Shared-IP clues — what your address can and cannot prove.

EDGE: READY
More options
What are you checking?
EXAMPLE Checked static example Cache n/a NOT LIVE
IP

8.8.8.8

EXAMPLERUN A LIVE CHECK
ASN
AS15169 · Google LLCgoogle.com
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessedIPJURY SCOREEXPERIMENTAL · NOT A PROBABILITY IPJURY VERDICT EXAMPLE

Run a live check for an evidence verdict and experimental interpretation.

Why this result · full calculation

Run a live check. The example is not scored.

    Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.

    OPEN FULL EVIDENCE REPORT

    JURY READY

    Enter an address, or check your own connection · the example below is replaced in place

    FULL REPORT IDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
    EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
    ANONYMITY
    No direct anonymity evidence observed
    ABUSE EVIDENCE
    No abuse evidence in covered sources
    COVERAGE
    6/7 jurors responded
    01

    IDENTITY

    COORDINATES
    not loaded in static example
    ROUTING
    ROUTE ORIGIN OBSERVED
    PREFIX
    8.8.8.0/24
    TIMEZONE
    America/Los_Angeles
    REVERSE DNS
    not loaded in static example
    STACK
    IPv4
    RANGE
    8.8.8.0 – 8.8.8.255
    REGISTRY
    not loaded in static example
    02

    SOURCE MATRIX

    4 location sources agree at country level · — not covered · W/H withheld

    SIGNALIPBotIPinfoGeoLite2DB-IPIPtoASN
    COUNTRYUSUSUSUS
    CITYCalifornia, Mountain ViewCalifornia, Mountain View
    ASNAS15169AS15169AS15169AS15169
    PROXYNO
    VPNW/H
    TORNO
    HOSTINGNO
    ABUSENO
    03

    SIX-AXIS VERDICT

    NETWORK ROLEHIGH
    Public internet infrastructure

    Service role · anycast context · operator identity

    ANONYMITYMEDIUM
    No direct anonymity evidence observed

    No proxy, VPN, or Tor finding in covered fields

    ABUSE EVIDENCEMEDIUM
    No abuse evidence in covered sources

    This means “not observed,” never “clean”

    GEO CONTEXTLOW
    US · single geolocation estimate

    Country-level context; physical location not proven

    ROUTINGHIGH
    Route origin observed · RPKI state withheld by licence

    Origin ASN · announced prefix · route-origin conflict

    COVERAGEMEDIUM
    6/7 jurors responded

    Named jurors · lineage families · abstentions visible

    04

    EVIDENCE RECORD

    JURORAXISCLAIMCONF.STATUS
    Network identityIPBot networknetwork roleAS15169 · Google LLCHIGHRESPONDED
    Operator and role profileIPBot classificationnetwork rolepublic infrastructureHIGHRESPONDED
    Anonymity signalsIPBot classificationanonymityno direct proxy/VPN/Tor evidenceMEDIUMRESPONDED
    Direct threat evidenceIPBot evidenceabuseno direct record in covered evidenceMEDIUMRESPONDED
    REPORT ipjury.com/check/8.8.8.8 EXPERIMENTAL INDEX
    TERMINAL curl ipjury.com/8.8.8.8 irm ipjury.com/8.8.8.8
    IPJURY.COM · EVIDENCE, NOT AN ENTERTAINMENT SCORE

    IPJury uses the IP2Location LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP Geolocation by DB-IP. Full source credits: source register.

    05

    SHARED EXITS AND CARRIER-GRADE NAT

    How can I investigate whether my connection uses shared IPv4?

    Compare your router’s WAN IPv4 with the public IPv4 used by the same connection at approximately the same time, accounting for proxies or VPNs. The lookup supplies network context; the provider must confirm its NAT arrangement.

    Evidence scope and register licence-review dates — not live lookup dates
    SourceRegister review
    IPBot Network Identity
    IANA special-purpose address registry

    Source availability depends on the current deployment and each returned record. These review dates do not establish when a particular IP was observed. Method axis-scope-2026-09-15 · Score ipjury-score-v3.

    A public IP lookup cannot, on its own, prove that you share an exit with other subscribers. It can show the network role, address scope and published evidence. To investigate carrier-grade NAT, compare those clues with the WAN address shown by your own router and ask your provider to confirm its setup.

    What carrier-grade NAT changes

    A provider can translate several customers' connections onto public IPv4 addresses at a carrier gateway. A website then sees the gateway's public address rather than the address assigned to the customer's router. The number of customers, allocation policy and mapping lifetime are provider-specific. Neither an ASN name nor a mobile-network label discloses those details.

