API documentation

A JSON API over HTTPS for IP addresses, AS numbers, networks and organisations. No SDK needed.

Base URL: https://ip-fd.net/api/v1. All responses are JSON encoded as UTF-8. Cross-origin requests are allowed, so the API can be called from a browser.

Authentication

Requests work without a key at a low rate. For higher limits, create a key on the API keys page and send it in a header:

curl -H "X-API-Key: ipfd_your_key" https://ip-fd.net/api/v1/ip/193.0.6.139

Authorization: Bearer ipfd_your_key works as well. Passing the key as ?key= is supported but not recommended, because URLs end up in logs.

Rate limits

  • Without a key: 100 requests per minute per IP address.
  • With a free key: 500 requests per minute and 10,000 requests per day.
  • After the daily quota is used up, the key falls back to the anonymous limit until midnight UTC.

Every response carries RateLimit and RateLimit-Policy headers. A 429 response means you should wait before retrying. Need more? Contact us.

Errors

Errors use standard HTTP status codes and a JSON body with an error message:

HTTP/1.1 404 Not Found
{ "error": "AS4294967200 is not in our registry data." }

400 invalid input, 401 invalid key, 403 suspended account, 404 not found, 429 rate limited, 5xx server error.

All endpoints

Lookups answer from our stored data and never call other services while you wait, so responses are fast and predictable. Single fields such as /me/ip or /ip/{address}/city return plain text (add ?format=json for JSON).

Your own address

GET/api/v1/me
Full lookup of the address you call from. Try
GET/api/v1/me/ip
Only your IP address, as plain text. Add ?format=json for JSON. Try
GET/api/v1/me/country
Your country code (also country-name, region, city, coordinates). Try
GET/api/v1/me/city
Your city. Try
GET/api/v1/me/asn
Your AS number (also as-name, org, network, route). Try
GET/api/v1/me/location
Your location as JSON with accuracy and source. Try
GET/api/v1/me/{field}
Any single field, see the list below.

IP address

GET/api/v1/ip/{address}
Full lookup: registration, routing, RPKI, location, flags and abuse contact. Try
GET/api/v1/ip/{address}/{field}
One field: ip, version, country, country-name, region, city, coordinates, location, asn, as-name, org, network, route, netname, description, registry, abuse, flags, rpki, hosting, vpn, tor, proxy. Try
GET/api/v1/ip/{address}/history
Changes to the holder, routing, RPKI state and location of the /24 or /48. Try
GET/api/v1/ip/{address}/reputation
Spamhaus ZEN listing and AbuseIPDB reports we already have (no live AbuseIPDB call). Try
GET/api/v1/ip/{address}/reputation/stream
All 18 DNS blocklists, streamed as Server-Sent Events.
GET/api/v1/ip/{address}/abuseipdb
Stored AbuseIPDB result for the address, if any.
POST/api/v1/bulk
Many addresses in one request (25 without a key, 500 with a key): {"ips": ["1.1.1.1", ...]}.

AS numbers

GET/api/v1/asn/{asn}
Holder, prefixes, neighbours, RPKI, health and WHOIS. Try
GET/api/v1/asn/{asn}/prefixes
Announced IPv4 and IPv6 prefixes with counts. Try
GET/api/v1/asn/{asn}/neighbours
Upstreams, downstreams and peers (also /upstreams, /downstreams, /peers). Try
GET/api/v1/asn/{asn}/graph
Upstreams and their upstreams, as nodes and edges. Try
GET/api/v1/asn/{asn}/health
Network health score, grade and checks. Try
GET/api/v1/asn/{asn}/rpki
RPKI state per announced prefix. Try
GET/api/v1/asn/{asn}/changes
Prefix and neighbour changes in the last 30 days. Try
GET/api/v1/asn/{asn}/whois
Registry record as text. Try
GET/api/v1/asn/{asn}/name
Display name, plain text (also /country). Try

Networks, organisations and domains

GET/api/v1/network/{prefix}
Registry network with parents, children and origin. Try
GET/api/v1/org/{handle}
Organisation with its AS numbers and networks. Try
GET/api/v1/domain/{name}
Addresses, mail, name servers, SPF, DMARC and CAA of a domain. Try
GET/api/v1/search?q={name}
AS numbers and organisations by name. Try

