What information must accompany an ISP subscriber request?¶
An ISP can only match a connection if the request preserves the same identifying details that its records use. An IP address on its own is usually not enough.
The short version¶
Ask a narrow, time-specific question using the complete event tuple. Include the public IP, exact time, time zone, and any source port and protocol recorded.
The request should contain¶
| Field | Why it matters |
|---|---|
| Public source IP | Identifies the address seen by the external service |
| Exact timestamp and offset | Prevents a near-match in the wrong minute or time zone |
| Source port and protocol | May distinguish users behind CGNAT or another shared address |
| Event reference | Keeps the request tied to the original record |
| Source and destination context | Explains what the timestamp and address represent |
Preserve the original precision. If the source recorded milliseconds, do not round them away. State whether the time marks a login, request, connection or later alert.
Check the fields before sending¶
Confirm that the address is the public source address, not a private address, destination address or forwarded field. Do not combine a port from one event with a time from another. If a field was not recorded, say so rather than guessing.
Also check historical control. A current lookup may identify the wrong organisation if the range has moved since the event.
What the result means¶
A provider result may identify a subscriber connection, service account or mobile session. It does not automatically identify the device, user or person who caused the recorded activity.
The point to remember
A good subscriber request asks which connection the provider associated with this exact public address, time and matching fields. It does not ask the provider to identify a person from an IP address alone.