Bulk IP Lookup
Paste a list of IP addresses and get the country, city, provider, network number and connection type for each one — in a single lookup. Useful for reading server logs, checking where sign-ups came from, or working out how much of your traffic is datacentre rather than human.
IPv4 and IPv6 both work. Up to 50 addresses per lookup.
| # | IP address | Type | Country | City / region | Provider | Network |
|---|
Every site you visit can look yours up exactly like this — provider, city and connection type. A VPN replaces it with the provider’s address, which moves that visibility from your ISP to the VPN company rather than removing it. Check your own with the IP checker.
PureVPN IPVanishAffiliate links — we earn a commission if you subscribe, at no extra cost to you.
What a Bulk IP Lookup Is — and Isn’t
A bulk IP lookup takes a list of addresses and returns, for each one, who the address belongs to, roughly where it is, and what kind of connection it sits on. It reads published registration and geolocation data about each address.
It is not a scan. Nothing is sent to the addresses themselves — no pings, no port probes — so the machines behind them never know you looked. Finding out which ports are open on a machine is a different job, and our port scanner only checks your own connection, deliberately.
How to Use It
- Paste the addresses. One per line, or separated by commas, semicolons or spaces. A column copied straight out of a spreadsheet works as it is.
- Don’t bother cleaning the list. Duplicates are removed automatically, and anything that isn’t a valid IPv4 or IPv6 address is skipped rather than failing the whole batch.
- Keep it to 50. The first 50 unique entries are looked up; run another batch for the rest.
- Click Look Up All, then Export CSV if you want the results in a spreadsheet.
Pulling the Addresses Out of a Log File
Most people arrive here with a log, not a list. In the standard web server log format the visitor’s address is the first field on every line, so these one-liners print the 50 busiest addresses, one per line, ready to paste.
Linux or macOS:
awk '{print $1}' access.log | sort | uniq -c | sort -rn | head -50 | awk '{print $2}'
Windows PowerShell:
Get-Content access.log | ForEach-Object { ($_ -split ' ')[0] } | Group-Object | Sort-Object Count -Descending | Select-Object -First 50 -ExpandProperty Name
Any other text — a firewall export, email headers, a pasted
report — can be mined for IPv4 addresses with
grep -oE '([0-9]{1,3}\.){3}[0-9]{1,3}' file.txt | sort -u. It will also catch the odd version
number that looks like an address; the tool simply skips anything that isn’t valid.
One catch: if your site sits behind Cloudflare, a load balancer or another reverse
proxy, the first field is the proxy’s address, and every row will come back as the same provider. The
real visitor address is in a header such as X-Forwarded-For or CF-Connecting-IP, which
your server has to be told to log.
What Each Column Means
| Column | What it is | How far to trust it |
|---|---|---|
| Type | The kind of connection — see the next section | Good for ranges on a known list; a brand-new server can be missed |
| Country | Where the range is registered or observed | Usually right |
| City / region | The database’s best guess for the range | A hint only — often the provider’s hub, not the user’s town |
| Provider | The ISP or hosting company that operates the range. The CSV adds org, the organisation the block is assigned to — for 8.8.8.8 the provider is Google LLC and the org is Google Public DNS | Reliable |
| Network | The autonomous system number (ASN) the address is routed through, such as AS15169 for Google. Every address in one ASN is run by the same operator | Reliable — the best column for spotting clusters |
What the Type Column Means
The connection type is the most useful column here, and the one most lookup tools get wrong. It comes from lists of known hosting, proxy and mobile ranges rather than a guess based on the provider’s name — which matters, because plenty of datacentre ranges belong to companies whose names sound like ordinary businesses.
| Type | What it tells you |
|---|---|
| Residential | A consumer or business broadband line with no hosting, proxy or mobile flag — most likely a real person |
| Data centre | A hosting or cloud range. Servers, bots, scrapers and APIs live here — rarely a human browsing |
| Data centre + Proxy-listed | A hosting range that also appears on proxy and VPN lists. Commercial VPN exits look like this — but so do some public services: Google’s 8.8.8.8 DNS resolver carries the proxy flag too |
| VPN / Proxy | A proxy-listed address that is not in a hosting range — often a residential proxy, where traffic is routed through someone’s home connection. The one worth a second look |
| Mobile | A carrier network, usually shared by many subscribers behind CGNAT |
What People Use This For
Reading server logs. Paste the addresses hitting an endpoint and the type column separates real visitors from scrapers immediately — a page of datacentre addresses is automated traffic, whatever the user agent claims.
