Evidence
Methods and evidence
probe, scan, cert, interpolated, feed: what each method establishes and what it does not.
Every claim carries the method that produced it. The methods are not interchangeable; the ordering below reflects evidential strength.
| Method | What happened | Strength |
|---|---|---|
probe | Traffic was routed through the provider and egressed here | Direct observation |
cert | The TLS certificate issuer names the provider | Strong. Operators sign with their own CA |
scan | The host responded on a port used by this infrastructure | Presence established, egress not proven |
interpolated | Not observed itself; other addresses of its announced prefix were, and the prefix’s providers are reported | Inference. Confidence from the share of the prefix observed |
feed | An external list asserts it | Third-party measurement. Publisher and retrieval date attached |
inferred | Derived from neighbouring observations | Weakest. Treat as a lead |
Interpolated addresses
An address we never observed is answered from the announced prefix it sits in — the most specific one the routing table carries — whenever any of our sources knows at least one address of that prefix, datacenter or residential. The prefix’s figures are the union of all sources as computed after the last sync — the same the prefix search shows: each known address once, by the provider of its most recent sighting. Providers and weights follow from those counts; network names the prefix; evidence.coverage is the share known, computed by us: distinct known addresses divided by the prefix’s size. First and last seen are the prefix’s first and last sighting in any source.
| Share of the prefix observed | Confidence |
|---|---|
| More than 50 % | High (3) |
| 10 % to 50 % | Medium (2) |
| 1 % to 10 % | Low (1) |
| Less than 1 % | Very low (0) |
Confidence
Every answer states its confidence — high (3), medium (2), low (1) or very low (0) — and how it was computed, in evidence.confidenceBasis and on the address page. The rule depends on what the answer rests on:
| Rests on | High (3) | Medium (2) | Low (1) | Very low (0) |
|---|---|---|---|---|
| Our probe events for the address | 50 or more | 5 to 49 | fewer than 5 | — |
| A certificate naming the provider | always | — | — | — |
| The enriched snapshot alone | — | always | — | — |
| Interpolation from the prefix | more than 50 % observed | 10–50 % | 1–10 % | less than 1 % |
| External lists alone | — | — | always | — |
Feeds never become measurements
External lists supplement gaps and never override a measurement. Attribution weights derive from our own probing and scanning only. Where a list names a provider, it appears under method: "feed" with the publisher, keeping retrieved data distinguishable from measured data. See External sources.