Skip to content
InternetData
Tool

Reverse DNS Lookup

Enter an IPv4 or IPv6 address to get the hostname its PTR record names, where that name came from, and which of our databases hold the address. Every answer links to the address's full record.

One address at a time, IPv4 or IPv6.

Try

How reverse DNS works

Forward DNS turns a hostname into an address. Reverse DNS goes the other way: the address is written backwards under a domain kept for the purpose, and the PTR record found there names the host. IPv4 lives under in-addr.arpa, one label per octet; IPv6 under ip6.arpa, one label per hex digit, all 32 of them written out.

203.0.113.77.113.0.203.in-addr.arpa
2001:db8::77.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa
The name a resolver asks for each address's PTR record. Both addresses are from the ranges reserved for documentation, so neither has one.

Whoever runs the reverse zone for an address writes its PTR record: the network it belongs to, or a customer that network has handed the zone to. Nothing requires one and nothing checks it. Many addresses have none, and a name need not lead back to the address it came from; one that does is called forward-confirmed.

This tool reads IP RDNS first: the PTR records our internet-wide scans last saw, in a database rebuilt weekly. For an address it doesn't hold, the tool asks DNS directly and keeps the answer for up to an hour. Each result says which of the two answered.

What a hostname gives away

Unless a network hands the zone to its customer, the PTR record is the network's to write, so the name says whose network an address is on before it says anything else. Many cloud and hosting providers name servers under their own domains, as in Amazon EC2's ec2-3-80-0-5.compute-1.amazonaws.com, and many consumer ISPs name subscriber lines the same way, with the address spelled out and a word like res, cable or dynamic beside it.

So a hostname can tell a server from a subscriber at a glance. VPN exits run on servers, and an exit's PTR record can carry the name of the company hosting it, whichever VPN brand sells the connection; some VPN operators name their servers under their own domain instead.

It's a hint, not proof. The name is whatever the zone's owner wrote, and the proxies hardest to catch look the most ordinary: a residential proxy exit is someone's home connection, so its name reads like any subscriber's. That's why every lookup here lists which of our databases hold the address beside the name, and links to its full record.

On this page

What is a reverse DNS lookup?

An ordinary DNS lookup run backwards: it starts from an IP address and asks for the hostname that address points to. The answer is a PTR record, kept under in-addr.arpa for IPv4 and ip6.arpa for IPv6.

00 · Evaluate

Test the real build first.

An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.

01 · License

Then license what you use.

Standard, for detection and decisions inside your own product and operations.
Redistribution, when the data ships onward inside what you sell — priced by scope, not by seat.
Annual terms, a named contact, and flexible payment terms — monthly, quarterly or yearly.