use it on infrastructure you own or are authorised to look into.

About the IP Reputation Report

Everything about one IP address in a single report: where it is, which network runs it, what it resolves back to, whether it carries any risk signals, and who to contact about abuse. It is the page to use when you have an address in front of you and you do not yet know which question you need to ask about it.

This exists alongside our focused IP tools rather than instead of them, and the difference is worth knowing. Our IP Address Lookup gives a clean location and network summary. The VPN & Proxy Detector answers one question thoroughly, with each signal weighted. IP WHOIS returns the registry record and the abuse contact in full. Each of those is one lookup and one charge. This report combines all three areas in a single lookup, which makes it the efficient choice when you genuinely want the whole picture — and the wasteful one when you only wanted the country.

The reverse hostname is the field that earns its place here and appears nowhere else. It is what the address resolves back to, and it is often the single most informative thing on the page. A hostname ending in a cloud provider's domain tells you immediately that you are looking at a server. One ending in a residential ISP's domain, frequently with the address embedded in it, tells you it is a home connection. Sometimes it names the machine's purpose outright — scanners and crawlers are often politely self-identifying if you look.

Risk signals are listed individually and weighted, not compressed into a verdict. A commercial VPN flag and a known-attacker flag are both true statements and are nothing like equivalent evidence, and a report that averaged them into one number would be hiding the only part that matters. Read the signals; the score is a summary of them, not a substitute for them.

How to use the IP Reputation Report

  1. Enter the address

    Type any public IPv4 or IPv6 address. Ports and CIDR suffixes copied from logs are removed automatically.

  2. Run the report

    Complete the verification check and press Run report. All the sections come from one lookup rather than several.

  3. Read the reverse hostname first

    It is often the fastest answer on the page — a cloud provider domain means a server, a residential ISP domain means a home connection, and some hosts name their own purpose.

  4. Weigh the signals individually

    Known attacker and residential proxy are strong. Commercial VPN and private relay are weak on their own, because ordinary people use both daily.

Frequently asked questions

When should I use this instead of your other IP tools?

Use this when you have an address and do not yet know what you need to know about it — it returns location, network, reverse hostname, risk signals and the abuse contact in one lookup. Use the focused tools when you have a specific question: IP Address Lookup for where it is, VPN & Proxy Detector for whether it is anonymised with each signal explained, IP WHOIS for the full registry record and abuse contacts. Getting all three separately costs three lookups; this costs one.

What is a reverse hostname and why is it useful?

It is the name an IP address resolves back to, set by whoever controls the address block. It is frequently the most informative field in the whole report. A hostname on a cloud provider's domain means you are looking at a server; one on a residential ISP's domain, often with the IP embedded in it, means a home connection. Crawlers and scanners commonly identify themselves in it too. An empty value means no reverse record is published, which is itself mildly notable.

Is a high threat score enough reason to block an address?

Not on its own, and the report deliberately shows you why. The score summarises several very different signals, and an address flagged only as a cloud provider can land uncomfortably close to one flagged as a known attacker. Read which signals are actually raised. Combined with behaviour — a login from a country the account has never used, a burst of failed attempts — the picture is much stronger than any single number.

The report says my own address has signals. Should I be worried?

Usually not. The commonest reasons are entirely benign: you are on a VPN, you are using Apple Private Relay, or your ISP has recycled an address block that used to host something else. If you see "known attacker" or "spam source" on your home connection and you are not using a VPN, it is worth checking your network for a compromised device, and worth asking your ISP whether the address was recently reassigned.

How current is the risk data?

The lookup is live, so you get whatever the provider knows at the moment you ask. The underlying reputation feeds update continuously, but they inevitably lag reality in both directions: a freshly compromised host may not be listed yet, and an address that was cleaned up weeks ago can stay listed for a while. Treat the absence of a signal as weaker evidence than the presence of one.

Do you keep the addresses I check?

No. The address is sent to the lookup service and is not written to our database or our logs. We count that a report was run so we know the tool is used, with no record of which address, who asked, or what was returned.