Entities
Prefixes
A network block, the providers within it, and the collateral of blocking it.
Answers the question a block decision turns on: which providers and how many addresses sit inside this range.
Shared prefixes
Prefixes carrying more than one provider are marked shared, with each provider's share. 37.19.196.0/23 in AS212238 carries NordVPN at 45.8 %, PIA at 36.1 % and CyberGhost at 18.1 %. Action against one provider necessarily affects all three.
Coverage and density
| Field | Means |
|---|---|
observedIps | Addresses in this prefix we have actually seen — on the prefix page the whole range; in a list of networks the prefix's own addresses (see Nested prefixes) |
networkSize | Addresses the prefix contains |
coverage | The ratio — how much of the block we can speak to |
Low coverage is not evidence of absence. A /16 with forty observed addresses supports statements about those forty only. The ratio is shown so the limit is visible.
Any range, not only our prefixes
A prefix is a set of addresses, so any CIDR can be searched — whether or not our data holds it as a prefix. Every exit address known inside it counts, from all sources together: our probing, the enriched snapshot and scan certificates, each address once, by the provider of its most recent sighting. The announced prefixes the range meets are listed in two groups: wholly inside the range, and covering the range — a larger prefix the range lies in. Two CIDR blocks never partly overlap, so there is no third case. All figures count only addresses inside the range; a covering prefix also states what our probing knows in the whole of it.
Nested prefixes
Networks are announced inside one another. Cogent announces 38.0.0.0/8 — 16.7 million addresses — and, inside it, 2,902 smaller prefixes with known addresses, most of them a customer's own network: a hosting company, an ISP, sometimes a VPN operator. Every address belongs to the most specific prefix that announces it. That is how the internet routes it, and how a lookup answers for it: an address in a /24 inside the /8 is judged by what we know of that /24, not of the /8 around it.
So a prefix has two counts:
| Count | What it holds | Where |
|---|---|---|
| Own addresses (not in a more specific prefix) | Known addresses whose most specific announced prefix is this one | A single address's verdict, interpolation and its confidence, the network lists of a provider, ASN and organisation, a provider's address space, the start-page total |
| Whole range | Every known address in the range, more specific prefixes included | The prefix page and any range search: what lies in here |
Why not always the whole range:
- A customer network is not its carrier. A VPN operator's /24 inside a carrier's /8 is that operator's network. Its evidence must not be diluted across 16.7 million addresses, nor lend the /8 a confidence of its own.
- Totals must add up. If the /8 counted its more specific prefixes too, every address in them would be counted twice — once in the /8, once in its own prefix — and a provider's address space and the start-page total would no longer sum.
Example (8 October 2026). In 38.0.0.0/8 we know 65 own addresses, 13 of them last seen as shifter; that is the row for the /8 on shifter's page, and with 0.0004 % of the block known it answers with very low confidence and adds nothing to anyone's address space. Across the whole range we know 27,543 addresses, 10,260 of them last seen as shifter; that is the prefix page. Both numbers are right — one says which network an address belongs to, the other what lies inside a range. Wherever a list shows a prefix with more specific ones inside it, it names them beside the own addresses and links the whole range.
Every address in the prefix
Addresses in this prefix lists, address by address, what our probing reached in a window you choose on the timeline — provider, protocol, pool, days seen and probes. Where several providers used an address, the share counts observation days, each worth half as much for every 30 days before the window’s end; where the most recent sighting belongs to another provider than the leader, the table names it.
Addresses the window knows only from the enriched snapshot or from a scan run that found an operator’s certificate are rows too, marked Snapshot or Certificate — they used to appear as interpolated. All observed includes them; a tunnel protocol filter does not.
The table also lists every address the window did not observe in an announced prefix that probing reached in the window, marked Interpolated and carrying the prefix’s providers — the same answer a lookup of that address gives. An address observed only outside the window is interpolated in it. See Interpolated addresses.
Filter by Provider, Method and Pool. Each choice shows how many addresses of the window carry it, counted before filtering. Methods combine: choose WireGuard and Interpolated together and the table lists both. All observed stands for every method our probing saw, so it hides only the interpolated rows; Interpolated alone shows only them. Filters and window are kept in the address bar, so a link reproduces the view.
37.19.196.0/23Three providers in one block.Open →