Incident response
Paste a block of suspicious IPs from your SIEM or web server logs and see at a glance which ones belong to hosting providers, VPN exits, or residential ISPs in unexpected regions.
Query multiple IP addresses at once. Paste up to 20 IPs (one per line), then trace them all in a single click — results are exportable to CSV.
Up to 20 IPs, 5 concurrent lookups
| IP | Country | City | Coordinates | Status | Actions |
|---|---|---|---|---|---|
| No results yet. Paste some IPs above and hit Trace. | |||||
Checking IPs one at a time is painful when you're working through a log, an access list, or a firewall ruleset. The batch tool keeps each lookup independent while giving you a single sortable, exportable view.
Paste a block of suspicious IPs from your SIEM or web server logs and see at a glance which ones belong to hosting providers, VPN exits, or residential ISPs in unexpected regions.
Verify that the IPs in an allowlist or block list still resolve to the locations you expect before rolling out a change.
Cluster signup, comment, or checkout traffic by country in seconds instead of copy-pasting one IP at a time.