Free IP intelligence datasets
11 live feeds mirrored from authoritative upstream sources (Tor Project, Mullvad, AWS, Google Cloud, Oracle, DigitalOcean, Fastly, Cloudflare, FireHOL, Spamhaus) plus 5 IPLogs-curated reference datasets. Stable URLs, CC-BY 4.0, auto-refreshed. No signup, no API key.
Live upstream feeds(11)
Mirrored from authoritative sources with stable Cache-Control. Build scripts can point here instead of hammering upstream.
Tor exit nodes
Every IPv4 currently listed as a Tor exit relay. Sourced directly from the Tor Project's signed exit-addresses feed, refreshed hourly. Use this to flag, contextualise, or block Tor-originated traffic.
ipstring · IPv4 exit addresspublishedISO8601last_statusISO8601seen_atISO8601
- · Fraud gating on checkout and signup
- · SOC / SIEM enrichment
- · Academic replication studies
185.220.101.1,2026-04-23T10:00:00Z,2026-04-23T11:00:00Z,...
Tor relays (all, not just exits)
Every running Tor relay on the network (guards, middles, bridges, exits), with fingerprint, nickname, IPv4 and IPv6 addresses. Sourced from the Tor Project's Onionoo consensus API.
fingerprintstringnicknamestringipv4stringipv6string
- · Network research (relay distribution studies)
- · Mapping entire Tor network footprint
- · Bridge discovery analysis
Mullvad WireGuard relays
Every active Mullvad VPN relay with hostname, country, city, provider, IPv4, IPv6, type, ownership flag. Direct passthrough from api.mullvad.net, refreshed every 6 hours. Canonical dataset for Mullvad exit detection.
hostnamestringcountry_codestringcountrystringcitystringipv4stringipv6stringproviderstringtypewireguard | openvpn | bridgeactive0 | 1owned0 | 1
- · Mullvad exit detection
- · Research on WireGuard deployment patterns
AWS IP ranges
Amazon's full published ip-ranges.json, mirrored with a stable Cache-Control so you don't have to hit ip-ranges.amazonaws.com directly from build scripts. Includes every AWS region and service (EC2, CloudFront, Route53), IPv4 and IPv6.
prefixes[]object with ip_prefix, region, service
- · AWS traffic classification
- · CloudFront origin allowlist
- · Cloud-region analytics
Google Cloud IP ranges
Google Cloud Platform's canonical IP range publication (cloud.json), mirrored with stable caching. Covers every GCP region, service, and scope (PREMIUM/STANDARD tier).
prefixes[]object with ipv4Prefix/ipv6Prefix, scope, service
- · GCP traffic classification
- · Allowlisting legitimate Google-originating traffic
Oracle Cloud IP ranges
Oracle Cloud Infrastructure's published IP range JSON, documented at docs.oracle.com. Every OCI region with CIDR blocks and service tags.
regions[]object with region, cidrs[]
- · OCI traffic classification
- · Enterprise allowlisting
DigitalOcean IP ranges
DigitalOcean's published geo-annotated CIDR list. Each row carries the CIDR plus country / region / city geolocation of the datacenter. Mirrored with a CSV header row we added for convenience.
cidrstringcountryISO 3166-1 alpha-2regionstringcitystringpostal_codestring
- · Flagging droplet-originated traffic
- · Geo-aware fraud rules
Fastly IP ranges
Fastly CDN's official public IP range API. Used to allowlist legitimate Fastly-delivered traffic or to detect traffic originating from Fastly compute.
addresses[]IPv4 CIDRipv6_addresses[]IPv6 CIDR
- · CDN allowlisting
- · WAF bypass for Fastly-origin traffic
Cloudflare IP ranges
Canonical Cloudflare IPv4 and IPv6 ranges (published at cloudflare.com/ips), mirrored with a stable Cache-Control so your build scripts don't hammer Cloudflare directly.
