What's New on WorldIP.io: Hosted Domains, a Domain DNS Timeline & Faster Pages
We've shipped a batch of upgrades across WorldIP.io over the past few weeks — new intelligence on every IP, a clearer way to read a domain's DNS history, and noticeably faster pages. Here's the rundown.
Every IP now shows the domains hosted on it
An IP page has always told you what an address is — its network, geolocation, routing, and reverse DNS. It now also shows what's hosted on it: the domains whose DNS points an A or AAAA record at that address. A shared-hosting or CDN IP might front hundreds of sites; a dedicated box might host one. That forward-DNS view is a dataset we don't collect ourselves, so we added it through a new data partnership with GRIP (General Research IP) — an internet-measurement project whose longitudinal forward-DNS data complements our own reverse-DNS sweep. Look for the new "Hosted domains" section on IP pages; the methodology and attribution are on our data sources page.
Spot VPNs, datacenters — and now residential proxies
Our VPN & proxy check has long told you whether an IP is easily identifiable as a VPN, datacenter or hosting address — the way streaming services and anti-fraud systems see it — from its network type, anonymizer blocklist hits, and reverse-DNS naming. The hard case was always the residential proxy: a real home or mobile connection that's been enrolled in a proxy network, quietly relaying other people's traffic. Because the address itself is genuinely residential, network-type and naming checks can't see it. Now we flag those too, drawing on GRIP's residential-proxy intelligence — so an ordinary-looking home IP that's proxying third-party traffic gets a clear "Residential proxy" tag right on its IP page, and the VPN check calls it out instead of waving it through as an ordinary connection.
Domain pages now read like a DNS timeline
The domain page lists every IP a domain has resolved to — forward and reverse — but it used to render a years-old record exactly like today's. If a site moved servers, its old addresses sat there looking like current, broken data. That's fixed:
- Current vs. historical. Forward A/AAAA records from the domain's most recent resolution are tagged current; superseded addresses are dimmed and labelled historical with the date they were last seen. A domain that moved off a CDN to its own origin now reads as accurate change history, not stale data.
- Active PTRs. Reverse (PTR) records — IPs whose reverse DNS points back at the domain — are marked active, instead of showing a blank where a "first seen" date would be. If we're tracking it, it's live.
- Grouped, active first. Everything currently in play — the live forward records and the active PTRs — is grouped at the top, with the historical records below. You see what's true now, then the history beneath it.
Pages load faster — from the edge
We moved page delivery onto a global edge cache. The IP, range, ASN and organization pages people reach for most are now served from a nearby edge location instead of a full round-trip to our origin on every request — so popular pages load near-instantly, and the backend stays lighter and steadier, which keeps the live lookups fast too.
Richer context on every network
We've also deepened the data on the pages around those lookups:
- Organizations & ASNs. ASN and organization pages now fold in PeeringDB and Wikidata — where a network peers and which internet exchanges it sits on, plus the operator's headquarters, founding date and corporate details. A bare AS number becomes a recognizable organization.
- Reputation & blocklists. IP pages now carry a reputation signal built from multiple public threat and blocklist feeds, so you can tell at a glance whether an address turns up on abuse or spam lists.
- Better coverage. We backfilled gaps in ASN and country data from additional public sources, so fewer lookups come back "unknown."
More is on the way. Explore the full toolbox under Tools, or jump straight to any IP, domain, or ASN to see it all in context.