Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Bulk IP Lookup

Every address in a log, counted and labelled with country, network, cloud and Tor.

Network No upload Uses live data Free preview, no sign-upIncluded in your pass Premium tool Premium pass: ₹799 for 30 days

Free preview.

  • Free preview: every summary count, with the first half of each table and list (up to 10 rows).
  • Locked until you unlock it: download and copy.
  • Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Text with IP addresses

Next steps

About the Bulk IP Lookup

Paste a server log, a firewall or SSH log, an e-mail header, a spreadsheet column or a plain list — or drop the log files themselves, .gz included — and every IPv4 and IPv6 address in it is found, counted and de-duplicated. Each unique address is then labelled from data that runs in your browser: its type (public, private, carrier-grade NAT, documentation… from IANA’s special-purpose registries), its country (DB-IP), the network that routes it (origin AS number and name, IPtoASN), the hosting, cloud or CDN provider with the cloud service and region where the provider publishes its ranges, and whether it is a Tor exit relay.

Country and network breakdowns show where the traffic comes from; filters keep only public addresses, one country, one AS number, cloud servers, Tor exits, or addresses inside or outside your own prefixes. Nothing is sent per address: the lookups use data files downloaded from MySmartCoPilot, and the Tor check downloads the Tor Project’s list once.

Without a pass the result is a free preview: every summary count, with the first half of the address table and of each breakdown (up to 10 rows); the CSV and the copied lists unlock with a Premium pass.

How to use it

  1. Paste the text into the box, or choose or drop one or more log files (text, CSV, JSON or .gz, up to 60 MB each).
  2. Leave Mark Tor exit relays on to label Tor exits (the page downloads the Tor Project’s current exit list; your addresses are not sent).
  3. Press Look up all. A progress bar shows the lookups; up to 100,000 unique addresses are looked up per run.
  4. Read the counts and the breakdowns by country, network and address type, then narrow the table with the filters: Public only, a kind (hosting and cloud, Tor exits, private), a country, an AS number, a search, or Inside or outside your own prefixes.
  5. Sort the table by address, count, country or network. The CSV download and the copied lists unlock with a Premium pass; without one the page shows the free preview.

Examples

An SSH log
Input
Failed password for root from 8.8.8.8 port 52011 ssh2
Failed password for root from 8.8.8.8 port 52013 ssh2
Result
1 unique address, 2 appearances · 8.8.8.8 · Public address · United States · AS15169 GOOGLE
A web server log behind a proxy
Input
[::ffff:203.0.113.9]:443 TLS handshake failed
X-Forwarded-For: 2606:4700:4700::1111, 10.0.0.5
Result
203.0.113.9 (IPv4-mapped, counted as IPv4) · Documentation (RFC 5737)
2606:4700:4700::1111 · AS13335 CLOUDFLARENET · Cloudflare
10.0.0.5 · Private-use (RFC 1918)
Things that are not addresses
Input
Chrome/122.0.0.0 · OID 1.3.6.1.4.1.9 · 10:30:00 · 00:1a:2b:3c:4d:5e
Result
No address found

Browser versions after a product name, longer dotted numbers, times and MAC addresses are skipped.

Common uses

  • Seeing which countries and networks a wave of login attempts, scans or spam comes from, before writing firewall rules.
  • Finding the requests in an access log that come from cloud servers or Tor exits rather than from people.
  • Cleaning up an exported list of addresses: duplicates removed, private ones separated, everything in one sortable table.
  • Checking which addresses in a log are inside or outside your own networks.

How addresses are found

The text is split into words, and each word is read as an address only if it is a valid one: IPv4 as four decimal numbers from 0 to 255 without leading zeros, IPv6 in any form allowed by RFC 4291 and shown in the short form of RFC 5952. Ports (203.0.113.9:443, [2001:db8::1]:443), brackets, a zone index (fe80::1%eth0) and a label in front (ip:203.0.113.9, SRC=…) are removed. IPv4-mapped IPv6 addresses such as ::ffff:203.0.113.9, which dual-stack servers log for IPv4 clients, count as the IPv4 address. A version number after a product name (Chrome/122.0.0.0) is not an address, and neither are times, MAC addresses or longer dotted numbers.

Where each label comes from

  • Type: IANA’s IPv4 and IPv6 special-purpose address registries (RFC 6890). Private, documentation and other special addresses are not looked up further: they have no public owner or location.
  • Country: DB-IP IP to Country Lite (CC BY 4.0), an estimate of where the address is used; VPNs, mobile networks and anycast services can appear in another country.
  • Network: the origin AS of the most specific route covering the address in the IPtoASN routing snapshot (PDDL). Not routed means no network announced it.
  • Hosting, cloud or CDN: the provider is named from the AS number; for AWS, Google Cloud, Azure, Oracle Cloud, DigitalOcean, Akamai (Linode) and Vultr the service and region come from their published IP range files.
  • Tor: the Tor Project’s Onionoo list of running exit relays, downloaded when you press Look up all.

What the free preview shows

Without a pass, every count at the top — unique addresses, IPv4 and IPv6, appearances, public addresses, countries, networks, hosting and Tor — is shown in full, so you can see what the log holds. The address table and each breakdown show their first half, up to 10 rows, and a single address shows its row with the looked-up values hidden. The CSV download and the copied address and CIDR lists unlock with a Premium pass.

Limitations

  • Up to 100,000 unique addresses and 60 MB of text per run; split larger logs into parts.
  • Country is an estimate from DB-IP’s Lite database, at country level only; it cannot locate a person, a street or a city.
  • Networks, cloud ranges and the provider list are snapshots built into this page; routing and cloud ranges change, so the newest changes may be missing. The Tor list is current when it downloads, but relays come and go.
  • Only cloud providers that publish their ranges get a service and region; other hosting companies are named from their AS number when they are known.

Privacy

Your text and the addresses in it are processed in your browser and never uploaded. To label the addresses the page downloads data files from MySmartCoPilot, each covering a large block of addresses, and, when Tor marking is on, the Tor Project’s public list of exit relays; neither request contains your addresses.

Frequently asked questions

What do I get without a pass?

Without a pass, Bulk IP Lookup shows every summary count, with the first half of each table and list (up to 10 rows). Until you unlock it, the result can’t be downloaded or copied. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

Are my logs uploaded?

No. The addresses are found and looked up in your browser. The page downloads data files from MySmartCoPilot that cover large blocks of the address space, and the Tor Project’s exit list, but it never sends your text or your addresses.

Why do some addresses have no country or network?

Private (10.x, 192.168.x, fc00::/7), loopback, documentation and other special-purpose addresses have no public owner or location, so they are labelled with their type only. A public address with Not routed is not announced by any network in the routing snapshot.

How do I block the addresses I found?

Filter the table (for example Tor exits, or one network) and use Copy as CIDR list, which merges the addresses into the fewest prefixes; with a Premium pass the list copies in full. The IP Range to CIDR Converter turns such a list into nginx, iptables, Windows Firewall or cloud rules.

Does a Tor exit mean the visitor is malicious?

No. Tor exits carry traffic for many people who want privacy, journalists and security researchers among them; the operator of the exit cannot see who sent it. Treat it as one signal among others.

Why does a cloud address show a region but a different country?

The region comes from the provider’s own published ranges, the country from DB-IP’s estimate. Cloud providers move address blocks between regions, and global services such as CDNs serve one address from many places, so the two can differ.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.