Guide · Fundamentals

What a reverse-IP lookup really tells you.

A reverse-IP lookup finds domains observed on an IP address. It is powerful context—but not automatic proof that those domains share an owner.

01

Forward DNS and reverse-IP are different questions.

Forward DNS starts with a hostname and asks which address it resolves to. Reverse-IP research starts with an address and asks which hostnames have been observed there.

The second question depends on collected observations because DNS does not provide one universal endpoint listing every associated domain.

02

Why providers return different answers.

Providers collect at different times, use different sources, retain history for different periods, and apply different normalization rules.

A smaller current set and a larger historical set can both be correct for their stated scope.

03

A responsible verification checklist.

For important findings, confirm current A/AAAA records, review certificate transparency where appropriate, compare RDAP or registration context, and inspect hosting evidence without exceeding authorization.

Evaluate with your own workflow

Start with evidence before choosing a longer term.

Use the protected public preview, review the coverage principles, and test the complete workflow with a short Proof Pass.