Skip to content
Skip to main content
IP Addresses & Networks Foundation explainer
Pathway: I have been given an IP address

What is an IP address?

An IP address is simply addressing information used to move data across an IP network. It helps networks deliver data to the right connection and send a response back. For an investigator, a recorded IP address can identify a network connection or the next organisation to ask - but it is not a person's, or even a device's, permanent digital name.

The short version
An IP address describes a connection as seen in a particular technical context. This is why its investigative meaning depends on the event, time, recording system and route taken by the traffic.
Corrected visual benchmark โ€” review version

What is an IP address?

This version retains the calibration script and Hazel placeholder narration while testing the corrected shared visual system. Its creative treatment remains unreviewed.

Open or download the corrected benchmark MP4 if inline playback does not work. Open the preserved original pilot.

Start with the investigation record

In the online-fraud walkthrough, a retailer supplies an activity record associated with a completed checkout:

SystemRetailer platform
EventCompleted checkout
Time14:36:42.318 UTC
Observed address198.51.100.27
Retailer activity record
2026-06-18T14:36:42.318Z   checkout_complete   request_id=7F3A91account_id=884219   source_ip=198.51.100.27   source_port=49152   status=success
The record supports

The retailer's system associated this checkout with a particular account, request, time, source IP address and source port. Those details allow the event to be checked against other records rather than treated as an isolated address.

It does not establish

The record does not by itself identify the person who acted, the physical device used or who was responsible for the fraud. This is because several people or devices may share an address, an address may change, and an intermediary may be what the retailer actually saw.

What the address gives usA line of enquiry: preserve the event and ask the likely network or record holder what the address represented at that time.

An IP address has its main investigative use as part of a recorded event. Copied out on its own - as just a bunch of numbers with dots or colons between them - it loses the time, system and activity that give it meaning.

How an IP address helps move data

Information travelling across an IP network is divided into small units called IP packets. Each packet combines addressing information with a portion of the data being carried so that networks can move it towards its destination.

1A connection sends dataThe packet carries source and destination addresses.
2Networks route itRouters use the destination address to move it onwards.
3A service receives itThe service may record the source address visible to it.
An IP packet divided into a header containing source and destination addresses and a payload containing the data being carried.
The header provides addressing information. The payload carries the relevant part of the webpage, message, image or other data.
  • The destination IP address tells routers where the packet is intended to go, so they can move it towards the receiving network.
  • The source IP address is the source presented in that packet, so responses can be directed back towards it.
  • The payload carries the relevant data, such as part of a webpage, message, image or other content.

Routers can therefore forward a packet without needing to understand its payload. The source address eventually recorded by an online service may still be changed or presented by translation or an intermediary elsewhere in the route, which is why the observation point matters to an investigation.

IPv4 and IPv6 are two address formats

The internet currently uses two versions of IP. They perform the same broad addressing job but write their addresses differently, so investigators need to recognise both when checking and comparing records.

IPv4198.51.100.27

Four decimal numbers separated by dots.

IPv62001:db8:4::27

A longer address using hexadecimal characters and colons.

The retailer's value is therefore an IPv4 address. Recognising the format helps validate and research the value, but the format does not reveal who used it.

A device or service may use IPv4, IPv6 or both. Two different-looking addresses do not automatically mean two different devices or people were involved, because one connection can use both address formats.

Go deeper into address formats

Public and private addresses answer different questions

A device inside a home or workplace commonly uses a private IP address. The same private ranges can be reused in millions of unrelated local networks, so a value such as 192.168.1.24 cannot normally identify an internet subscriber on its own. In theory, a device in every house on a street could use that same address without any conflict, because each use is contained inside its own local network.

When the device communicates with an internet service, its router normally uses Network Address Translation (NAT) to represent that local traffic using a public IP address. The private address stays meaningful only inside the home or workplace network; the public address is the one normally presented to the internet service. This is why a retailer's address may identify the household or organisation's internet connection without identifying the particular device inside it.

