Skip to content
IP-001 IP Addresses & Networks
Pathway: I have been given an IP address

I’ve been told the offender came from an IP address. What do I do now?

Great question.

You’ve been told that the offender came from an IP address.

What do you actually do now?

First, let’s slow down.

And don’t start firing off requests just because somebody’s given you something that looks technical.

At its simplest, an IP address is part of the addressing information used when devices and online services communicate across a network.

When somebody logs in, sends something or connects to a service, the system at the other end may record the IP address it saw.

That can be a really useful starting point.

But it doesn’t automatically identify a person.

It doesn’t necessarily identify their device or their physical location either.

And even if you eventually get the name of a subscriber, that doesn’t prove that they were the person responsible.

So, before you do anything else, there are five questions we need to work through.

That’s what this IF Digital pathway is here to help you with.

Inside IF Digital, there are several different ways you can go next.

This isn’t a course that you have to work through from beginning to end.

You can choose the route that matches what you already understand, what information you’ve got and where you’ve reached in your enquiry.

You might need to start with the basic explanation.

You might need to go back and obtain missing information.

You might be ready to assess the evidence, carry out some initial checks or consider making a request.

Or you might already have a subscriber or account result and need to understand what it actually means.

We’ll signpost the relevant content as we work through the question.

So, the first question is: what have you actually been given?

Have you got the original record showing the IP address, the activity and the time?

Or has somebody simply copied an IP address into an email and sent it to you?

If it’s the second one, you may need to go back and ask for more information before you can sensibly do anything with it.

There’s a separate IF Digital card explaining exactly what should come with an IP address and what you should ask for if information is missing.

The second question is: can you evidence what the IP address allegedly did?

There’s a difference between somebody saying:

“The offender used this IP address.”

And a platform record showing:

“This account successfully logged in from this IP address at this time.”

Even that second example doesn’t identify the person responsible.

But it does tell us more clearly what the system actually recorded.

You need to understand whether you’re dealing with a login, a failed attempt, a message, an upload or simply a connection appearing in a log.

Don’t let the description of what happened become stronger than the evidence you’ve actually got.

The third question is: what sort of IP address are you dealing with?

There are different types of IP address and lots of different places they can lead.

It might point towards home broadband, a mobile network, a workplace, a hotel, a cloud service, a VPN or some other form of shared infrastructure.

Those different situations can lead to completely different enquiries.

Now, if none of that means anything to you yet, that’s absolutely fine.

You don’t need to be a network engineer to investigate an IP address properly.

The foundation material in this pathway will explain the bits you need, in plain English, before you move on.

The fourth question is: what can you establish before making a request?

Some straightforward open-source checks and a search of any relevant intelligence may help you understand what sort of service you’re dealing with and who might hold useful information.

Those checks probably won’t identify the offender.

What they can do is help you decide where to go next, what information might exist and whether making a request is actually worthwhile.

And that brings us to the fifth question.

What are you actually trying to find out?

Are you trying to identify the subscriber associated with an internet connection?

Are you trying to identify the account controlling some online infrastructure?

Are you looking to see whether several events are connected?

Is there an immediate safeguarding risk?

Or are you simply trying to decide whether the IP address is strong enough to justify doing anything else?

If you can’t explain the question you’re trying to answer, you may end up carrying out enquiries simply because an IP address looks like something that ought to be investigated.

That work may not be necessary, justifiable or proportionate to what you’re actually dealing with.

There’s also one warning that we’ll come back to throughout this pathway.

If a provider eventually gives you the name of a subscriber or account holder, that’s another stage in the enquiry.

It isn’t normally the end of it.

The subscriber is usually the person or organisation named on the service.

That doesn’t automatically make them the person who used the connection, controlled the device or carried out the activity.

So, where should you go next?

If you’ve been sent an IP address without its original context, start with the card explaining what information should come with it.

If you don’t yet understand what an IP address can identify, start with the foundation material.

If you’ve got the original record but you’re unsure what it actually proves, move into the evidence and logging section.

If you understand the record and want to know what can be established before making a request, move into the open-source and intelligence checks.

And if you’ve already received a possible subscriber or account-holder result, go straight to the section explaining what that result means and what should happen next.

If there’s an urgent risk, or you think relevant records may disappear, consider what can be preserved and escalated through your organisation’s processes while you work through the remaining questions.

The point of this pathway isn’t to turn you into a technical expert.

It’s to stop an IP address being turned into a suspect before the evidence has earned it.

We’ll help you work out what you’ve got, what it means and what you should do next.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.