Skip to main content

IPinfo Max

Every flagged IP is directly observed operating as a proxy exit, confirmed by behavior rather than an ASN or hostname guess. Max bundles geolocation, privacy detection, residential proxy, carrier, and connection context in one API. Sign up and start querying the same day.

{
"ip": "1.1.1.1",
"hostname": "one.one.one.one",
"geo": {
"city": "Brisbane",
"region": "Queensland",
"region_code": "QLD",
"country": "Australia",
"country_code": "AU",
"continent": "Oceania",
"continent_code": "OC",
"latitude": -27.4679,
"longitude": 153.0281,
"timezone": "Australia/Brisbane",
"postal_code": "9010",
"geoname_id": "2174003",
"radius": 50,
"last_changed": "2026-01-04"
},
"place": {},
"as": {
"asn": "AS13335",
"name": "Cloudflare, Inc.",
"domain": "cloudflare.com",
"type": "hosting",
"last_changed": "2021-05-01"
},
"mobile": {},
"anonymous": {
"is_proxy": false,
"is_relay": false,
"is_tor": false,
"is_vpn": false,
"is_res_proxy": false
},
"is_place": false,
"is_anonymous": false,
"is_anycast": true,
"is_hosting": true,
"is_mobile": false,
"is_satellite": false
}

Self-serve from day one

Sign up, generate a token, and start detecting. No minimum contract, no procurement queue, no demo gate.

Named proxy providers

See the specific provider behind an IP, like 711Proxy or ProxyScrape, instead of an anonymous flag, with coverage deep into the long tail.

Recency and frequency

last_seen and percent_days_seen show how recently and how consistently an IP acted as a proxy.

Why Choose IPinfo Max?

Every IP in our residential proxy dataset was directly observed operating inside a proxy network. Membership rests on observed behavior alone: if it's in the dataset, we saw it act as a proxy exit. That is what makes it a signal you can automate on.

Observed in the act

Every IP was seen acting as a residential proxy exit, held to a strict definition of genuinely residential, with mobile and datacenter sub-segments broken out per provider.

Behavior over time

An IP seen once three months ago and one active every day carry very different risk. last_seen and percent_days_seen ship with every IP so you can tell them apart.

Provider attribution

Each IP is tied to the operator running it, with mobile and datacenter pools flagged, so you can weigh a residential exit differently from the same operator's datacenter traffic.

What's Included in IPinfo Max

Sample Response

$curl https://api.ipinfo.io/lookup/1.1.1.1?token=$TOKEN
{
"ip": "1.1.1.1",
"hostname": "one.one.one.one",
"geo": {
"city": "Brisbane",
"region": "Queensland",
"region_code": "QLD",
"country": "Australia",
"country_code": "AU",
"continent": "Oceania",
"continent_code": "OC",
"latitude": -27.4679,
"longitude": 153.0281,
"timezone": "Australia/Brisbane",
"postal_code": "9010",
"geoname_id": "2174003",
"radius": 50,
"last_changed": "2026-01-04"
},
"place": {},
"as": {
"asn": "AS13335",
"name": "Cloudflare, Inc.",
"domain": "cloudflare.com",
"type": "hosting",
"last_changed": "2021-05-01"
},
"mobile": {},
"anonymous": {
"is_proxy": false,
"is_relay": false,
"is_tor": false,
"is_vpn": false,
"is_res_proxy": false
},
"is_place": false,
"is_anonymous": false,
"is_anycast": true,
"is_hosting": true,
"is_mobile": false,
"is_satellite": false
}

Available Data Fields

Field NameDescription
hostnameThe reverse DNS hostname for the IP address.
geo.cityThe city name.
geo.regionThe region or state name.
geo.region_codeThe region or state code.
geo.countryThe country name.
geo.country_codeThe two-letter country code (ISO 3166-1 alpha-2).
geo.continentThe continent name.
geo.continent_codeThe two-letter continent code.
geo.latitudeThe latitude coordinate.
geo.longitudeThe longitude coordinate.
geo.timezoneThe IANA timezone for the location.
geo.postal_codeThe postal or ZIP code.
IPinfo Places

Need Places as a data file?

The IPinfo Max API response above returns IPinfo Places, the venue behind an IP address: hotels, airports, stadiums, train stations and more. As a file, it's a custom offering, built to the coverage and format you need. Our team will scope it with you.

CiscoMicrosoftDockerGoogleDataDogSnowflakeOpenAIAnthropic

Unrivaled data accuracy

Verified IP Accuracy. Not Estimates.

Most IP providers stop at noisy Whois and geofeeds. IPinfo goes further. We don’t just collect IP data — we verify it, validate it, and engineer it for developers.

They guess. We measure. And that makes all the difference.

Step 1: Collect & Clean

Like most IP data companies, we aggregate raw IP data from multiple sources as a starting point.

Step 2: Learn

Our proprietary algorithms then score and filter 20TB+ of IP data daily to measure accuracy and confidence.

Step 3: ProbeNet Ground Truth

1000+ live PoP’s map IPs around the world in real time, delivering unmatched ground-truth accuracy.

Step 4: Validate

A custom hint engine runs 400B+ weekly checks to verify and confirm every signal for total accuracy.

Step 5: Continual Updates

IP’s change continually… so our data refreshes daily to keep every lookup accurate, stable, and production-ready.

Fast and Easy API Access

Start using our fast & easy API right away. Setup takes only a few minutes.

