API documentation
A JSON API over HTTPS for IP addresses, AS numbers, networks and organisations. No SDK needed.
Base URL: https://ip-fd.net/api/v1. All responses are JSON encoded as UTF-8. Cross-origin requests are allowed, so the API can be called from a browser.
Authentication
Requests work without a key at a low rate. For higher limits, create a key on the API keys page and send it in a header:
curl -H "X-API-Key: ipfd_your_key" https://ip-fd.net/api/v1/ip/193.0.6.139
Authorization: Bearer ipfd_your_key works as well. Passing the key as ?key= is supported but not recommended, because URLs end up in logs.
Rate limits
- Without a key: 100 requests per minute per IP address.
- With a free key: 500 requests per minute and 10,000 requests per day.
- After the daily quota is used up, the key falls back to the anonymous limit until midnight UTC.
Every response carries RateLimit and RateLimit-Policy headers. A 429 response means you should wait before retrying. Need more? Contact us.
Errors
Errors use standard HTTP status codes and a JSON body with an error message:
HTTP/1.1 404 Not Found
{ "error": "AS4294967200 is not in our registry data." }
400 invalid input, 401 invalid key, 403 suspended account, 404 not found, 429 rate limited, 5xx server error.
All endpoints
Lookups answer from our stored data and never call other services while you wait, so responses are fast and predictable. Single fields such as /me/ip or /ip/{address}/city return plain text (add ?format=json for JSON).
Your own address
| GET | /api/v1/meFull lookup of the address you call from. Try |
| GET | /api/v1/me/ipOnly your IP address, as plain text. Add ?format=json for JSON. Try |
| GET | /api/v1/me/countryYour country code (also country-name, region, city, coordinates). Try |
| GET | /api/v1/me/cityYour city. Try |
| GET | /api/v1/me/asnYour AS number (also as-name, org, network, route). Try |
| GET | /api/v1/me/locationYour location as JSON with accuracy and source. Try |
| GET | /api/v1/me/{field}Any single field, see the list below. |
IP address
| GET | /api/v1/ip/{address}Full lookup: registration, routing, RPKI, location, flags and abuse contact. Try |
| GET | /api/v1/ip/{address}/{field}One field: ip, version, country, country-name, region, city, coordinates, location, asn, as-name, org, network, route, netname, description, registry, abuse, flags, rpki, hosting, vpn, tor, proxy. Try |
| GET | /api/v1/ip/{address}/historyChanges to the holder, routing, RPKI state and location of the /24 or /48. Try |
| GET | /api/v1/ip/{address}/reputationSpamhaus ZEN listing and AbuseIPDB reports we already have (no live AbuseIPDB call). Try |
| GET | /api/v1/ip/{address}/reputation/streamAll 18 DNS blocklists, streamed as Server-Sent Events. |
| GET | /api/v1/ip/{address}/abuseipdbStored AbuseIPDB result for the address, if any. |
| POST | /api/v1/bulkMany addresses in one request (25 without a key, 500 with a key): {"ips": ["1.1.1.1", ...]}. |
AS numbers
| GET | /api/v1/asn/{asn}Holder, prefixes, neighbours, RPKI, health and WHOIS. Try |
| GET | /api/v1/asn/{asn}/prefixesAnnounced IPv4 and IPv6 prefixes with counts. Try |
| GET | /api/v1/asn/{asn}/neighboursUpstreams, downstreams and peers (also /upstreams, /downstreams, /peers). Try |
| GET | /api/v1/asn/{asn}/graphUpstreams and their upstreams, as nodes and edges. Try |
| GET | /api/v1/asn/{asn}/healthNetwork health score, grade and checks. Try |
