IP Address Response Fields

Every IP address lookup returns the fields below. Each JSON payload always contains every field: when a value cannot be determined, it is set to null. Examples are illustrative values, not one single response.

When using the origin IP lookup endpoint, the response also includes user-agent fields for the client that made the request.

root

Top level

The address that was looked up and how it resolves.

ip string
The IP address that is analyzed.

Example "8.8.8.8"

type string
The IP address type.
One of
  • IPv4
  • IPv6

Example "IPv4"

hostname string
The reverse DNS hostname of the IP address. This value is only resolved when the hostname parameter is set to true; otherwise it is null. See Hostname Lookup.

Example "dns.google"

carrier

Carrier

The mobile network operator, when the address serves mobile traffic.

carrier.name string
The name of the mobile carrier that owns the IP address. If the value is not null, the IP address is very likely used for mobile carrier traffic.

Example "T-Mobile"

company

Company

The organization that uses the address block.

company.domain string
The domain guessed for the company associated with the IP.

Example "google.com"

company.name string
The name of the company associated with the IP.
The ability of Ipregistry to tell the company depends on the size of the company and how it runs its network. Say WeWork rents its space to a startup: if someone from that startup visits your website, we might not identify the startup, since it is small and uses its building's network. We can still tell you that the IP is from WeWork.

Example "Google LLC"

company.type string
Classifies the company type.
One of
  • business
  • education
  • government
  • hosting
  • isp

Example "hosting"

connection

Connection

The network that announces the address on the Internet.

connection.domain string
The top-level domain name associated with the organization that owns the connection IP.

Example "google.com"

connection.is_anycast boolean
Whether the IP address is announced via anycast, i.e. simultaneously from multiple locations. Anycast addresses (public DNS resolvers, CDN edges) have no single physical location, so their geolocation should be treated with caution.

Example true

The name of the organization that owns the Autonomous System for the IP address. The value may fall back to the Autonomous System name if the organization name is not available.

Example "Google LLC"

connection.route string
The AS route associated with the IP address, as announced and used in Border Gateway Protocol (BGP) routing tables over the Internet.

Example "8.8.8.0/24"

connection.type string
Classifies the connection type.
One of
  • business
  • education
  • government
  • hosting
  • inactive
  • isp

Example "hosting"

currency

Currency

The local currency and how to format amounts in it.

currency.name string
The name of the currency in US locale.

Example "US Dollar"

currency.name_native string
The name of the currency in the native locale, based on the detected location and primary language.

Example "US Dollar"

currency.plural string
The plural name of the currency in US locale.

Example "US dollars"

The plural name of the currency in the native locale, based on the detected location and primary language.

Example "US dollars"

currency.symbol string
The symbol of the currency. For instance, A$ for Australian dollars.

Example "$"

The native (local) symbol of the currency. For instance, $ for Australian dollars.

Example "$"

location

Location

Where the address is used, from continent down to coordinates, plus country facts.

The 2-letter code of the continent associated with the IP.
Values
AF
Africa
AN
Antarctica
AS
Asia
EU
Europe
NA
North America
OC
Oceania
SA
South America

Example "NA"

The name of the continent associated with the IP address.

Example "North America"

location.country.area integer
The sum of land and water areas within international boundaries and coastlines, in km².

Example 9629091

location.country.borders string[]
The ISO 3166-1 alpha-2 codes of the countries that border the country associated with the IP. An empty list is returned if the country has no land borders.

Example ["CA", "MX"]

The capital city of the country associated with the IP.

Example "Washington D.C."

location.country.name string
The name of the country where the IP address is located.

Example "United States"

The total population, in number of residents, of the country associated with the IP.

Example 340110988

A link to the EmojiTwo SVG file for the flag of the country where the IP address is located. See the license for requirements about how to use these images.

Example "https://cdn.ipregistry.co/flags/emojitwo/us.svg"

A link to the Noto PNG file for the flag of the country where the IP address is located. See the license for requirements about how to use these images.

Example "https://cdn.ipregistry.co/flags/noto/us.png"

A link to the Twemoji SVG file for the flag of the country where the IP address is located. See the license for requirements about how to use these images.

Example "https://cdn.ipregistry.co/flags/twemoji/us.svg"

A link to the raw SVG file for the flag of the country where the IP address is located. The source files were taken from Wikipedia and are not under copyright protection, since raw flags are in the public domain.

Example "https://cdn.ipregistry.co/flags/wikimedia/us.svg"

The languages spoken in the country associated with the IP, sorted by popularity in descending order.
location.country.tld string
The country code top-level domain (ccTLD) of the country, as defined by the Internet Assigned Numbers Authority (IANA).

Example ".us"

location.region.code string
The ISO 3166-2 subdivision (region) code associated with the IP, when available. We publish complete and up-to-date ISO 3166 data sets on GitHub.

Example "US-CA"

location.region.name string
The name of the region associated with the IP address. When a region code is available, the name is in the administrative language of the country.

Example "California"

location.city string
The name of the city associated with the IP address.

Example "Mountain View"

location.postal string
The postal (ZIP) code associated with the IP address.

Example "94043"

location.latitude number
The approximate WGS84 latitude of the location associated with the IP.
The coordinates returned for an IP address are not precise and should not be used to identify a particular street address or household (this applies to any IP geolocation provider). Refer to a larger area such as the city, region or country.

Example 37.40552

location.longitude number
The approximate WGS84 longitude of the location associated with the IP.

Example -122.07746

The name of the main language associated with the IP location.

Example "English"

The native name of the main language associated with the IP location.

Example "English"

location.in_eu boolean
Whether the country is a member of the European Union.

Example false

security

Security

Anonymization and threat signals attached to the address.

security.is_abuser boolean
Whether the IP address is a known source of abuse (e.g. spam, harvesters, registration bots).

Example false

security.is_attacker boolean
Whether the IP address is a known source of malicious activity (e.g. attacks, malware, botnet activity).

Example false

security.is_bogon boolean
Whether the IP address is a bogon: an unassigned, unaddressable IP address.

Example false

Whether the IP address is used for hosting purposes (e.g. a node from Akamai, Cloudflare, Google Cloud Platform, Amazon EC2, and more).

Example true

security.is_proxy boolean
Whether the IP address is a known proxy. It includes HTTP/HTTPS/SSL/SOCKS/CONNECT and transparent proxies. Residential proxies are included.

Example false

security.is_relay boolean
Whether the IP address is a known relay. Relay IP addresses are not designed to bypass geo-controls but pool multiple users behind the same IP. At this time, only Apple Private Relay IP addresses are detected.

Example false

Whether the IP address is a known residential proxy: a consumer connection (home broadband or mobile) whose traffic is resold to route third-party requests. When true, is_proxy is also true.

Example false

security.is_threat boolean
true when is_abuser or is_attacker is true. is_cloud_provider is not considered: it is up to you to combine it with a logical OR.

Example false

security.is_tor boolean
Whether the IP address is a Tor relay: exit relay node, middle relay node or bridge.

Example false

security.is_vpn boolean
Whether the IP address is used by a Virtual Private Network (VPN).

Example false

time_zone

Time zone

The local time zone and the current time there.

time_zone.name string
The name of the time zone.

Example "Pacific Standard Time"

time_zone.offset integer
The offset from UTC of the time zone, in seconds.

Example -28800