Look up an autonomous system.
Enter an AS number or any IP address. You get the organisation behind the network, how much of it we have observed, and what share of that observed traffic turned out to be abusive.
AS15169
Google LLC
Of the 25,099 addresses we have observed on this network, 13,125 are flagged abusive, which is 52%. That is high enough that traffic from this network deserves scrutiny by default.
Organisation
Google LLC
Addresses observed
25,099
Flagged abusive
13,125 (52%)
Proxy or VPN share
8%
These figures describe the addresses we have observed on this network, not every address it holds, and they are a statement about observed traffic rather than about the operator. Full profile for AS15169.
Pre-filled with a large, well-known network. Enter an AS number such as AS15169, or just paste an IP address and we will find its network for you.
Behind every check
19.8 million
IP addresses profiled
2.4 million
malicious domains tracked
208,000
disposable email domains
1.9 million
networks scored
Counts read live from the engine, not written into the page. The full dataset is published on GitHub under the MIT license and rebuilt every 30 minutes.
What an ASN is
An autonomous system is a block of the internet under one routing policy, identified by a number, and it is the unit networks actually announce routes in. That makes it the right altitude for a question individual addresses cannot answer. One abusive address is an incident. A network where most of the addresses you have ever seen were abusive is a pattern, and the two justify very different responses.
What the lookup returns
The organisation
Who announces the network. Frequently a hosting company, a national carrier, or a cloud provider rather than a name you recognise from the address.
Addresses observed
How many addresses on this network we hold data for. This is what we have seen, never a claim about the size of the allocation.
Share flagged abusive
What proportion of those observed addresses carry confirmed abuse. This is the number that actually distinguishes networks.
Proxy and VPN share
How much of the observed space is anonymising infrastructure. A very high share on a small network is close to a definition of a proxy provider.
Reading the abuse ratio honestly
The ratio is observed abuse over observed addresses, and both halves deserve care. We see more of a network when it sends us more traffic, and the traffic that reaches a fraud-intelligence sensor is not a random sample of what a network carries, so a consumer broadband provider with millions of ordinary customers and a small hosting company can both show elevated ratios for completely different reasons. A high figure on a large, well-known carrier usually reflects scale and shared addressing rather than a badly run network. A high figure on a small network whose observed space is almost entirely proxies is a different statement. This is a measurement of what we saw, not a judgment about an operator, and the published dataset carries the same wording for the same reason.
Using it
Deciding how much to trust an address
The network an address sits in is context the address alone does not carry. A clean address inside overwhelmingly abusive space deserves more scrutiny than its own record suggests.
Finding who to contact
Abuse handling happens at the network operator. Identifying the autonomous system tells you which organisation actually has the power to disconnect a customer.
Understanding blocks at scale
If traffic from a whole region or provider is failing, the answer is usually at network level rather than address level.
Four networks, and how to read them.
Live results, fetched as this page loaded. These are chosen to show why the abuse ratio must be read next to the sample size.
AS60729
100% flagged
TORSERVERS-NET · 766 addresses observed
A small network whose observed addresses are effectively all flagged. When a network exists to run Tor exits, the ratio simply reports that.
AS16509
91% flagged
Amazon.com, Inc. · 616,648 addresses observed
The number that most needs reading carefully. A very large cloud provider shows a high ratio because the traffic reaching a fraud sensor from cloud space is overwhelmingly automated, not because the operator is bad.
AS13335
55% flagged
Cloudflare, Inc. · 60,484 addresses observed
A major CDN and DNS provider. Shared infrastructure at enormous scale, where one address fronts a great many unrelated customers.
AS15169
52% flagged
Google LLC · 25,099 addresses observed
Another large provider where the observed sample skews hard toward automation. Read the ratio next to the sample size, never on its own.
Every verdict above was fetched from the engine when this page loaded. Nothing here is a screenshot or a stored example, so if a number looks surprising, that is what our data actually says right now.
Questions people ask
What is an ASN lookup?
It is finding out which autonomous system, meaning which routed network, an address or AS number belongs to, and who operates it. Enter either an AS number such as AS15169 or an IP address above; if you give an address we resolve it to its network first, so you do not need to know which one you are holding.
How do I find the ASN for an IP address?
Paste the address into the box above. We look up which autonomous system announces it and then return that network's profile, including the operator and the share of observed addresses carrying confirmed abuse.
What is a good abuse ratio for a network?
There is no single threshold, and anyone offering one is oversimplifying. Large consumer carriers routinely show elevated figures because of scale and shared addressing, while a small hosting network with a high ratio and a high proxy share is a far stronger signal. Read the ratio together with the size of the observed sample and the proxy share rather than on its own.
Does a high abuse ratio mean the network operator is bad?
No, and we are careful not to say that. The figure describes traffic we observed from addresses on that network. Operators of very large networks cannot police every customer, and address sharing puts many unrelated users behind one address. It is a signal about traffic, not a judgment about a company, and if you believe a figure is wrong we would rather hear it than have it stay wrong.
Can I download the network reputation data?
Yes. The networks whose observed traffic was overwhelmingly abusive are published as a CSV on GitHub under the MIT license, alongside the much larger confirmed-abusive IP file, rebuilt every 30 minutes.
Other free tools
Free IP lookup
Owner, network, autonomous system, reverse DNS, and approximate location for any address.
Reverse DNS lookup
Find the PTR record for any address, the network behind it, and what the hostname gives away.
IP reputation
A 0 to 100 fraud score for any IP address, with every signal that produced it shown in the open.
Do it in code.
The same answer from a free API endpoint, or download the whole database and never call an API at all. No card, no quota, no expiry.