Is this actually a valid and complete IP address?¶
Before running a lookup or sending a provider request, check that the value is a complete IP address and preserve it exactly as recorded.
IPv4 format¶
An IPv4 address is normally four numbers separated by full stops:
203.0.113.25
Each number must be between 0 and 255.
| Example | Problem |
|---|---|
203.0.113 | One section is missing |
203.0.113.300 | 300 is outside the permitted range |
203..113.25 | One section is empty |
IPv6 format¶
IPv6 uses hexadecimal characters (0-9 and a-f) with sections separated by colons:
2001:db8::25
A double colon :: compresses one or more zero sections and normally appears only once in a valid IPv6 address. Different written forms can therefore represent the same address.
Separate the extra connection details¶
An address may appear with a port number:
- IPv4:
203.0.113.25:51543 - IPv6:
[2001:db8::25]:443
The port is not part of the address, but it should be preserved as a separate field.
A slash and number, such as /24 or /64, normally describes a network prefix or range rather than one individual address.
Check for missing or altered characters¶
Look for:
- stars,
xcharacters or other redaction; - an IPv6 value cropped by a screenshot;
- line wrapping that removed part of the address;
- confusion between similar characters; and
- transcription errors introduced when the value was copied.
A hostname, URL or account identifier shown beside an address is useful context, but it is not part of the IP address.
Preserve the original record¶
Keep the address in its original context, including the field name, timestamp, time zone, port, protocol and surrounding event. If the value appears incomplete, return to the source record rather than guessing the missing section.
Operational takeaway
Validate the format before attribution. Preserve the exact value and all accompanying connection details from the original record.