cidrone CIDR per line, IPv4 then IPv6
- · Reverse-proxy allowlist
- · WAF bypass of Cloudflare-origin traffic
FireHOL Level 1 threat aggregate
FireHOL's Level 1 blocklist: a curated aggregate of the highest-signal threat feeds (Spamhaus DROP/EDROP, DShield top attacking, attacker honeypot feeds). Minimal false positives. CC-BY 4.0 licensed.
cidrone CIDR per line; comments start with #
- · Edge-firewall blocklist
- · Threat intel enrichment
- · SOC rule feed
Spamhaus DROP (Don't Route or Peer)
Networks controlled by criminal enterprises, hijacked IP ranges, and known-malicious prefixes. Published by Spamhaus multiple times per day. Free for defensive use; one of the most respected threat-intel feeds in the industry.
cidr ; SBL-refone CIDR + ; + Spamhaus Block List reference per line
- · Border-router ACL
- · Threat intel enrichment
- · Hijack-prefix detection
IPLogs curated reference data(5)
Our own classification tables used by the detection pipeline. Smaller than the upstream feeds but carry per-entry descriptions and signal metadata.
Datacenter and CDN ASNs
IPLogs-curated catalogue of autonomous systems we classify as datacenter hosting or CDN. Used internally by the detection pipeline's dc_ip signal. Smaller than the upstream cloud-provider feeds but has per-ASN descriptions and categorisation.
asnstringnamestringcountrystringcategorydatacenter | cdndescriptionstring
- · Bot defence allow/deny lists
- · Traffic classification in analytics
- · Compliance reporting
AS15169,Google LLC,US,datacenter,Google Cloud Platform…
Commercial VPN ASNs
Autonomous systems officially registered to commercial VPN providers or confirmed as partner hosting infrastructure (NordVPN, Mullvad + parent, ProtonVPN, PIA, ExpressVPN, CyberGhost, VyprVPN, Opera VPN, M247, Trabia, Datacamp, and others). Any IP routed through one of these ASNs is a confirmed VPN exit without needing a probe.
asnstringnamestringcountrystringdescriptionstring
- · High-confidence VPN classification
- · Fraud rule engines
- · Regional licensing compliance
AS212238,NordVPN,PA,NordVPN officially registered ASN...
Residential-proxy backbone ASNs
26 hosting ASNs known to host residential-proxy infrastructure (Leaseweb family, ColoCrossing, M247, Performive, Hivelocity, HostPapa and others). Matches the residential_proxy_backbone signal used in the detection pipeline.
asnstringnamestringcountrystring
- · Residential-proxy heuristic enrichment
- · Bot defence (scraping prevention)
- · Ad-fraud click auditing
AS60781,Leaseweb Netherlands B.V.,NL
VPN provider catalogue
31 commercial and self-host VPN providers with jurisdiction, registered ASN, protocols, and which detection signals flag them.
slugstringnamestringjurisdictionstringasnstring · when registeredprotocolssemicolon-separateddetected_bysemicolon-separated signal namesdescriptionstring
- · Per-provider detection policy
- · Licensing and jurisdiction review
Country IP context
73 countries with dominant residential ISPs, hosting footprint, known VPN provider presence, and regional notes. Useful for geo-risk scoring and regional compliance.
codeISO 3166-1 alpha-2namestringregionstringnotesstring
- · Geo-risk scoring
- · Regional bot-defence policy
- · Compliance mapping
Licensing and attribution
IPLogs-curated datasets are released under CC BY 4.0. Live feeds retain their upstream license (Tor Project, Mullvad, Spamhaus DROP free for defensive use, FireHOL CC-BY 4.0, the cloud-provider ranges are published openly by their respective providers). Mirroring exists for caching convenience, not republishing.
Suggested citation: IPLogs (2026). {Dataset name}. https://iplogs.com/tools
Prefer a live lookup?
The same classifications behind these datasets back the live detection API at POST https://iplogs.com/v1/check. Pass any IPv4, get verdict, score, confidence, and every signal that produced the reading.