Data and coverage
Where the data comes from, where it is strong and thin, and how to tell how fresh an answer is.
Sources
| Data | Source | Kind |
|---|---|---|
| Domains on an IP, DNS history, hosting moves | Our own resolver, querying the seed list below | Measured by us |
| PTR names | Our own resolver, for IPs we have observed | Measured by us |
Network category (asn.category) | Our own classification; ipverse as-metadata where we have none | Classified by us, or imported from ipverse (category_source says which) |
Network role (asn.network_role) | ipverse as-metadata, from each network's BGP neighbors | Imported |
| Cloud, hosting and CDN ranges | The lists AWS, Google Cloud, Microsoft Azure, Oracle Cloud, Linode, DigitalOcean, Vultr, Cloudflare and Fastly publish | Published by the providers |
| Tor exits, iCloud Private Relay egress, crawler ranges | The Tor Project's exit list, Apple's egress ranges, and Google's and DuckDuckGo's crawler ranges | Published by the operators |
| Routing ASN, name and country | The IPtoASN mapping | Imported |
How we collect
- Seed list: we resolve the domains in the Majestic Million, a list of 1,000,000 popular domains, and the
www.name of each.coverage.seedin each response says when the list in use was retrieved, andcoverage.derivedcounts thewww.names. - One resolver, one vantage point. Answers that differ by location, such as GeoDNS and some CDNs, are recorded as our resolver sees them, so your own lookup of the same name may return other addresses.
- Record types: A and AAAA, with the CNAME chain that led to them. PTR names only for IPs we have observed. No MX, NS, TXT or other types.
- History starts with our first observation, on October 1, 2026.
coverage.observation_windowin each response gives the span it is based on. - Networks come from the current snapshot's ASN mapping and published ranges, applied to every address in the
history. A hosting run in
domain_hostingshows which network an address belongs to today, not how it was routed at the time.
Where it is strong, and where it isn't
Strong
Shared-hosting platforms and website builders. CDN and cloud addresses serving popular sites. Popular registered domains and where they moved.
Thin
Residential and ISP addresses (usually the ASN only). Brand-new and long-tail domains. Subdomains other than
www..
Not offered
History before October 1, 2026, when collection started. Geolocation. Abuse or reputation scores. WHOIS and
company ownership. Guesses: unknown stays null.
Many hosting companies publish no range list, so many hosting IPs read is_datacenter: null. PTR names are checked for
a share of observed IPs; coverage.ptr in each response gives the counts.
Freshness
The API serves snapshots of the collected data. Each response says how fresh it is, so you don't have to take it on trust:
release.idandrelease.built_at: the snapshot that answered, and when it was built.last_confirmedandage_seconds: when we last saw each answer.staleandstale_reason: set when an answer was last confirmed more than seven days ago, when the last query failed, or when it was never confirmed. See Read an answer.first_seenandlast_seenon each published range: when we first and last saw it on that list.
Using the data
Every response lists its sources in attribution. Credit them when you republish data from the API; the Majestic Million
is licensed CC BY 3.0. Using answers inside your own product, research
or investigations is fine; reselling or redistributing the data in bulk as a dataset needs our written permission. The
Terms have the details.