Countries, routing and RPKI

GET/api/v1/countries
Address space and AS numbers per country. Try
GET/api/v1/country/{code}
One country with its largest networks. Try
GET/api/v1/rpki/validate?asn={asn}&prefix={prefix}
RFC 6811 origin validation. Try
GET/api/v1/outages
Current and recent routing outages of the largest networks per country. Try
GET/api/v1/status
Service status and data freshness. Try

DNS and web tools

GET/api/v1/tools/propagation?name={domain}&type={type}
A record on 21 public resolvers worldwide. Try
POST/api/v1/tools/email-headers
Analyze email headers: {"headers": "Received: ..."}. Hops, networks, delays, SPF, DKIM, DMARC.
POST/api/v1/tools/prefix
Prefix tools: {"action": "aggregate|range|ipv6|reverse", "input": "..."}.
POST/api/v1/dnsleak
Start a DNS leak test: returns names to look up.
GET/api/v1/dnsleak/{token}
Resolvers that looked up the test names, with their networks.
GET/api/v1/status-page/{slug}
Public status page of a user as JSON.
POST/api/v1/dns/lookup
DNS records: {"domain": "example.com", "type": "MX"}.
POST/api/v1/dns/mail
MX, SPF and DMARC check: {"domain": "example.com"}.
POST/api/v1/tools/ssl
TLS certificate: {"hostname": "example.com"}.
POST/api/v1/tools/http-headers
HTTP response headers: {"url": "https://example.com"}.
POST/api/v1/tools/blacklist
All DNS blocklists for one IPv4 address: {"ip": "192.0.2.10"}.
POST/api/v1/tools/subnet
Subnet calculator: {"cidr": "10.0.0.0/22"}.
POST/api/v1/tools/geofeed-check
Validate a geofeed: {"url": "https://..."} or {"content": "..."}.

Your account (API key required)

GET/api/v1/account/blocklists
Your blocklist watches with current listings.
POST/api/v1/account/blocklists
Watch an address: {"target": "192.0.2.10", "label": "Mail"}.
DELETE/api/v1/account/blocklists/{id}
Stop watching.
GET/api/v1/account/bgp/watches
Your BGP watches.
POST/api/v1/account/bgp/watches
Watch an AS or prefix: {"target": "AS3333"} or {"target": "193.0.0.0/21", "allowed_origins": "3333"}.
DELETE/api/v1/account/bgp/watches/{id}
Stop watching.
GET/api/v1/account/bgp/events
Open alerts and the last 30 days.
GET/api/v1/account/status-page
Your status page settings.
POST/api/v1/account/status-page
Save it: {"enabled": true, "slug": "acme", "title": "Acme status", "monitors": [1, 2]}.
POST/api/v1/account/weekly-report
Turn the weekly report on or off: {"enabled": true}.

IP address

GET/api/v1/ip/{address}

Accepts an IPv4 or IPv6 address, or a hostname (resolved to its first address). Returns registration, routing, location and abuse data.

{
  "ip": "193.0.6.139",
  "version": 4,
  "found": true,
  "hostname": "www.ripe.net",
  "network": {
    "prefix": "193.0.0.0 - 193.0.7.255",
    "cidrs": ["193.0.0.0/21"],
    "first": "193.0.0.0", "last": "193.0.7.255", "size": "2048",
    "netname": "RIPE-NCC", "country": "NL",
    "status": "ASSIGNED PA", "org_id": "ORG-RIEN1-RIPE",
    "registry": "RIPE", "updated": "2026-09-30T00:00:00.000Z"
  },
  "delegation": { "registry": "RIPE", "country": "NL", "block": "193.0.0.0 - 193.0.7.255" },
  "asn": { "asn": 3333, "name": "RIPE-NCC-AS", "route": "193.0.0.0/21", "country": "NL" },
  "organisation": { "id": "ORG-RIEN1-RIPE", "name": "Reseaux IP Europeens Network Coordination Centre (RIPE NCC)", "country": "NL" },
  "abuse": { "handle": "ops4-ripe", "email": "abuse@ripe.net" },
  "rpki": { "state": "valid", "reason": "ROA 193.0.0.0/21 allows AS3333 up to /21" },
  "location": {
    "country": "NL", "region": "North Holland", "city": "Amsterdam",
    "latitude": 52.374, "longitude": 4.8897,
    "accuracy": "city", "confidence": "medium",
    "source": "ipmap", "sourceLabel": "RIPE IPmap measurement",
    "candidates": [ ... ]
  },
  "queryTimeMs": 41
}

Your address

GET/api/v1/me

Same response as the IP endpoint for the address the request came from. Add ?format=text to get only the address as plain text.

