From a login alert, firewall log or email header. We show the owner network, reverse DNS and matches on open threat lists.
IPv4 or IPv6. Private addresses such as 192.168.x.x are explained rather than looked up.
RDAP tells us which organisation holds the range; DNS tells us the address's name.
abuse.ch Feodo Tracker (botnet command servers), Spamhaus DROP (hijacked and criminal networks), the Tor exit list and, where enabled, AbuseIPDB reports.
Check the owner and country here, then compare with where and when you were online. A login from a data-centre address in another country while you were asleep is a strong signal to change the password and enable MFA.
Lists lag behind. Use the result with the context — what the address did and when.
Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.