Skip to content
InternetData

Every host answering on the web's two ports.

Each address that answered a TLS handshake or an HTTP request on TCP port 443 or 80, with the certificate it presented (its names, issuer, validity and SHA-256 fingerprint, and whether it is self-signed or browser-trusted), the JA3S of its TLS handshake, and the status, Server header, redirect, cookie names and page title of its first response. A port that was open but never answered isn't in the file.

Request evaluation

Schema at a glance.

See documentation →

The database's schema and metadata are documented carefully. It is published as CSVGZ.

ipporttls_oksession_okstatus_codeserverlocationtitleset_cookie_namescert_subject_cncert_subject_ocert_issuer_dncert_sanscert_not_beforecert_not_aftercert_fp_sha256cert_self_signedcert_browser_trustedja3stls_versiontls_cipherhttp_versionfirst_seenlast_seen
3.96.111.7844311403awselb/2.0403 Forbiddenwelbi.hostC=US, O=Amazon, CN=Amazon RSA 2048 M04*.versions.welbi.host *.welbi.host welbi.host2025-11-262026-12-25a95efbc9c08135682c273fbe992c21fbad4b8f1e641783143e1492d7b594ba011f4febc55ea12b31ae17cfb7e614afda8TLSv1.3TLS_AES_128_GCM_SHA256HTTP/2.02026-07-272026-10-06
47.253.191.24344311200nginx/1.24.0 (Ubuntu)GSG-Tech Domain Updated | GSG-TechNEXT_LOCALEwww.xmgsgroup.comC=US, O=DigiCert Inc, OU=www.digicert.com, CN=RapidSSL TLS RSA CA G1www.xmgsgroup.com xmgsgroup.com2026-01-292027-01-28aac71a22da91e561811b6d1a3a2d36842717e370298d8db9b623db04d744e9ef115af977ce25de452b96affa2addb1036TLSv1.3TLS_AES_256_GCM_SHA384HTTP/1.12026-07-142026-10-05
163.172.175.8444311404TRAEFIK DEFAULT CERTCN=TRAEFIK DEFAULT CERTb102bf897b8e5c96318a582ab2773b6b.bcda50b5da922719fe1b66c6ec80d252.traefik.default2026-10-062027-10-06d5a99cf7a629007e9107c86c4c9b35856f8366633f72e4374e5941a0a1dec00d1475c9302dc42b2751db9edcac3b74891TLSv1.3TLS_CHACHA20_POLY1305_SHA256HTTP/2.02026-07-172026-10-03
38.59.242.153801308Caddyhttps://38.59.242.153/HTTP/1.12026-07-132026-10-02
51.38.39.174801200Apache/2.4.58 (Ubuntu)Apache2 Ubuntu Default Page: It worksHTTP/1.12026-07-122026-10-03
ID
web_ip_v1
Entries
56,332,585
Refresh
Weekly
CSVGZ
1.75 GB

Downloading it from code.

Database API reference →

One call gets you the current Web IP build. Every official client wraps it three ways: straight to disk, a time-limited link you hand to your own runner, or bytes in memory. A file written to disk lands only once the whole transfer has arrived, and checksums() returns the published digests to verify it against.

download()
Streams the current build to a file, which lands only once the whole transfer has arrived, so a failed one never leaves a truncated file behind.
downloadUrl()
The time-limited link the API redirects to, for your own downloader, a job runner or a CDN pull.
downloadBytes()
The build in memory, for a small database or a pipeline that never touches a filesystem.
metadata()
Row count, file sizes and when the build last updated. Poll it and fetch only when a new one has landed.
checksums()
The md5, sha1, sha256 and sha512 digests of one file, to verify it once it lands.
import os
from internetdata import InternetData
client = InternetData(os.environ["INTERNETDATA_API_KEY"])
# what is in today's build, without moving the file
meta = client.database.metadata("web_ip_v1")
client.database.download("web_ip_v1", "csvgz", "./web_ip_v1.csv.gz")
sums = client.database.checksums("web_ip_v1", "csvgz")
print(meta.updated, meta.entries, sums["sha256"])
load.pypip install internetdata
Also available for .NET, Ruby, Rust, Swift, Erlang, Perl and Zig. See all on GitHub →

Getting your hands on it.

The file is the product. Teams join Web IP against traffic they already log, inside their own infrastructure, and never send an address anywhere to get an answer.

Attack-surface audit

Find your own hosts answering on 443 and 80: expired and self-signed certificates, default pages, and admin panels that should never face the internet.

Infrastructure pivots

Group hosts by certificate fingerprint, by the names a certificate covers or by the JA3S of their TLS stack, to follow one operator's servers across addresses.

Brand monitoring

Search certificate names and page titles for your brand, and find the hosts presenting it that are not yours.

License the full database
Sales will quote on volume, term and whether you need redistribution rights.
Checksums published per file — md5, sha1, sha256 and sha512.
The id fixes the schema, so a new build never changes the columns your parser reads.
Samples are cut from the current build, not a synthetic extract.

An official client for every major language.

All SDKs on GitHub →

Twelve official clients for the languages you ship in, each wrapping the database endpoints — list what you are licensed for, poll a build, follow the download redirect, verify what landed. Install commands are in the docs.

On this page

Why are the TLS columns empty on some rows?

A row on port 80 is plain HTTP, with no TLS handshake, so tls_ok, every cert_ column, ja3s, tls_version and tls_cipher are empty there. On 443 they're filled whenever the handshake completed.

00 · Evaluate

Test the real build first.

An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.

Request evaluation
01 · License

Then license what you use.

Standard, for detection and decisions inside your own product and operations.
Redistribution, when the data ships onward inside what you sell — priced by scope, not by seat.
Annual terms, a named contact, and flexible payment terms — monthly, quarterly or yearly.