IP intelligence

IP address tags

IP Lens uses tags to describe network roles, services, and observed risk indicators. Tags provide context about an address or network. intent, or behavior.

Threats

Malicious activity and serious security risk signals.

Privacy and proxying

Infrastructure that relays, proxies, or obscures network traffic.

Bots and crawlers

Automated agents, crawlers, and fetchers that retrieve or interact with online content.

Scanners

Infrastructure that probes internet hosts, ports, and services for research, measurement, or other purposes.

Lists and interventions

External restrictions, security lists, and defensive interventions.

Domain infrastructure

Infrastructure associated with how domains are operated or used.

Address and routing

Address-space and routing characteristics.

Services

Recognized infrastructure roles and network services.

Network and hosting

Network placement and hosting characteristics.

Content and use

The content, service, or activity associated with a target.

Can one IP address have several tags?

Yes. Tags can describe compatible aspects of one endpoint. The 9.9.9.9 result can show Public DNS for its service role and Anycast for how that service is delivered.

Multiple tags are not multiple verdicts. A tag can also come from a containing range, so check the real client IP, event time, and observed behavior before acting.

How should I use IP address tags?

Treat tags as clues, not legal or operational proof. Read them alongside the Registered Owner, observed origin Autonomous System Number (ASN), reverse DNS, and location sections.

Bot, hosting, VPN, proxy, Tor, scanner, and Bogon tags can identify traffic that deserves a closer look. They do not prove that a request is abusive, and one tag should not automatically block an entire range. For crawler traffic, follow the operator checks in Search bot verification.

What should I verify before acting on a tag?

Check the event timestamp, request and account behavior, source port where relevant, real client IP, registration context, and whether the address was shared or reassigned. Prefer narrow, reversible controls such as a challenge or short rate limit over a permanent block based only on a tag.

How do I report a correction?

Record the result URL, address, tag, event time, and evidence showing the address or range's current role. Then send the request through the IP Lens Contact page. A correction may require verification and may not appear immediately.