    An address-based rate limit can consequently affect several unrelated people. Cloudflare describes detecting CGNAT to reduce such collateral effects. That mechanism is a reason to investigate shared egress, not proof that CGNAT caused your particular CAPTCHA. Websites can also use account, browser, session and behaviour signals that this lookup does not observe.

    Compare the right pair of addresses

    1. Record the public IPv4 for this connection. Use the My IP action and note the time. An IPv6 result is not the IPv4 exit; comparing the two will not diagnose IPv4 NAT.
    2. Read the WAN or Internet IPv4 in your router's status page. Do not use your laptop's local address or the router's LAN address. No router password or screenshot needs to be uploaded to IPJury.
    3. Compare them at approximately the same time. A WAN address in 100.64.0.0/10 and a different public IPv4 is consistent with an upstream translation arrangement. An RFC 1918 private WAN address can also reflect another router under your control, so a mismatch alone does not distinguish provider CGNAT from double NAT.
    4. Account for the path being tested. A browser proxy, VPN, corporate gateway or split-tunnel setup can make the browser's exit differ from the router's. Record that context rather than treating every mismatch as CGNAT.
    5. Ask the provider for confirmation. Ask whether your service uses carrier-grade NAT, whether a public IPv4 option exists, and whether its static-address offering is dedicated. A static address and an exclusive address are different promises.

    What the IPJury record contributes

    Network role identifies source-reported mobile, residential, business or hosting context. ASN and prefix identify the network or block named by a source, not its subscriber count. PTR can contain operator naming clues, but a name containing “pool” or “nat” is not independent proof of shared service.

    Read abuse evidence separately. A listing can name the public address without identifying which subscriber generated traffic. A prefix-level observation applies at a different scope again. No finding in covered sources means no finding was returned for this check; it does not establish that the address is exclusive, safe or accepted by a platform. An unanswered or withheld source leaves an explicit gap.

    A useful question to send to support

    “At the recorded time, my router reported this WAN IPv4, while my browser used this public IPv4. I was using the following proxy or VPN setup, or none. Does this service use provider-side NAT, and is the public address shared with other subscribers?” Attach only the facts you intend to disclose. The IPJury report can support the network-identity part of that question; it cannot answer on the provider's behalf.

    06

    A NUMBER NEEDS ITS EVIDENCE

    IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.

    MYSTERY SCORE MODEL
    83/100

    What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.

    • Cross-axis averaging
    • Hidden source lineage
    • Missing source treated as “false”
    • Disagreement averaged away
    • Platform outcome implied
    EVIDENCE + EXPLAINED INTERPRETATION
    BANDDISPUTED RULEsource-conflict ROLEhosting ANONYMITYno direct evidence ABUSEno record observed GEOcountry disputed ROUTINGorigin observed COVERAGE6/7 responded

    One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.

    07

    THE FIVE RULES OF EVIDENCE

    [ READ FULL METHOD ]
    1. 01

      Vote only on the same axis

      A proxy flag, an abuse report, a hosting role, and a city estimate are not interchangeable votes.

    2. 02

      Direct evidence outranks a prior

      An exact-IP record is different from an inference based on the ASN, prefix, or network category.

    3. 03

      Deduplicate source lineage

      Three websites backed by one upstream database do not become three independent evidence families.

    4. 04

      Let jurors abstain

      Timeout, no IPv6 coverage, disabled license, or missing record is shown—not silently converted to “no.”

    5. 05

      Explain dissent

      CGNAT, anycast, reassignment, data age, and route context can all produce legitimate disagreement.

    09

    QUESTIONS THE SCORE CANNOT ANSWER

    How can I tell whether my public address is shared with other subscribers?

    A public IP lookup alone cannot establish subscriber sharing. Compare your router's WAN IPv4 with the public IPv4 on the same connection, account for VPNs or another router, and ask your provider to confirm its NAT setup. 100.64.0.0/10 identifies non-global Shared Address Space, not a subscriber count.

    What is carrier-grade NAT?

    It is provider-side address translation that can place several customers behind public IPv4 exits. A website may see the same public address for unrelated subscribers, but it can also distinguish sessions using account, browser and behaviour signals.

    Will restarting my router or clearing cookies change how sites treat me?

    The outcome depends on the cause. A router restart may or may not change the exit address, while clearing cookies changes session state. Neither establishes the cause of a challenge or guarantees that a platform will treat the connection differently.

    Can I get a public address that is not shared?

    Ask your provider whether it offers a dedicated public IPv4 and whether the advertised static address is exclusive. Static and dedicated are different promises. IPv6 may use a different path where supported, but none of these options guarantees a platform outcome.

    IPJURY // RECORD

    Methodology