  • 50-200 ms response time on average
  • 99.999% uptime
  • Data updates every 24 hours
  • Bank grade security

Custom Database Download

Leverage raw IP datasets, customize your data feeds, and choose your ideal format.

  • Available in CSV, MMDB, JSON and Parquet
  • Customizable fields
  • Data updates every 24 hours
  • Bank grade security

Catch the Traffic Other Checks Miss

Fraud Prevention

Flag transactions masked through residential proxies while trusted users pass straight through.

Traffic Quality

Filter proxy-based traffic so campaign analytics and engagement data reflect real visitors.

Threat Intelligence

Surface proxy infrastructure used to hide the origin of malicious activity during investigations.

To explore more, check out our full list of use cases.

We feed in a single IP address and get back location, privacy flags like Tor usage, and company or abuse contacts. That has been huge for kicking out malicious logins. In our first week, we caught someone logging in from Kentucky, but the abuse contact was based in Shanghai. This client had zero business in Asia, so we kicked them out in under 200 seconds—far faster than a typical SOC, which can take tens of minutes to hours. We later discovered it was a Russian hacker trying to transfer money. Thanks to IPinfo's data, we were able to stop it within about 90 seconds.

Jake ReynoldsCo-Founder / CTO at Wirespeed

We feed in a single IP address and get back location, privacy flags like Tor usage, and company or abuse contacts. That has been huge for kicking out malicious logins. In our first week, we caught someone logging in from Kentucky, but the abuse contact was based in Shanghai. This client had zero business in Asia, so we kicked them out in under 200 seconds—far faster than a typical SOC, which can take tens of minutes to hours. We later discovered it was a Russian hacker trying to transfer money. Thanks to IPinfo's data, we were able to stop it within about 90 seconds.

Jake ReynoldsCo-Founder / CTO at Wirespeed

We feed in a single IP address and get back location, privacy flags like Tor usage, and company or abuse contacts. That has been huge for kicking out malicious logins. In our first week, we caught someone logging in from Kentucky, but the abuse contact was based in Shanghai. This client had zero business in Asia, so we kicked them out in under 200 seconds—far faster than a typical SOC, which can take tens of minutes to hours. We later discovered it was a Russian hacker trying to transfer money. Thanks to IPinfo's data, we were able to stop it within about 90 seconds.

Jake ReynoldsCo-Founder / CTO at Wirespeed

Made for Developers, Trusted by Enterprises

Our expert in-house team diligently maintains and supports IPinfo Max, ensuring you always have accurate, up-to-date IP data at your fingertips. With libraries for more than a dozen popular programming languages—from Ruby to Rust and PHP to Perl—integrating our API is quick and seamless. Explore our developer docs to see just how easy it is to get started.

PHP
Spring
Python
Node.js
Ruby
Django
C#
Rails
Java
Express
Swift
Laravel
Go
Rust
Perl
Erlang

Employ Our Data on Other Leading Platforms

Our API integrations merge the power of IPinfo’s proprietary IP data with other industry-leading cloud platforms. Use your IP data at scale with our supported integrations, such as Snowflake, Splunk, GCP, and more.

Google Cloud
Splunk
Zapier
Palo Alto Networks
Snowflake
Heroku
Wordpress
Datadog

Get started With IPinfo Max

Query it live over the API, self-serve today, or run the whole dataset inside your own infrastructure. Same signals either way.

Start at 250k Requests

Scale as you need—no hidden fees, and flexible tiers to match your growth.

Provider Attribution

service names the operator running the IP, with mobile and datacenter pools broken out.

Recency

last_seen gives the date the IP was most recently observed as a proxy exit.

Frequency

percent_days_seen gives how consistently it appeared across the observation period.

Detailed Privacy Service Definitions

Identify VPNs, Tor, proxies and relays including the exact provider when detectable.

Precision-Radius Geolocation

City, region and country data with kilometer-level accuracy.

ASN & Geo Change Tracking

Spot freshly reassigned blocks by checking the last-changed timestamps for both location and ASN.

Daily Data Refresh

Leverage our continuously refreshed IP data for the most accurate insights.

Custom IP Data Solutions For Your Enterprise

Need more than a million monthly requests or specialized IP data? Our Enterprise team is here to help. We’ll tailor a plan to your exact needs—whether you require custom data fields, an OEM relationship, database downloads or dedicated support.

  • High-Volume API Requests
  • Bespoke Data Combinations
  • OEM Partnerships
  • Database Downloads

Your Questions, Answered

  • What is a residential proxy?
    A residential proxy routes traffic through a real IP address assigned by an ISP (Internet Service Provider), often a home connection. Because the IP looks like an ordinary user, it gets past detection built only for VPNs, hosting ranges, and datacenter proxies.
  • How is Max different from Privacy Detection?
    Privacy Detection covers VPNs, Tor, public proxies, and relays. Max is a separate dataset built specifically for residential proxies, which are the hardest of the group to catch.
  • What does percent_days_seen tell me?
    It's the share of recent days an IP was observed acting as a residential proxy. Pair it with last_seen to judge whether a sighting is fresh and persistent or stale and occasional.
  • How quickly can I start?
    Same day. You sign up, upgrade to Max, and start querying straight away.
  • Can I get the data as a database download?
    The API is the fastest way to start. Talk to us about database access for higher-volume, offline-matching needs.
  • How fresh is the data?
    The dataset refreshes every 24 hours, so a node that goes quiet drops out of recent activity quickly.