Checking sign-ups or orders. A batch of accounts created from the same datacentre range, or from VPN exits in a country you don’t serve, is a pattern worth knowing about before you ship anything.
Investigating spam or abuse. Run the addresses from your mail logs or comment queue and look at the provider and network number — abuse usually clusters in a handful of ranges. Pair it with the IP reputation checker to see whether they’re already on a blacklist.
⚠️ Why the Location Is Sometimes Absurd
Look up 1.1.1.1 and you may be told Australia. The address is
Cloudflare’s, registered through the Asia-Pacific registry, but the server answering you is almost certainly in
your own city — it’s an anycast address, meaning the same number is announced from dozens of
locations at once and you reach the nearest one. When we checked in September 2026, its IPv6 twin,
2606:4700:4700::1111, came back as Montreal: same service, same operator, a different answer.
Geolocation databases store one location per range, so anycast addresses, satellite links and recently reassigned ranges all produce results that look wrong and are. Treat the location column as a hint and the provider and network columns as the reliable parts. Background: how IP geolocation actually works.
Where the Data Comes From
Each batch goes from our server to ip-api.com in a single request, and the answers are passed straight back to your browser. The connection-type labels are built from that service’s hosting, proxy and mobile flags. Those are lists of known ranges, not a live test of the address — so a VPN server switched on last week, or a range recently sold to a new owner, can be labelled by what it used to be.
Bulk Lookup, WHOIS or Reputation Check?
| Your question | The tool for it |
|---|---|
| Where are these addresses, who runs them, and are they home lines or servers? | Bulk IP Lookup (this page) |
| Who is this range formally registered to, and since when? | WHOIS lookup |
| Is this address on spam or abuse blacklists? | IP reputation checker |
| What can websites see about my address? | What Is My IP |
Frequently Asked Questions
How many addresses can I check at once?
Fifty per lookup. Run several batches if you have more — there’s no signup. If the lookup service is busy you’ll be asked to wait a minute and try again.
Does it work with IPv6?
Yes. Mix IPv4 and IPv6 in the same batch if you like; both are validated before anything is sent.
Does looking up an address alert its owner?
No. The lookup asks a database about the address; nothing is sent to the address itself, so there is nothing for its owner to see.
Can it tell me who is behind an IP address?
No. It names the provider, not the subscriber. Only the provider can match an address to a customer account, and it normally does that only for a court order or a police request — see can police track you by your IP address.
Can I get the results as a file?
Yes — “Export CSV” downloads every column, including the region, organisation and proxy-listed flag that aren’t shown in the table.
Do you store the addresses I paste?
No. They’re validated, looked up and returned. Nothing is written to a log or a database on our side.
Why does a row say “private range” or “reserved range”?
Those addresses don’t exist on the public internet, so there’s nothing to look up.
192.168.x.x and 10.x.x.x are private ranges used inside home and office networks;
100.64.x.x is reserved for carriers sharing one public address among many customers. See
public vs private addresses.
Why does 8.8.8.8 say “Proxy-listed”?
Because the range appears on the proxy lists the labels are built from, even though it’s Google’s public DNS resolver. That’s why the tag sits beside “Data centre” instead of replacing it: it tells you the range is listed, not that someone is hiding behind it.
Is “Data centre” the same as “bot”?
No, but it’s a strong hint. Real people occasionally browse from cloud desktops or corporate VPNs. It means the address isn’t a home line, not that the traffic is hostile.