Skip to content

IP/Domain Info

IP/Domain Info tool provides a summary of Netlas data for a specific IP address or domain name. This tool supports queries by IP or domain only, but returns aggregated data from all Netlas data collections in a single response.

IP/Domain Info tool IP/Domain Info tool

Usage

Input a valid IP address or domain name to retrieve data.

Examples:

  • 1.1.1.1
  • google.com

Without an argument, the tool returns a summary for the requester's IP, allowing you to quickly assess your external IP by visiting Netlas app.

Contents

The tool returns different data for IPs and domains. The most majority of fields are optional.

Data availability depends on your pricing plan

For example, if your pricing plan does not provide you with access to contact details such as phone numbers and email addresses, this data will not be returned (displayed) by any of Netlas tools.

Anonymity Labels

Displayed next to the IP address are labels indicating if the IP is associated with a TOR exit node, a VPN, or a proxy service.

TOR / VPN / Proxy bages TOR / VPN / Proxy bages

  • TOR label displayed if the IP address hosts a TOR exit node according to Onionoo protocol data. Updated daily.

  • VPN label displayed if the scanner has detected a software of the corresponding category. Updated during scanning.

  • Proxy label displayed if the scanner has detected socks-proxy service. Updated during scanning.

IP to Organization

The Organization field in the IP info view is a calculated property:

  1. By default it equals to net.organization field.
  2. If net.organization is undefined, it equals to net.description.
  3. If net.description is also undefined, it equals to net.name.

Threat Intelligence Data

For an IP address or domain, threat intelligence records can also be displayed. This information is provided by our partners.

Netlas stores and displays IoCs (Indicators of Compromise) for the past year, so please take note of the date in the first column. Some IoCs may be reported as false positives; these will be marked with a special symbol in the last column. The IoCs data is updated daily.

Threat intelligence data is available only in the IP/Domain Info Tool.

Indicators of Compromise in Netlas Indicators of Compromise in Netlas

Scan Results

Display of scan results varies between IP addresses and domains:

  • For IP addresses, all available protocols are displayed, including HTTP requested by IP.

  • For domains, only the HTTP protocol scan results are displayed.

Scan results on IP address view Scan results on IP address view

Scan results on Domain view Scan results on Domain view

Tags and CVE data available starting from the Freelancer tier

Private Scan Results

By default, IP/Domain Info tool shows the lates available data for requested IP address or domain name. The search is carried out in all the indexes available to you:

  • Your indices produced by the Netlas Private Scanner
  • Indices of your team matesб if you are a member of the team(s)
  • Public Netlas indices, available to all Netlas users

To limit the search to public indexes only, click on "Switch to public data" link under the "Exposed Ports & Software" table.