Trace an IP to its network, prefix, and route authority.

EDGE: READY
More options
What are you checking?
EXAMPLE Checked static example Cache n/a NOT LIVE
IP

8.8.8.8

EXAMPLERUN A LIVE CHECK
ASN
AS15169 · Google LLCgoogle.com
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessedIPJURY SCOREEXPERIMENTAL · NOT A PROBABILITY IPJURY VERDICT EXAMPLE

Run a live check for an evidence verdict and experimental interpretation.

Why this result · full calculation

Run a live check. The example is not scored.

    Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.

    OPEN FULL EVIDENCE REPORT

    JURY READY

    Enter an address, or check your own connection · the example below is replaced in place

    FULL REPORT IDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
    EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
    ANONYMITY
    No direct anonymity evidence observed
    ABUSE EVIDENCE
    No abuse evidence in covered sources
    COVERAGE
    6/7 jurors responded
    01

    IDENTITY

    COORDINATES
    not loaded in static example
    ROUTING
    ROUTE ORIGIN OBSERVED
    PREFIX
    8.8.8.0/24
    TIMEZONE
    America/Los_Angeles
    REVERSE DNS
    not loaded in static example
    STACK
    IPv4
    RANGE
    8.8.8.0 – 8.8.8.255
    REGISTRY
    not loaded in static example
    02

    SOURCE MATRIX

    4 location sources agree at country level · — not covered · W/H withheld

    SIGNALIPBotIPinfoGeoLite2DB-IPIPtoASN
    COUNTRYUSUSUSUS
    CITYCalifornia, Mountain ViewCalifornia, Mountain View
    ASNAS15169AS15169AS15169AS15169
    PROXYNO
    VPNW/H
    TORNO
    HOSTINGNO
    ABUSENO
    03

    SIX-AXIS VERDICT

    NETWORK ROLEHIGH
    Public internet infrastructure

    Service role · anycast context · operator identity

    ANONYMITYMEDIUM
    No direct anonymity evidence observed

    No proxy, VPN, or Tor finding in covered fields

    ABUSE EVIDENCEMEDIUM
    No abuse evidence in covered sources

    This means “not observed,” never “clean”

    GEO CONTEXTLOW
    US · single geolocation estimate

    Country-level context; physical location not proven

    ROUTINGHIGH
    Route origin observed · RPKI state withheld by licence

    Origin ASN · announced prefix · route-origin conflict

    COVERAGEMEDIUM
    6/7 jurors responded

    Named jurors · lineage families · abstentions visible

    04

    EVIDENCE RECORD

    JURORAXISCLAIMCONF.STATUS
    Network identityIPBot networknetwork roleAS15169 · Google LLCHIGHRESPONDED
    Operator and role profileIPBot classificationnetwork rolepublic infrastructureHIGHRESPONDED
    Anonymity signalsIPBot classificationanonymityno direct proxy/VPN/Tor evidenceMEDIUMRESPONDED
    Direct threat evidenceIPBot evidenceabuseno direct record in covered evidenceMEDIUMRESPONDED
    REPORT ipjury.com/check/8.8.8.8 EXPERIMENTAL INDEX
    TERMINAL curl ipjury.com/8.8.8.8 irm ipjury.com/8.8.8.8
    IPJURY.COM · EVIDENCE, NOT AN ENTERTAINMENT SCORE

    IPJury uses the IP2Location LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP Geolocation by DB-IP. Full source credits: source register.

    05

    ROUTING CONTEXT AND ROUTE AUTHORITY

    Which network and source-reported range carry this IP?

    Read the reported ASN, operator and source range, with independent origin corroboration where available. These are network facts, not subscriber identity. The current deployment withholds RPKI validity instead of presenting it as verified.

    Evidence scope and register licence-review dates — not live lookup dates
    SourceRegister review
    IPtoASN prefix-to-origin table
    MaxMind GeoLite2 ASN
    Reverse DNS (PTR)

    Source availability depends on the current deployment and each returned record. These review dates do not establish when a particular IP was observed. Method axis-scope-2026-09-15 · Score ipjury-score-v3.

    This record reports which network and range the permitted sources name for an address. It does not currently validate route authorization. Useful context — and regularly mistaken for what it is not: a statement about the person using the address.

    Allocation is not the same as routed reality

    Two records describe an address block and answer different questions. A regional internet registry — one of five bodies distributing number resources under IANA — records who was allocated the block and under which allocation type: the paper trail. BGP separately shows which prefix is announced today and which ASN originates it. The paper trail changes when the registry is updated; the routed reality changes when someone changes a router.

    The gap is normal, not suspicious. Blocks are leased, sub-allocated, transferred, and re-purposed, and records can update on different schedules. When a registry says an enterprise in one country holds a block while routing shows a hosting provider in another announcing it, the records may describe different scopes; compare their dates and definitions instead of assuming either is automatically correct. IPJury shows the announced prefix alongside the allocation rather than calling one the truth.

