Skip to content
Skip to main content
IP Addresses & Networks Technical Explainer

What information must accompany an ISP subscriber request?

An ISP can only match a connection if the request preserves the same identifying details that its records use. An IP address on its own is usually not enough.

The short version

Ask a narrow, time-specific question using the complete event tuple. Include the public IP, exact time, time zone, and any source port and protocol recorded.

The request should contain

Field Why it matters
Public source IP Identifies the address seen by the external service
Exact timestamp and offset Prevents a near-match in the wrong minute or time zone
Source port and protocol May distinguish users behind CGNAT or another shared address
Event reference Keeps the request tied to the original record
Source and destination context Explains what the timestamp and address represent

Preserve the original precision. If the source recorded milliseconds, do not round them away. State whether the time marks a login, request, connection or later alert.

Check the fields before sending

Confirm that the address is the public source address, not a private address, destination address or forwarded field. Do not combine a port from one event with a time from another. If a field was not recorded, say so rather than guessing.

Also check historical control. A current lookup may identify the wrong organisation if the range has moved since the event.

What the result means

A provider result may identify a subscriber connection, service account or mobile session. It does not automatically identify the device, user or person who caused the recorded activity.

The point to remember

A good subscriber request asks which connection the provider associated with this exact public address, time and matching fields. It does not ask the provider to identify a person from an IP address alone.

Reference: IP-077IP Addresses & Networks