What can reverse DNS tell me about an IP address?¶
DNS commonly starts with a name and returns an IP address. Reverse DNS starts with an IP address and asks whether a hostname has been published for it.
The answer normally comes from a DNS PTR record.
What the hostname can show¶
A reverse-DNS name may provide clues about:
- the internet or hosting provider;
- the network or service using the address;
- whether it appears to be residential, mobile, hosting or email infrastructure; and
- the organisation that may hold further records.
Some providers include apparent locations, customer-line references or terms such as broadband, mail or server in their hostnames.
Use those labels as leads. They are chosen by the network operator and may reflect an internal naming scheme rather than a verified device location or customer identity.
What a result does not list¶
One address can support many services and domain names. A reverse-DNS result normally returns a selected hostname, not a complete list of every website or service using the address.
Shared hosting may place thousands of domains on an address whose PTR record shows only the hosting provider’s generic name.
Reverse DNS is also optional. No result does not mean the address is invalid or unused.
Check the result in context¶
PTR records can be changed, left outdated or configured incorrectly. For an older event, note when the lookup was performed and consider whether historical data is available.
You can also check whether the returned hostname currently resolves back to the same address. A mismatch does not erase the reverse-DNS result, but it helps explain how much weight to place on it.
Combine the hostname with registration, routing and other ordinary IP lookup results to classify the address and identify the likely record holder.
Read a representative PTR result¶
Suppose a reverse lookup for 198.51.100.20 returns this simplified answer:
20.100.51.198.in-addr.arpa. 3600 IN PTR broadband-20.example.net.
| Part | What it means | What it does not establish |
|---|---|---|
| Reversed lookup name | DNS is asking about 198.51.100.20 | It does not identify a customer or device |
PTR | The answer is a reverse-DNS hostname | It is not a list of every domain using the address |
broadband-20.example.net | The address operator published this label | Words such as broadband or a place name are not independently verified facts |
TTL 3600 | The answer may be cached for up to one hour | It does not show how long the hostname has existed |
If an ordinary forward lookup of broadband-20.example.net also returns 198.51.100.20, the two records are consistent at the time checked. That strengthens confidence that the hostname is deliberately associated with the address, but it still identifies network naming rather than the person using a connection.
Operational takeaway
Reverse DNS adds a network-administered hostname to the address. Use it to identify infrastructure and possible record holders, then verify the lead with other lookup and provider information.