Skip to content
IP-015 IP Addresses & Networks

Where did this IP address come from?


title: "Where did this IP address come from?" card_id: "IP-015" status: "complete" source_document: "https://docs.google.com/document/d/1dVL28wRxL3ut8zb33ZrmvllppZUlXBvQApUshhzMMUQ/edit?usp=drivesdk"


Where did this IP address come from?

Before you interpret an IP address, establish where it came from.

An IP address without its source has very little meaning.

It might have come from a platform login record.

A website or application log.

An email header.

A router or firewall.

A device.

An intelligence report.

A screenshot supplied by somebody else.

Or an IP address copied into an email without any of its original context.

Those aren’t equivalent sources.

A platform login record may show the IP address that the platform recorded when somebody accessed an account.

A router or firewall may record addresses involved in traffic passing through a network.

That could include public addresses, private addresses, source addresses and destination addresses.

A device log might show the address assigned to the device itself, the address of another system it connected to or an address used by part of an application.

An email header may contain several IP addresses belonging to mail servers involved in delivering the message.

Those addresses don’t automatically identify the device or connection used by the sender.

An intelligence report may tell you that an address has previously been associated with a service, account or type of activity.

That doesn’t prove that the same association existed during the event you’re examining.

And if somebody has simply pasted an address into an email or report, you may not know what the original system recorded at all.

The same IP address can therefore mean very different things depending on where it appears.

You need to identify the system or record that produced it.

You also need to understand which field you’re looking at.

Was it recorded as the source of a connection?

Was it the destination?

Was it assigned to a local device?

Was it taken from an email relay?

Was it supplied by the user or observed by the system?

Or was it added later as intelligence or commentary?

The label matters.

A field called “IP address” isn’t enough by itself.

Before moving on, you should be able to complete this sentence:

“This IP address was recorded by this system, in this type of record, in connection with this event.”

If you can’t complete that sentence, go back to whoever supplied the address and ask where it came from.

At this stage, don’t strengthen the description to fill the gaps.

Don’t call it the offender’s IP address.

Don’t assume it came from their device.

And don’t assume it represents their physical location.

Describe it according to what you actually know.

For example:

“The platform recorded this IP address during a successful login to the account.”

Or:

“This address appears in a firewall record as the source of a connection.”

Or, if the source remains unclear:

“This IP address was supplied in relation to the event, but its original source hasn’t yet been established.”

Once you know where the address came from, you can ask the next questions.

Do you have the original record?

What could the recording system actually see?

And what activity does the record show?

But establish the source first.

Until you know where the IP address came from, you don’t yet know what it represents.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.