    RPKI: what the three states actually mean

    IPJury does not currently display RPKI validity. The state is withheld rather than unknown: the deployed build sources validation from RIPEstat, whose terms restrict commercial reuse, so the routing axis reports origin ASN, announced prefix and route-origin conflicts instead. The states below are what the field would tell you, and what to check it against elsewhere.

    The Resource Public Key Infrastructure lets an address holder publish a signed statement — a Route Origin Authorisation — naming which ASN may originate their prefix and up to what length. Validating routers compare announcements against it and produce one of three states, defined in RFC 6811.

    Valid
    A published authorisation covers this prefix and permits this origin ASN at this length. The announcement matches what the holder authorised, and says nothing about the traffic it carries.
    Invalid
    An authorisation exists for the prefix but none permits this origin or length. The state worth attention — and still not proof of an attack: misconfiguration or an outdated authorization is one possible explanation to investigate.
    Not found
    No authorisation covers the prefix: a holder who has not published one. Neither good nor bad news; reading it as a negative penalises networks for not adopting an optional practice.

    Route-origin conflicts

    A conflict appears when the same or overlapping prefixes are announced from more than one origin ASN, or when an unexpected more-specific announcement shadows a covering block. Some are legitimate: multi-origin announcements occur in anycast deployments, during provider migrations, and where a customer and its upstream both originate a block. Some are misconfiguration; a few are hijacks. The state prompts a look at operator context rather than standing as a verdict, and belongs to the prefix, not to any address in it.

    PTR is a weak clue, by design

    Reverse DNS maps an address back to a hostname, and hostnames look informative: names like static, dynamic, pool, or vpn hint at how a range is used. But PTR is set by whoever controls the reverse zone, verified by nobody, and frequently left over from an old configuration — wrong through neglect as easily as intent. IPJury reports it as a naming clue and labels it weak. A forward-confirmed lookup, where the hostname resolves back to the address, is stronger, and still only a claim about DNS.

    What routing informs and what it cannot decide

    Routing context makes the other axes readable. It distinguishes consumer ISPs from carriers, clouds, CDNs, and transit providers, and explains why an address inherits a network-level prior. What it cannot do is settle those axes: an ASN running hosting infrastructure does not make an address inside it a proxy, and a valid RPKI state is not an absence of abuse history. Routing describes the road; the other axes describe the traffic.

    For how routing feeds the role determination, see the network role guide.

    06

    A NUMBER NEEDS ITS EVIDENCE

    IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.

    MYSTERY SCORE MODEL
    83/100

    What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.

    • Cross-axis averaging
    • Hidden source lineage
    • Missing source treated as “false”
    • Disagreement averaged away
    • Platform outcome implied
    EVIDENCE + EXPLAINED INTERPRETATION
    BANDDISPUTED RULEsource-conflict ROLEhosting ANONYMITYno direct evidence ABUSEno record observed GEOcountry disputed ROUTINGorigin observed COVERAGE6/7 responded

    One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.

    07

    THE FIVE RULES OF EVIDENCE

    [ READ FULL METHOD ]
    1. 01

      Vote only on the same axis

      A proxy flag, an abuse report, a hosting role, and a city estimate are not interchangeable votes.

    2. 02

      Direct evidence outranks a prior

      An exact-IP record is different from an inference based on the ASN, prefix, or network category.

    3. 03

      Deduplicate source lineage

      Three websites backed by one upstream database do not become three independent evidence families.

    4. 04

      Let jurors abstain

      Timeout, no IPv6 coverage, disabled license, or missing record is shown—not silently converted to “no.”

    5. 05

      Explain dissent

      CGNAT, anycast, reassignment, data age, and route context can all produce legitimate disagreement.

    09

    QUESTIONS THE SCORE CANNOT ANSWER

    What is an ASN, and why does it appear in an IP check?

    An autonomous system number identifies the network announcing a block of addresses to the rest of the internet. It supplies ownership and routing context for the address, though never the identity or intent of an individual user.

    What does the announced prefix tell me that the address alone does not?

    It shows the block the address is routed inside, which is the unit most network-level evidence actually applies to. It is also how you tell an exact-address finding apart from one inherited from neighbors.

    What does an RPKI invalid state mean?

    In RPKI, invalid means the announcement does not match a relevant authorization. IPJury does not currently display RPKI validity under its active source permissions; the explanation is not a validation of this address.

    Can ASN or registry records tell me who was using an address at a given moment?

    No. Those records identify the operator responsible for the block. The mapping from an address to a subscriber at a point in time exists only inside that operator's own systems.

    IPJURY // RECORD

    Methodology