Yes. Tags can describe compatible aspects of one endpoint. The
9.9.9.9 result can show
Public DNS for its service role and
Anycast for how that service is delivered.
Multiple tags are not multiple verdicts. A tag can also come from a containing range, so check the real
client IP, event time, and observed behavior before acting.
Treat tags as clues, not legal or operational proof. Read them alongside the Registered Owner, observed
origin Autonomous System Number (ASN), reverse DNS,
and location sections.
Bot, hosting, VPN, proxy, Tor, scanner, and Bogon tags can identify traffic that deserves a closer look.
They do not prove that a request is abusive, and one tag should not automatically block an entire range.
For crawler traffic, follow the operator checks in
Search bot verification.
Check the event timestamp, request and account behavior, source port where relevant, real client IP,
registration context, and whether the address was shared or reassigned. Prefer narrow, reversible controls
such as a challenge or short rate limit over a permanent block based only on a tag.
How do I report a correction?
Record the result URL, address, tag, event time, and evidence showing the address or range's current role.
Then send the request through the IP Lens
Contact page.
A correction may require verification and may not appear immediately.