Reverse DNS Lookup
Enter an IPv4 or IPv6 address to get the hostname its PTR record names, where that name came from, and which of our databases hold the address. Every answer links to the address's full record.
How reverse DNS works
Forward DNS turns a hostname into an address. Reverse DNS goes the other way: the address is written backwards under a domain kept for the purpose, and the PTR record found there names the host. IPv4 lives under in-addr.arpa, one label per octet; IPv6 under ip6.arpa, one label per hex digit, all 32 of them written out.
203.0.113.77.113.0.203.in-addr.arpa2001:db8::77.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpaWhoever runs the reverse zone for an address writes its PTR record: the network it belongs to, or a customer that network has handed the zone to. Nothing requires one and nothing checks it. Many addresses have none, and a name need not lead back to the address it came from; one that does is called forward-confirmed.
This tool reads IP RDNS first: the PTR records our internet-wide scans last saw, in a database rebuilt weekly. For an address it doesn't hold, the tool asks DNS directly and keeps the answer for up to an hour. Each result says which of the two answered.
What a hostname gives away
Unless a network hands the zone to its customer, the PTR record is the network's to write, so the name says whose network an address is on before it says anything else. Many cloud and hosting providers name servers under their own domains, as in Amazon EC2's ec2-3-80-0-5.compute-1.amazonaws.com, and many consumer ISPs name subscriber lines the same way, with the address spelled out and a word like res, cable or dynamic beside it.
So a hostname can tell a server from a subscriber at a glance. VPN exits run on servers, and an exit's PTR record can carry the name of the company hosting it, whichever VPN brand sells the connection; some VPN operators name their servers under their own domain instead.
It's a hint, not proof. The name is whatever the zone's owner wrote, and the proxies hardest to catch look the most ordinary: a residential proxy exit is someone's home connection, so its name reads like any subscriber's. That's why every lookup here lists which of our databases hold the address beside the name, and links to its full record.
No loose ends.
What is a reverse DNS lookup?
An ordinary DNS lookup run backwards: it starts from an IP address and asks for the hostname that address points to. The answer is a PTR record, kept under in-addr.arpa for IPv4 and ip6.arpa for IPv6.
Why does an address have no PTR record?
Nothing requires one. The network an address belongs to decides whether to publish a name for it, and many never do. No PTR record means DNS has no name for the address, not that nothing is using it.
Where does the hostname come from?
From our IP RDNS database when it holds the address: the PTR record our internet-wide scans last saw, rebuilt weekly. Otherwise from a live PTR query made for the lookup, whose answer is kept for up to an hour. Each result says which one answered.
Does a hostname prove an address is a VPN?
No. A PTR record says whatever the owner of its zone wrote, and nothing checks it. A hosting company's name is a strong hint that an address is a server; the databases listed beside it are what our own data says about the address.
Is there a limit?
Lookups here are free and need no account. Each one counts toward the same hourly allowance as every other address lookup on this site: past it you're asked to confirm you're a person, and later refused until the hour is up. The example addresses cost nothing. To name every address in your logs without a query each, license IP RDNS.
Test the real build first.
An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.