Data sources and fact classes
Different sources state different kinds of fact. n0.wiki sorts them into five classes that never stand in for one another: every field on a result page shows its class, its source and its confidence.
Five fact classes
| Class | Meaning | Examples |
|---|---|---|
| Registry | Records at the regional internet registries (RIRs), RDAP and IANA | Holder, registration country, allocation date |
| Routing | BGP routing and RPKI observations | Originating AS, announced prefix |
| Operator-declared | Statements published by the address operator | Cloud IP ranges, RFC 9632 geofeeds, iCloud Private Relay egress list |
| Measured | What we observe with our own probes | DNS leak, dual-stack exits, WebRTC candidates |
| Inferred | Judgements from databases or models | Geolocation, network type, VPN or not |
Operator-declared data has a key asymmetry: a hit is strong evidence, a miss proves nothing. An address missing from AWS's list does not show that it is not a datacenter.
Main sources
Registry and routing
RIR delegated stats, RDAP / IANA, RIPE NCC (RIPEstat), Team Cymru, PeeringDB.
Operator-declared
Published IP ranges of the major cloud providers, RFC 9632 geofeeds, Apple iCloud Private Relay egress list, the Tor Project exit list, and Google Public DNS prefixes (for the DNS leak test).
Geolocation and network type
DB-IP, MaxMind GeoLite2, IPinfo, IP2Location.io, ip-api.com, ipapi.is. Agreement between them only shows that the databases agree, not that they are right, which is why the dimension is called geo agreement.
Blocklists and threat intelligence
abuse.ch Feodo, FireHOL level1, IPsum, blocklist.de, CINS Army, GreenSnow, Emerging Threats, Pulsedive, and DNSBLs including SpamCop, PSBL, DroneBL, UCEPROTECT, s5h and Mailspike.
Abuse and fraud
AbuseIPDB, StopForumSpam, SANS ISC DShield, Scamalytics, IP2Proxy (via Scamalytics).
Anonymization and exposure
proxycheck.io, X4BNet VPN and datacenter lists, Shodan InternetDB, GreyNoise.
Privacy tiers: when third parties are asked
- Basic check (runs when the page opens): local databases plus registry and routing infrastructure such as RIPEstat, RDAP and Team Cymru.
- Deep check (only when you click it): your IP goes to third-party intelligence sources such as proxycheck, AbuseIPDB, ipapi.is, ip-api, StopForumSpam, DShield, several DNSBLs and Shodan. The page lists which third parties are involved before you click.
- Typing someone else's IP into the search box is a lookup you started, so it runs the deep check by default.
How fresh the data is
- Local blocklists, cloud IP ranges, RIR statistics and the RDAP bootstrap are checked every 6 hours, each source on its own schedule; if a download fails or shrinks abnormally, the old data is kept.
- Lists past their expiry are dropped at query time and no longer scored, rather than being used stale.
- Results for the same IP are cached in memory for up to 24 hours. The service restarts whenever data is updated, which clears the cache, so a result never outlives a data update. Results in which a source failed are cached for 90 seconds only.
How this turns into a score: scoring.