AS number

GET/api/v1/asn/{asn}

Holder, country, registry, announced IPv4 and IPv6 prefixes, upstreams, downstreams and peers. The number can be given with or without the AS prefix.

Network

GET/api/v1/network/{prefix}

A registry record by CIDR (193.0.0.0/21), range (193.0.0.0-193.0.7.255) or single address. Includes parent allocations, up to 250 more specific assignments, announced routes and a WHOIS style text block.

Organisation

GET/api/v1/org/{handle}

An organisation by its registry handle, for example ORG-RIEN1-RIPE, with its AS numbers and up to 500 networks.

Domain

GET/api/v1/domain/{domain}

Addresses with their provider, location and RPKI state, mail servers, name servers, SPF, DMARC and CAA.

History

GET/api/v1/ip/{address}/history

Changes we recorded for the /24 (or /48) of an address: network, holder, origin AS, RPKI state and location, with the first and last time each state was seen.

Bulk lookup

POST/api/v1/bulk

Look up to 100 addresses per request (500 with an API key). Each address counts as one request against your quota. Live checks such as reverse DNS are skipped to keep the call fast.

curl -X POST https://ip-fd.net/api/v1/bulk \
  -H "Content-Type: application/json" -H "X-API-Key: ipfd_your_key" \
  -d '{"ips": ["193.0.6.139", "2001:67c:2e8:22::c100:68b"]}'

Reputation

GET/api/v1/ip/{address}/reputation

Live Spamhaus ZEN listing and, when configured, the AbuseIPDB confidence score. IPv4 only.

DNS and web checks

POST/api/v1/dns/lookup { "domain": "example.com", "type": "MX" }
POST/api/v1/dns/mail { "domain": "example.com" }
POST/api/v1/tools/ssl { "hostname": "example.com" }
POST/api/v1/tools/http-headers { "url": "https://example.com" }
POST/api/v1/tools/blacklist { "ip": "192.0.2.10" }
POST/api/v1/tools/subnet { "cidr": "10.0.0.0/22" }

Location fields

location.source tells you where the answer came from. Sources are tried in this order and the first one that names a city is used:

  • override: a correction we made after a verified report.
  • geofeed: the network operator's RFC 8805 geofeed.
  • geoloc: coordinates in the registry object.
  • rule: a rule we maintain for a network that publishes no geofeed.
  • ipmap: a RIPE IPmap measurement based on RIPE Atlas latency.
  • rdns: a city or airport code in the reverse DNS name.
  • registry_text: a city named in the netname or description.
  • cloud: the region list published by AWS, Google Cloud or Oracle.
  • org_address: the registered address of the holder (same country only).
  • atlas: our own RIPE Atlas latency measurement, used when nothing else names a city.
  • country: only the registry country is known.

accuracy is city, region or country. confidence is high, medium, low or country. candidates lists every source that returned something. More on the data page.

Privacy flags

Every IP response has a flags object. Each flag is null or an object with evidence and confidence: listed (the address is on a published list), likely or estimate.

  • tor: a Tor exit node (Tor Project exit lists, refreshed every 30 minutes).
  • vpn: a VPN server, with provider. Listed from the server lists of Mullvad, NordVPN, Private Internet Access, AirVPN, IVPN and Surfshark; likely from VPN reverse DNS names.
  • proxy: an open proxy seen in the last 7 days.
  • relay: an iCloud Private Relay egress address.
  • hosting: a hosting or cloud network.
  • anonymous: true when any of tor, vpn, proxy or relay is set.

No list is complete. A missing flag means the address is not on any list we know, not that it is a regular connection.

Legacy endpoints

The old endpoints /api/ip/{address}, /api/asn/{asn}, /api/range/{prefix}, /api/dns/* and /api/tools/* keep working with their previous response format. New integrations should use /api/v1.