IP/Domain Info
IP/Domain Info tool provides a summary of Netlas data for a specific IP address or domain name. This tool supports queries by IP or domain only, but returns aggregated data from all Netlas data collections in a single response.


Usage
Input a valid IP address or domain name to retrieve data.
Examples:
1.1.1.1
google.com
Without an argument, the tool returns a summary for the requester's IP, allowing you to quickly assess your external IP by visiting Netlas app.
Contents
The tool returns different data for IPs and domains. The most majority of fields are optional.
Data availability depends on your pricing plan
For example, if your pricing plan does not provide you with access to contact details such as phone numbers and email addresses, this data will not be returned (displayed) by any of Netlas tools.
Anonymity Labels
Not available on the free plan
Displayed next to the IP address are labels indicating if the IP is associated with a TOR exit node, a VPN, or a proxy service.


-
TOR label displayed if the IP address hosts a TOR exit node according to Onionoo protocol data. Updated daily.
-
VPN label displayed if the scanner has detected a software of the corresponding category. Updated during scanning.
-
Proxy label displayed if the scanner has detected socks-proxy service. Updated during scanning.
IP to Organization
The Organization
field in the IP info view is a calculated property:
- By default it equals to
net.organization
field. - If
net.organization
is undefined, it equals tonet.description
. - If
net.description
is also undefined, it equals tonet.name
.
Threat Intelligence Data
Not available on the free plan
For an IP address or domain, threat intelligence records can also be displayed. This information is provided by our partners.
Netlas stores and displays IoCs (Indicators of Compromise) for the past year, so please take note of the date in the first column. Some IoCs may be reported as false positives; these will be marked with a special symbol in the last column. The IoCs data is updated daily.
Threat intelligence data is available only in the IP/Domain Info Tool.


Scan Results
Limited availability on the free plan
Display of scan results varies between IP addresses and domains:
-
For IP addresses, all available protocols are displayed, including HTTP requested by IP.
-
For domains, only the HTTP protocol scan results are displayed.
Tags and CVE data available starting from the Freelancer tier
Private Scan Results
Not available on the free plan
By default, IP/Domain Info tool shows the lates available data for requested IP address or domain name. The search is carried out in all the indexes available to you:
- Your indices produced by the Netlas Private Scanner
- Indices of your team matesб if you are a member of the team(s)
- Public Netlas indices, available to all Netlas users
To limit the search to public indexes only, click on "Switch to public data" link under the "Exposed Ports & Software" table.