PrivateDevice192.168.1.24
TranslationRouter using NATSeveral local devices may share one public address.
PublicOnline service198.51.100.27
A device with a private IP address passing through a router using NAT, across the internet, to an online service that records the public IP address.
The retailer records what is visible at its end of the connection. The device may use a different private address inside the local network.

Why one address does not mean one device - or one person

Shared household

Several phones, computers and other devices can use one public address through the same router. The address alone cannot select the device or person involved.

Shared provider address

Carrier-Grade NAT can place several customers behind one public IPv4 address. An IP address and time may therefore be insufficient to select one customer.

Changing address

A provider may reallocate an address, and a phone may change address between Wi-Fi and mobile data. The holder now may not be the holder at the event time.

Intermediary

A VPN, proxy or Tor exit can become the source visible to the destination service. The address may lead to that intermediary rather than the user's ordinary connection.

In a shared-address system, the public IP address and timestamp may not be enough to distinguish one customer's connection. The source port and protocol should also be preserved whenever the recording system has them, because the provider may need those fields to separate simultaneous users of the same address. Whether an address is static or dynamic matters for the same reason: it affects what the provider must match at the event time.

The practical consequence

One public IP address can represent several devices - and sometimes several customers. One device can also use several IP addresses over time. This is why an IP match is a connection lead, not proof of a person or device.

The observation point controls what is visible

A system records the address visible from its own position in the connection path. That address might be associated with:

  • home or business broadband;
  • a mobile network;
  • workplace, hotel or public Wi-Fi;
  • a server or hosting service;
  • shared provider infrastructure; or
  • an intermediary such as a VPN, proxy or Tor exit.

These possibilities matter because the same user's activity can produce different visible addresses at different points in the route, and the final service may see an intermediary rather than the user's earlier connection.

Ask before interpreting the addressWhich system recorded it, where was that system in the route, and what did the field mean there?

If traffic passes through a VPN, the online service normally sees the VPN exit address because the VPN makes the onward connection. If a retailer receives traffic through a reverse proxy, its records must preserve the correct original source field because the immediate network connection may otherwise appear to come from the proxy. The recorded address remains potentially useful, but it may identify a point in the route rather than the user's ordinary connection.

Choose the explanation that matches the record

What an IP address can contribute

It may help
  • identify the likely network or record holder;
  • match an address to a subscriber connection at a relevant time;
  • connect or distinguish recorded events;
  • identify records requiring preservation; and
  • test an account of how a device connected.

Each use advances the enquiry by identifying a record to obtain, a comparison to make or an explanation to test.

It does not prove by itself
  • the identity of the user;
  • a unique physical device;
  • an exact physical location; or
  • responsibility for the recorded activity.

Those conclusions need other records because an IP address describes a network connection, not the person or device behind every event using it.

The result should therefore be framed as narrowly as the evidence allows: an IP address may direct the next enquiry, while subscriber, account, device and other evidence test who or what was actually involved.

Read the address as part of the event

  1. Preserve

    Keep the complete event, including any recorded source port and protocol, because separating the address from its account, request and activity removes the relationships that can be checked.

  2. Fix the time

    Retain the full timestamp, time zone and every precision the system records - milliseconds or microseconds where available - because shared addresses can be reassigned or used by different connections within the same second.

  3. Understand the field

    Establish what the recording system meant by source, client or remote address, because differently named fields may describe different points in the connection.

  4. Find the observation point

    Identify any translation, proxy, VPN or other intermediary, because it may be the source the recording system saw.

  5. Identify the next holder

    Start with an [IP registration lookup](../ip-034/) - for example through RIPE, ARIN or a WHOIS service - to identify the organisation responsible for the address block and frame the next proportionate enquiry. This identifies a likely record holder or route to the holder; it does not identify the subscriber or user.

  6. Keep the conclusion narrow

    Say what the resulting record establishes - and what remains unresolved - because a connection match does not by itself identify the user or prove responsibility.

The point to remember

Operational takeaway
An IP address can direct the next enquiry; it does not identify the offender. Preserve its event, time and recording context, then use the wider evidence to test who controlled the connection, account or device.
Continue from another perspective

Follow the investigation

Follow a separate offender-perspective case

Go deeper

Reference: IP-007IP Addresses & Networks