| GET | /api/v1/asn/{asn}/rpkiRPKI state per announced prefix. Try |
| GET | /api/v1/asn/{asn}/changesPrefix and neighbour changes in the last 30 days. Try |
| GET | /api/v1/asn/{asn}/whoisRegistry record as text. Try |
| GET | /api/v1/asn/{asn}/nameDisplay name, plain text (also /country). Try |
Networks, organisations and domains
| GET | /api/v1/network/{prefix}Registry network with parents, children and origin. Try |
| GET | /api/v1/org/{handle}Organisation with its AS numbers and networks. Try |
| GET | /api/v1/domain/{name}Addresses, mail, name servers, SPF, DMARC and CAA of a domain. Try |
| GET | /api/v1/search?q={name}AS numbers and organisations by name. Try |
Countries, routing and RPKI
| GET | /api/v1/countriesAddress space and AS numbers per country. Try |
| GET | /api/v1/country/{code}One country with its largest networks. Try |
| GET | /api/v1/rpki/validate?asn={asn}&prefix={prefix}RFC 6811 origin validation. Try |
| GET | /api/v1/outagesCurrent and recent routing outages of the largest networks per country. Try |
| GET | /api/v1/statusService status and data freshness. Try |
DNS and web tools
| GET | /api/v1/tools/propagation?name={domain}&type={type}A record on 21 public resolvers worldwide. Try |
| POST | /api/v1/tools/email-headersAnalyze email headers: {"headers": "Received: ..."}. Hops, networks, delays, SPF, DKIM, DMARC. |
| POST | /api/v1/tools/prefixPrefix tools: {"action": "aggregate|range|ipv6|reverse", "input": "..."}. |
| POST | /api/v1/dnsleakStart a DNS leak test: returns names to look up. |
| GET | /api/v1/dnsleak/{token}Resolvers that looked up the test names, with their networks. |
| GET | /api/v1/status-page/{slug}Public status page of a user as JSON. |
| POST | /api/v1/dns/lookupDNS records: {"domain": "example.com", "type": "MX"}. |
| POST | /api/v1/dns/mailMX, SPF and DMARC check: {"domain": "example.com"}. |
| POST | /api/v1/tools/sslTLS certificate: {"hostname": "example.com"}. |
| POST | /api/v1/tools/http-headersHTTP response headers: {"url": "https://example.com"}. |
| POST | /api/v1/tools/blacklistAll DNS blocklists for one IPv4 address: {"ip": "192.0.2.10"}. |
| POST | /api/v1/tools/subnetSubnet calculator: {"cidr": "10.0.0.0/22"}. |
| POST | /api/v1/tools/geofeed-checkValidate a geofeed: {"url": "https://..."} or {"content": "..."}. |
Your account (API key required)
| GET | /api/v1/account/blocklistsYour blocklist watches with current listings. |
| POST | /api/v1/account/blocklistsWatch an address: {"target": "192.0.2.10", "label": "Mail"}. |
| DELETE | /api/v1/account/blocklists/{id}Stop watching. |
| GET | /api/v1/account/bgp/watchesYour BGP watches. |
| POST | /api/v1/account/bgp/watchesWatch an AS or prefix: {"target": "AS3333"} or {"target": "193.0.0.0/21", "allowed_origins": "3333"}. |
| DELETE | /api/v1/account/bgp/watches/{id}Stop watching. |
| GET | /api/v1/account/bgp/eventsOpen alerts and the last 30 days. |
| GET | /api/v1/account/status-pageYour status page settings. |
| POST | /api/v1/account/status-pageSave it: {"enabled": true, "slug": "acme", "title": "Acme status", "monitors": [1, 2]}. |
| POST | /api/v1/account/weekly-reportTurn the weekly report on or off: {"enabled": true}. |
IP address
Accepts an IPv4 or IPv6 address, or a hostname (resolved to its first address). Returns registration, routing, location and abuse data.
