Announced address space, by origin AS.
Every IPv4 and IPv6 range in the global routing table, attributed to the AS that originates it, with that network's name, domain and type, and whether RPKI validates the route.
Schema at a glance.
See documentation →The database's schema and metadata are documented carefully. It is published as CSVGZ and MMDB.
| start_ip | end_ip | prefix | asn | name | domain | type | country | rpki_status |
|---|---|---|---|---|---|---|---|---|
| 1.1.1.0 | 1.1.1.255 | 1.1.1.0/24 | 13335 | Cloudflare, Inc. | cloudflare.com | hosting | US | valid |
| 13.35.201.0 | 13.35.201.255 | 13.35.201.0/24 | 16509 | Amazon.com, Inc. | amazon.com | hosting | US | valid |
| 37.99.10.0 | 37.99.10.255 | 37.99.10.0/24 | 21299 | Kar-Tel LLC | beeline.kz | isp | KZ | not_found |
| 102.135.34.0 | 102.135.34.255 | 102.135.34.0/24 | 9009 | M247 Europe SRL | m247global.com | hosting | RO | invalid:origin |
| 2a01:4f8:: | 2a01:4f8:ffff:ffff:ffff:ffff:ffff:ffff | 2a01:4f8::/32 | 24940 | Hetzner Online GmbH | hetzner.com | hosting | DE | valid |
Downloading it from code.
Database API reference →One call gets you the current IP ASN build. Every official client wraps it three ways: straight to disk, a time-limited link you hand to your own runner, or bytes in memory. A file written to disk lands only once the whole transfer has arrived, and checksums() returns the published digests to verify it against.
download()downloadUrl()downloadBytes()metadata()checksums()import osfrom internetdata import InternetDataclient = InternetData(os.environ["INTERNETDATA_API_KEY"])# what is in today's build, without moving the filemeta = client.database.metadata("ip_asn_v1")client.database.download("ip_asn_v1", "mmdb", "./ip_asn_v1.mmdb")sums = client.database.checksums("ip_asn_v1", "mmdb")print(meta.updated, meta.entries, sums["sha256"])
Getting your hands on it.
The file is the product. Teams join IP ASN against traffic they already log, inside their own infrastructure, and never send an address anywhere to get an answer.
Traffic attribution
Group requests, flows and logs by the network they come from, down to the announced prefix.
Route security
Flag traffic from a range whose announcement RPKI marks invalid, the mark of a misconfiguration or a hijack.
An official client for every major language.
All SDKs on GitHub →Twelve official clients for the languages you ship in, each wrapping the database endpoints — list what you are licensed for, poll a build, follow the download redirect, verify what landed. Install commands are in the docs.
No loose ends.
How often does this database rebuild?
Daily, except IP RDNS and IP RWHOIS, which change weekly. The metadata call answers when the current build landed and how many rows it holds, before you fetch it.
Where does the data come from?
The five regional internet registries and the national ones, network operators' own RWHOIS servers, the global routing table, and our own scans of the address space. The documentation names the sources of each database.
Why is a contact field empty?
Because the registry does not publish it. Bulk registry data leaves out what privacy rules withhold, most often a personal contact's email, and a record carries only what its holder filed.
Which formats does a build ship in?
Gzipped CSV for all of them, and MMDB for IP ASN, IP Whois, IP RWHOIS and IP Abuse Contact. The schema section above names this one's.
Test the real build first.
An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.