Why are many IP addresses based in the United States?
Many foreign threat actors use US-based infrastructure to obfuscate their true location. The US has the largest number of VPN and proxy exit IPs.
Similar questions
How can I download all IP addresses for a certain VPN or proxy provider?
This functionality is reserved for our on-prem data customers. Our API access only allows for individual IP Address lookups.
What indicators may suggest a candidate or worker is masking their location?
Potential indicators include repeated VPN usage, residential proxy activity, frequent geographic inconsistencies, remote-access tooling, rapid location changes, and infrastructure patterns inconsistent with the worker's claimed location.
What signals can indicate possible location spoofing?
Potential indicators include VPN usage, proxy activity, GEO_MISMATCH signals, infrastructure classifications that conflict with expected user behavior, unusual location changes, and inconsistencies between geographic, device, and behavioral information.
How can I download data on all IPv4 and IPv6 addresses?
IP location, routing, and ownership information is produced at the network level and presented into netblocks. Other data such as client fields or service attributions are produced on an individual IP address basis. For our API customer this coverage is automatically merged to produce full IPv4 and IPv6 coverage. For on-prem services, a combination of these two granularities must be used to cover all IP space.
Can Spur enrich large volumes of IP addresses?
Yes. Organizations commonly use the Spur Context API and data feeds to enrich IP addresses at scale, enabling proxy detection, VPN identification, infrastructure classification, and geolocation analysis across large datasets.