{
"ip": "193.0.6.139",
"version": 4,
"found": true,
"hostname": "www.ripe.net",
"network": {
"prefix": "193.0.0.0 - 193.0.7.255",
"cidrs": ["193.0.0.0/21"],
"first": "193.0.0.0", "last": "193.0.7.255", "size": "2048",
"netname": "RIPE-NCC", "country": "NL",
"status": "ASSIGNED PA", "org_id": "ORG-RIEN1-RIPE",
"registry": "RIPE", "updated": "2026-09-30T00:00:00.000Z"
},
"delegation": { "registry": "RIPE", "country": "NL", "block": "193.0.0.0 - 193.0.7.255" },
"asn": { "asn": 3333, "name": "RIPE-NCC-AS", "route": "193.0.0.0/21", "country": "NL" },
"organisation": { "id": "ORG-RIEN1-RIPE", "name": "Reseaux IP Europeens Network Coordination Centre (RIPE NCC)", "country": "NL" },
"abuse": { "handle": "ops4-ripe", "email": "abuse@ripe.net" },
"rpki": { "state": "valid", "reason": "ROA 193.0.0.0/21 allows AS3333 up to /21" },
"location": {
"country": "NL", "region": "North Holland", "city": "Amsterdam",
"latitude": 52.374, "longitude": 4.8897,
"accuracy": "city", "confidence": "medium",
"source": "ipmap", "sourceLabel": "RIPE IPmap measurement",
"candidates": [ ... ]
},
"queryTimeMs": 41
}
Your address
Same response as the IP endpoint for the address the request came from. Add ?format=text to get only the address as plain text.
AS number
Holder, country, registry, announced IPv4 and IPv6 prefixes, upstreams, downstreams and peers. The number can be given with or without the AS prefix.
Network
A registry record by CIDR (193.0.0.0/21), range (193.0.0.0-193.0.7.255) or single address. Includes parent allocations, up to 250 more specific assignments, announced routes and a WHOIS style text block.
Organisation
An organisation by its registry handle, for example ORG-RIEN1-RIPE, with its AS numbers and up to 500 networks.
Domain
Addresses with their provider, location and RPKI state, mail servers, name servers, SPF, DMARC and CAA.
History
Changes we recorded for the /24 (or /48) of an address: network, holder, origin AS, RPKI state and location, with the first and last time each state was seen.
Bulk lookup
Look up to 100 addresses per request (500 with an API key). Each address counts as one request against your quota. Live checks such as reverse DNS are skipped to keep the call fast.
curl -X POST https://ip-fd.net/api/v1/bulk \
-H "Content-Type: application/json" -H "X-API-Key: ipfd_your_key" \
-d '{"ips": ["193.0.6.139", "2001:67c:2e8:22::c100:68b"]}'
Reputation
Live Spamhaus ZEN listing and, when configured, the AbuseIPDB confidence score. IPv4 only.
DNS and web checks
Location fields
location.source tells you where the answer came from. Sources are tried in this order and the first one that names a city is used:
override: a correction we made after a verified report.geofeed: the network operator's RFC 8805 geofeed.geoloc: coordinates in the registry object.rule: a rule we maintain for a network that publishes no geofeed.ipmap: a RIPE IPmap measurement based on RIPE Atlas latency.rdns: a city or airport code in the reverse DNS name.registry_text: a city named in the netname or description.cloud: the region list published by AWS, Google Cloud or Oracle.org_address: the registered address of the holder (same country only).atlas: our own RIPE Atlas latency measurement, used when nothing else names a city.country: only the registry country is known.
accuracy is city, region or country. confidence is high, medium, low or country. candidates lists every source that returned something. More on the data page.
Privacy flags
Every IP response has a flags object. Each flag is null or an object with evidence and confidence: listed (the address is on a published list), likely or estimate.
tor: a Tor exit node (Tor Project exit lists, refreshed every 30 minutes).vpn: a VPN server, withprovider. Listed from the server lists of Mullvad, NordVPN, Private Internet Access, AirVPN, IVPN and Surfshark; likely from VPN reverse DNS names.proxy: an open proxy seen in the last 7 days.relay: an iCloud Private Relay egress address.hosting: a hosting or cloud network.anonymous: true when any of tor, vpn, proxy or relay is set.
No list is complete. A missing flag means the address is not on any list we know, not that it is a regular connection.
Legacy endpoints
The old endpoints /api/ip/{address}, /api/asn/{asn}, /api/range/{prefix}, /api/dns/* and /api/tools/* keep working with their previous response format. New integrations should use /api/v1.