Lookup API
IP intelligence. One API request.
Identify proxy providers, VPNs, and botnet infrastructure behind an IP or domain. Get observed behavior, device signatures, and a risk score for your fraud and abuse checks.
Tracking adversary
infrastructure.
Of all types.
Identify ISP and datacenter proxy providers, VPN services, and botnet networks across IPv4 and IPv6.
Explore the response schemaOne request. Connected context.
Resolve an IP or domain to network, location, behavior, and provider intelligence. Batch up to 1,000 addresses.
Name the infrastructure.
Move from an address to its proxy provider, ASN, organization, and network type.
See observed behavior.
Connect an address to observed activity and behavioral signals, with the timestamps behind them.
Prioritize the right signals.
Use a 0–100 risk score alongside the underlying evidence to inform your fraud and abuse checks.
The response,
field by field.
Provider names, device observations, risk scores, and last-seen timestamps. Query one address or batch up to 1,000.
200 OK · application/jsonResponse field reference
Who owns and operates the address.
- asn int
- Autonomous system number routing the address
- isp string
- Network operator name
- type string
- RESIDENTIAL, MOBILE, DATACENTER, CORPORATE, and more
- org / domain string | null
- Registered organization and reverse DNS domain
- abuse_email / abuse_phone string | null
- Published abuse contacts when available
Where the address resolves.
- country / state / city string
- Resolved geography for the address
- timezone string
- IANA timezone identifier
- latitude / longitude number
- Approximate coordinates
- geo_hash string
- Geohash bucket for coarse joins
What Synthient has observed.
- risk_score int 0-100
- Score derived from observed behavior
- behavior string[]
- Observed behavior signals
- categories string[]
- Network classifications such as RESIDENTIAL_PROXY
- devices object[]
- Device OS fingerprints with last_seen
- providers object[]
- Proxy and VPN provider attribution with last_seen
Go beyond
a proxy flag.
Identify who operates the exit, what activity was observed, and when it was last seen.
| Capability | Generic provider IP data + proxy flag | Synthient |
|---|---|---|
| Detection method | Low-confidence NetFlowProxy use inferred from traffic patterns | High-confidence indexingDirect observations of proxy infrastructure |
| Network identity | Residential · USASN, ISP & geolocation | Residential · USASN, ISP & geolocation |
| Provider attribution | proxy: trueNo named operator | |
| Behavior & risk | No behavior detail | Programmatic traffic87/100 Observed behavior alongside risk |
| Infrastructure coverage | Public reputation listsKnown, publicly listed services | Public + private networksISP proxies, datacenter proxies, VPNs & botnets |
| IPv6 visibility | IPv4-first coverageLimited visibility into IPv6 proxy networks | IPv4 + IPv6 intelligenceActive IPv6 proxy mapping alongside network signals |
| Device observations | No device context | Android 14Windows 11 OS, version & last seen |
| Observation time | No observation timestamps | Per-provider & per-device timestamps |
Try an IP lookup.
See the providers and risk signals associated with an IP address.