The IP belongs to a mobile network - what changes?¶
The enquiry is still about which connection or session used the IP address at the event time. A mobile-network result changes what you may need to supply and what the provider’s answer is likely to identify.
The short version
A mobile-network IP lookup does not identify a handset, customer or location. Treat it as a route to the likely network record holder and preserve the full connection record, including the source port where available, before making the next enquiry.
The route is different from fixed broadband¶
| Stage | What you may have | What it actually tells you |
|---|---|---|
| External service | Public IP, time, possibly source port and protocol | What that service observed for one event |
| IP classification | Mobile operator or mobile-network range | Likely infrastructure or record holder |
| Provider match | Session, SIM, subscriber account or service record | A network-level association |
| Further enquiries | Handset, account, activity and other evidence | Whether the event can be linked to a user and responsibility |
The important separation is:
mobile gateway → network session → SIM/account → possible handset → user → responsibility
Those are not interchangeable conclusions.
Why the source port may matter¶
Many mobile networks use CGNAT. That can allow many customers to share the same public IPv4 address at the same time.
In that situation, this may be incomplete:
The values below are fictional documentation data.
time=2026-07-24T20:41:16Z
source_ip=198.51.100.84
The provider may also need the translated public source port and protocol from that same event:
time=2026-07-24T20:41:16.482Z
source_ip=198.51.100.84
source_port=51543
protocol=TCP
Use the mobile/CGNAT request checklist before sending the request.
What does CGNAT mean here?
The public address seen by the forum, retailer or other online service may belong to a provider gateway shared by many customers. The provider’s internal translation records are what may distinguish one connection from another.
That is why a public IP and rough time can be insufficient even when the lookup correctly identifies the mobile operator.
What a provider result might look like¶
A qualified response may say that the supplied public IP, exact time, source port and protocol matched a mobile-data session associated with a particular SIM or subscriber account.
That is useful evidence - but it does not automatically prove:
- which handset held the SIM at that moment;
- whether the phone was providing a hotspot to another device;
- who physically used the handset or connected device;
- whether the account holder was the user; or
- who was responsible for the activity under investigation.
See what an ISP or network-provider subscriber result actually establishes.
Mobile complications worth testing¶
- SIM moved between handsets: the SIM/account result and device identity may be different questions.
- Hotspot or tethering: the mobile handset may have provided connectivity to another device.
- Shared or business account: the billing or subscriber name may not be the person using the service.
- Roaming: more than one network operator may be relevant to the data trail.
- Wi‑Fi switching: the same handset may use mobile data for one event and Wi‑Fi for another.
What should I do next after a mobile match?
Record exactly what level the provider has identified - session, SIM, account or another service record - and preserve the identifiers and qualifications in the response.
Then choose proportionate enquiries that test the next attribution layer: handset, account control, location, communications, platform activity or other case evidence. Do not silently turn a network association into a person-level conclusion.
Operational takeaway¶
Use the mobile-network result to move one level at a time. First identify the right network session. Then establish what that result connects to. Only then test the handset, user and responsibility with other evidence.