ASN, WHOIS, and ownership records correlated across all five regional internet registries to baseline every routed network.
Continuous internet-wide port and protocol fingerprinting identifies VPN appliances, OpenVPN listeners, WireGuard, and SOCKS exits that public data alone misses.
We observe residential-proxy exit IPs and attribute each to its operating network, re-enumerated continuously — the signal scan-based methods structurally miss.
Proprietary network-telemetry signals corroborate residential and mobile proxy IPs that look like normal traffic and stay invisible to active scans.
Commercial and corporate VPN endpoints.
Hosted proxy infrastructure.
Per-IP provider attribution where available.
Carrier attribution where applicable.
Tor network exit nodes from the current consensus.
Cloud and CDN tenancy that should not appear as a residential endpoint.
Per-request live lookups, batched calls up to 100 IPs, and full bulk exports for analytics workloads.
For real-time classification and provider attribution at signup, checkout, and content-moderation decision points.
Up to 100 IPs per call for fraud and risk pipelines processing burst traffic.
CSV, MMDB, and Parquet for analytics. MMDB drops into existing MaxMind-compatible toolchains. Parquet is available on Business plans, where competitors gate it at the enterprise custom level.
Block account takeover and payment fraud at signup by flagging residential and datacenter proxy IPs commonly used for credential stuffing and synthetic identity creation.
Add proxy / VPN signal to KYC pipelines, content moderation, and review-system integrity. Filter automated signups and policy-evasion attempts.
Map customer attack surface and quantify exposure. Detect corporate VPN appliances and identify high-risk infrastructure tenancy in underwriting workflows.
Verify customers are where they claim to be for licensing, pricing, and compliance. Detect VPN-based geo-evasion.
Identify residential and datacenter proxies fronting automated scrapers and AI agents so you can rate-limit or challenge non-human traffic.
Embed VPN and proxy classification, provider attribution and a risk score directly into your platform with one integration.
It is an API that takes an IP address and tells you whether it belongs to a VPN, proxy, Tor exit, or hosting provider, along with provider attribution, recency, a risk score and a confidence value. You can use it for real-time proxy detection at signup, checkout, or any decision point.
Most stop at public ASN data. We observe residential-proxy exit IPs directly and attribute each to its operating network, with NetFlow corroboration — surfacing residential and mobile proxies that scan-based methods miss.
The data is refreshed continuously. Residential proxy IPs churn rapidly — roughly 90% of any pool rotates within 6 days — so we re-enumerate hourly on the high-churn tiers. Bulk exports are regenerated daily.
The API covers IPv4 today. IPv6 coverage is on the roadmap.
Yes. CSV exports are included from the Pro plan, and full MMDB and Parquet exports are included on Business plans, via /api/v1/export/{csv,mmdb,parquet}. MMDB files drop into existing MMDB-compatible toolchains.
Send the IP to the lookup endpoint. If it is an anonymous IP behind a VPN, proxy, or Tor exit, the response flags the type and returns the supporting evidence.
Yes. Start with the real-time API, then migrate to bulk databases or feeds as volumes grow, with the same consistent formats throughout.
Yes. Pair it with IP Geolocation API, IP Netblocks API, and Threat Intelligence API to add location, network-ownership and threat context from one provider.
















Find out the exact physical location of any IP address, email or domain name.
Learn more
Get the most relevant data to be ahead of emerging security threats.
Learn more
Assess the domain's or IP addresses reputation and risk profile with a simple score based on a comprehensive...
Learn more
Find domains and subdomains related by specific terms in their hostnames.
Learn more
Find out which domains were added or dropped by registrants, with given search criteria.
Learn more
Get well-parsed and normalized WHOIS information for any domain name, IP address or email.
Learn more
Give the list of domain names tied to the specified DNS records via API calls with outputs in JSON and XML.
Learn more
Get the most comprehensive database of SSL (Secure Sockets Layer) Certificates.
Learn more
Get data feeds of new registered domains along with their WHOIS data generated in real time.
Learn more
Get data feeds of SSL certificates along with their well parsed fields in real time. Accurate. Up-to-date.
Learn more
Monitor exact matches, variations and common misspellings of your brand name & trademarks.
Learn more
Get insights for the new business registered on the web.
Learn more
Enhance your domain research toolkit by our enterprise-grade web-based solution that helps you in searching...
Learn more
Easily detect all typosquatting domain names as soon as they are registered each day.
Learn more
We provide complete and relevant domain WHOIS data which can be customized and easily integrated as per your business needs.
Learn more
Easily identify malicious resources and retrieve their threat information.
Learn more