Bulk IP Lookup

Paste a list of IP addresses and get the country, city, provider, network number and connection type for each one — in a single lookup. Useful for reading server logs, checking where sign-ups came from, or working out how much of your traffic is datacentre rather than human.

0 / 50

IPv4 and IPv6 both work. Up to 50 addresses per lookup.

What a Bulk IP Lookup Is — and Isn’t

A bulk IP lookup takes a list of addresses and returns, for each one, who the address belongs to, roughly where it is, and what kind of connection it sits on. It reads published registration and geolocation data about each address.

It is not a scan. Nothing is sent to the addresses themselves — no pings, no port probes — so the machines behind them never know you looked. Finding out which ports are open on a machine is a different job, and our port scanner only checks your own connection, deliberately.


How to Use It

  1. Paste the addresses. One per line, or separated by commas, semicolons or spaces. A column copied straight out of a spreadsheet works as it is.
  2. Don’t bother cleaning the list. Duplicates are removed automatically, and anything that isn’t a valid IPv4 or IPv6 address is skipped rather than failing the whole batch.
  3. Keep it to 50. The first 50 unique entries are looked up; run another batch for the rest.
  4. Click Look Up All, then Export CSV if you want the results in a spreadsheet.

Pulling the Addresses Out of a Log File

Most people arrive here with a log, not a list. In the standard web server log format the visitor’s address is the first field on every line, so these one-liners print the 50 busiest addresses, one per line, ready to paste.

Linux or macOS:

awk '{print $1}' access.log | sort | uniq -c | sort -rn | head -50 | awk '{print $2}'

Windows PowerShell:

Get-Content access.log | ForEach-Object { ($_ -split ' ')[0] } | Group-Object | Sort-Object Count -Descending | Select-Object -First 50 -ExpandProperty Name

Any other text — a firewall export, email headers, a pasted report — can be mined for IPv4 addresses with grep -oE '([0-9]{1,3}\.){3}[0-9]{1,3}' file.txt | sort -u. It will also catch the odd version number that looks like an address; the tool simply skips anything that isn’t valid.

One catch: if your site sits behind Cloudflare, a load balancer or another reverse proxy, the first field is the proxy’s address, and every row will come back as the same provider. The real visitor address is in a header such as X-Forwarded-For or CF-Connecting-IP, which your server has to be told to log.


What Each Column Means

Column What it is How far to trust it
Type The kind of connection — see the next section Good for ranges on a known list; a brand-new server can be missed
Country Where the range is registered or observed Usually right
City / region The database’s best guess for the range A hint only — often the provider’s hub, not the user’s town
Provider The ISP or hosting company that operates the range. The CSV adds org, the organisation the block is assigned to — for 8.8.8.8 the provider is Google LLC and the org is Google Public DNS Reliable
Network The autonomous system number (ASN) the address is routed through, such as AS15169 for Google. Every address in one ASN is run by the same operator Reliable — the best column for spotting clusters

What the Type Column Means

The connection type is the most useful column here, and the one most lookup tools get wrong. It comes from lists of known hosting, proxy and mobile ranges rather than a guess based on the provider’s name — which matters, because plenty of datacentre ranges belong to companies whose names sound like ordinary businesses.

Type What it tells you
Residential A consumer or business broadband line with no hosting, proxy or mobile flag — most likely a real person
Data centre A hosting or cloud range. Servers, bots, scrapers and APIs live here — rarely a human browsing
Data centre + Proxy-listed A hosting range that also appears on proxy and VPN lists. Commercial VPN exits look like this — but so do some public services: Google’s 8.8.8.8 DNS resolver carries the proxy flag too
VPN / Proxy A proxy-listed address that is not in a hosting range — often a residential proxy, where traffic is routed through someone’s home connection. The one worth a second look
Mobile A carrier network, usually shared by many subscribers behind CGNAT

What People Use This For

Reading server logs. Paste the addresses hitting an endpoint and the type column separates real visitors from scrapers immediately — a page of datacentre addresses is automated traffic, whatever the user agent claims.

Checking sign-ups or orders. A batch of accounts created from the same datacentre range, or from VPN exits in a country you don’t serve, is a pattern worth knowing about before you ship anything.

Investigating spam or abuse. Run the addresses from your mail logs or comment queue and look at the provider and network number — abuse usually clusters in a handful of ranges. Pair it with the IP reputation checker to see whether they’re already on a blacklist.

⚠️ Why the Location Is Sometimes Absurd

Look up 1.1.1.1 and you may be told Australia. The address is Cloudflare’s, registered through the Asia-Pacific registry, but the server answering you is almost certainly in your own city — it’s an anycast address, meaning the same number is announced from dozens of locations at once and you reach the nearest one. When we checked in September 2026, its IPv6 twin, 2606:4700:4700::1111, came back as Montreal: same service, same operator, a different answer.

Geolocation databases store one location per range, so anycast addresses, satellite links and recently reassigned ranges all produce results that look wrong and are. Treat the location column as a hint and the provider and network columns as the reliable parts. Background: how IP geolocation actually works.

Where the Data Comes From

Each batch goes from our server to ip-api.com in a single request, and the answers are passed straight back to your browser. The connection-type labels are built from that service’s hosting, proxy and mobile flags. Those are lists of known ranges, not a live test of the address — so a VPN server switched on last week, or a range recently sold to a new owner, can be labelled by what it used to be.


Bulk Lookup, WHOIS or Reputation Check?

Your question The tool for it
Where are these addresses, who runs them, and are they home lines or servers? Bulk IP Lookup (this page)
Who is this range formally registered to, and since when? WHOIS lookup
Is this address on spam or abuse blacklists? IP reputation checker
What can websites see about my address? What Is My IP

Frequently Asked Questions

How many addresses can I check at once?

Fifty per lookup. Run several batches if you have more — there’s no signup. If the lookup service is busy you’ll be asked to wait a minute and try again.

Does it work with IPv6?

Yes. Mix IPv4 and IPv6 in the same batch if you like; both are validated before anything is sent.

Does looking up an address alert its owner?

No. The lookup asks a database about the address; nothing is sent to the address itself, so there is nothing for its owner to see.

Can it tell me who is behind an IP address?

No. It names the provider, not the subscriber. Only the provider can match an address to a customer account, and it normally does that only for a court order or a police request — see can police track you by your IP address.

Can I get the results as a file?

Yes — “Export CSV” downloads every column, including the region, organisation and proxy-listed flag that aren’t shown in the table.

Do you store the addresses I paste?

No. They’re validated, looked up and returned. Nothing is written to a log or a database on our side.

Why does a row say “private range” or “reserved range”?

Those addresses don’t exist on the public internet, so there’s nothing to look up. 192.168.x.x and 10.x.x.x are private ranges used inside home and office networks; 100.64.x.x is reserved for carriers sharing one public address among many customers. See public vs private addresses.

Why does 8.8.8.8 say “Proxy-listed”?

Because the range appears on the proxy lists the labels are built from, even though it’s Google’s public DNS resolver. That’s why the tag sits beside “Data centre” instead of replacing it: it tells you the range is listed, not that someone is hiding behind it.

Is “Data centre” the same as “bot”?

No, but it’s a strong hint. Real people occasionally browse from cloud desktops or corporate VPNs. It means the address isn’t a home line, not that the traffic is hostile.


Related Tools and Reading

Scroll to Top