FIRST-PARTY IP ATTRIBUTION

Most of your alerts
are just business.

CDNs, update servers, public DNS, SaaS APIs and monitoring probes generate a constant stream of traffic that looks like activity and almost never is. SourceIP tells you which operator an address belongs to, so your analysts spend their time on the rest.

300+
providers tracked

300 Million
IPv4 addresses
7% ipv4 space

1037
IPv6 addresses
3% ipv6 space
Try it
Why this is different
Traceable

Every range has a source

Ranges come from the operator's own published lists such as a provider config, an SPF record, a documented API endpoint. Nothing is inferred from traffic observation.

Graded

Trust levels, documented

A match on a provider's own control plane means something different from a match on infrastructure they rent to customers. SourceIP grades that difference explicitly instead of flattening it into one score.

Reviewed

Reviewed by hand, provider by provider

Every provider in the dataset has been through an analyst's hands before it reaches yours. Every source checked against the operator's own domain, ownership confirmed, edge cases split out rather than lumped together. Our judgment is the product.

Lookup record
GET /v1/lookup?ip=8.8.8.8200
PROVIDERGoogle Public DNSCIDR8.8.8.8/32CATEGORYpublic_dnsTRUSTTRUSTED
Trust levels
LevelMeaningTag
1The provider directly operates the service (e.g., API endpoints, DNS, software delivery, or control-plane infrastructure published by the operator itself).TRUSTED
2Ownership is known, but the provider supplies infrastructure to customers or third parties, so activity is not attributable to the provider itself.SHARED INFRASTRUCTURE
0Descriptive context only — the match provides information without serving as a basis for trust or distrust decisions.INFORMATIONAL
-1Important to label, but a match must not imply benign behaviour, accountability, or allow-list suitability.UNTRUSTED

SourceIP is an attribution dataset. A trust level describes what a match means. Only our TRUSTED level should be used for whitelisting. The others are for context and should be treated as advisory.

Coverage
CategoryProviders
cloud89
saas35
security29
monitoring27
bot20
software15

300+ providers across 20 categories. Ask about coverage for a service you depend on.