How to Read an IP Address Lookup Result
An IP Lens address result answers several different questions: which organization is listed for the address range, which network was observed announcing that it can route traffic to that range, what names DNS associates with the address, how the address is categorized, and where location sources place it. A DNS name for a host or service, such as dns.google, is called a hostname. A network's announcement that a range can be reached through it is a routing announcement.
Example: How should I read 1.1.1.1?
- Open the 1.1.1.1 result. IP Lens does not show a separate address-status field on an ordinary address result. As an addressing fact, 1.1.1.1 is public rather than private, loopback, documentation, or another special-purpose address. A search for a special-purpose address opens the result for its special-purpose block.
- If the Registered Owner section appears, read it next. In this example, APNIC is the responsible registry and the larger allocation is associated with APNIC Research and Development. The 1.1.1.0/24 prefix is carved from that allocation. None of this identifies the current user.
- If a Network section appears, compare its observed origin with the Registered Owner. The routing information currently available in IP Lens can associate the range with Cloudflare's AS13335. That illustrates why registration and observed routing can differ; it is not a complete traffic path.
- Finish with supporting context. When present, the DNS Pointer (PTR) name one.one.one.one and the visible Public DNS and Anycast tags describe compatible roles; the exact fields can change as the available data changes. Location remains an estimate: an anycast address can be served from many sites, so a country, city, or coordinate does not identify the Cloudflare site that handled a request.
Why are some fields missing?
IP Lens only shows sections and fields for which usable data is available. A section can be absent because no record matched or because a lookup supplied no usable value. The incomplete-data banner appears when the lookup reports a failure or timeout, but it is not an exhaustive source-status report: a section can be missing without that banner. Treat an absent section as unknown, not as a negative finding.
What do the network signals mean?
Tags
Tags summarize a known use or role for the address or its prefix, such as Hosting, Content Delivery Network, Public Proxy, or Public DNS. A content delivery network (CDN) serves content through distributed servers; a public proxy relays requests for other clients. They do not identify the person using the address or prove intent. See IP address tags for the public vocabulary.
Tor Exit Node
This note means the address is listed as a Tor exit node. A service sees the exit address, not the original client, so the exit operator did not necessarily initiate the traffic and Tor use alone does not prove abuse.
Reverse Hostnames
These are previously collected PTR observations for the address. Opening a result does not perform a new DNS query or connect to the queried address. They can suggest a provider, service, or network role, but they are operator-controlled labels rather than proof of ownership or location. IP Lens separates older names from the latest result. "Latest" means the newest DNS check available in IP Lens that returned hostname records or confirmed that there were none (a conclusive observation). It does not necessarily describe the address's current DNS state. IP Lens keeps at most 100 reverse DNS observations, ordered by the most recent last-seen date, so older history can be omitted. NXDOMAIN means the queried reverse name did not exist. NODATA means the name existed but the response had no PTR answer. More than one hostname can be present. See Reverse DNS.
What does Registered Owner mean?
This section comes from public registration data. Although the result page is labeled Registered Owner, read it as the registered holder, registrant, or organization listed in the source record. It does not establish legal ownership and does not necessarily name the organization routing the traffic or the person using one address.
IP Prefix
The most specific registered block returned for the address. The range in parentheses shows its first and last addresses.
Delegated Prefix
A usually broader block that a registry delegated to an organization. It can contain the more specific IP Prefix, so facts about it cover a larger set of addresses. See IP ranges and CIDR.
Registry
The Regional Internet Registry responsible for the registration record, such as ARIN, RIPE NCC, APNIC, LACNIC, or AFRINIC. See IP registries.
What does the Owner field mean?
The organization named in the registration record. Compare it with the Autonomous System section because another network may route the address space.
Handle
The registry's identifier for the registered holder. Some records provide only a handle, rather than a descriptive organization name.
Country
The country code published in the registration record. It describes the registration, not the physical location of the queried IP or its user.
Address
The registrant's published contact address. It is not the physical location of the queried IP, a server, or an end user.
Which network announces the route?
Networks exchange routing announcements using Border Gateway Protocol (BGP), a set of rules for telling other networks which address ranges they can reach. This section shows the announcing networks (origin networks) in the routing information currently available in IP Lens. More than one section can appear when the source associates a prefix with multiple origin networks. This is an observation from one updated dataset, not a live view from every network and not the complete path taken by your traffic. Routing and registration answer different questions; see IP ownership and ASNs.
Autonomous System Number (ASN)
The identifier of the network that the source observed as the route origin. Follow it to open the corresponding Autonomous System result page.
Description
A human-readable name or description supplied with the Autonomous System metadata.
Handle
A short registry or source identifier for the Autonomous System. It is a label, not proof that the named organization owns every routed address.
Country
The country attached to the Autonomous System metadata. A network can operate globally, so this is not the location of every address, router, or user.
Category
A broad source-provided classification of the network, such as an Internet Service Provider, hosting provider, business, or education network. Treat it as descriptive metadata.
CIDR
The address range (prefix) in the routing information that matched the queried address. The range in parentheses is the span covered by that source record. The data may combine several ranges into a larger one (aggregation), so the row may not match a single BGP announcement seen at the moment of your event.
Why are there several location sources?
IP Lens shows maintained sources side by side because IP geolocation is an estimate. Agreement can support a coarser conclusion, while disagreement is a warning to reduce confidence. Providers can use some of the same registry, routing, geofeed, or correction signals, so agreement does not necessarily mean independent confirmation and is never proof of a person's location. See IP location.
IPinfo.io Lite
A maintained source of country and continent data. IP Lens does not repeat IPinfo.io Lite's Autonomous System metadata in this table; use the Autonomous System section instead.
GeoLite City
A maintained city database that can provide country, region, city, and coordinates.
DB-IP City Lite
A maintained city database that can provide country, region, city, and coordinates for comparison with the other sources.
IP2Location Lite
IP Lens uses the IP2Location Lite database for IP geolocation. It can provide country, region, city, and coordinates for comparison with the other sources.
Geofeed
Location data asserted by a network operator for prefixes it manages. It can be a useful hint, but it is not measured proof and can be broad, stale, or incorrect. Consumers still need to verify the publisher's authority and the data's accuracy.
What do the location fields mean?
The comparison has Source, Country, and City or region columns. Coordinates, when available, appear beneath the locality in the City or region cell. A dash means that the source did not provide a value.
Source
The named location dataset that supplied the row. Sources can disagree or reuse some of the same upstream signals, so compare their estimates without treating agreement as proof.
Country
The source's estimate of the country where the address is used. It is different from an Autonomous System country. If IPinfo.io Lite has no country result, IP Lens shows its continent result instead.
City or region
Approximate administrative-area and city labels. Prefer the coarsest level supported by the available evidence, and remember that providers may share some upstream signals.
Coordinates
A representative point for the estimated area, often a city or provider location. IP Lens places it below the locality in the City or region cell. It is not the measured position of a device or person.
How broad should a firewall rule be?
The prefixes on a result page show how much address space surrounds the queried address: the registered IP Prefix and Delegated Prefix, and the CIDR range in the routing information. They describe different scopes; they are not automatic recommendations to block those scopes.
Start with the narrowest rule supported by your evidence and broaden it only when the behavior spans a larger range. See IP ranges and CIDR for scope and overblocking guidance.