Skip to main content

IPv4 guide

How Police and Governments Trace IP Addresses

Can police trace an IP address? The short answer

An IP address alone does not identify a person. Police or another authorised investigator can use a recorded address as one lead in a wider evidence chain. A useful record normally needs an accurate timestamp and, when an address is shared, the source port and protocol. Investigators may then use lawful process to ask a website, app, cloud provider, VPN, or access provider for records that connect that event to an account or network assignment.

Even a correct provider match usually identifies a subscriber account, organisation, exit service, or network connection—not automatically the person who performed the activity. A household may share a router. A company may put thousands of devices behind a gateway. A compromised device may be controlled remotely. The subscriber account is a lead, not proof of the person at the keyboard. Reliable attribution comes from corroborating service, account, device, payment, communication, and other evidence.

This guide explains the technical path in general terms. Legal authority, preservation rules, disclosure standards, and retention periods vary by jurisdiction, provider, data type, and case. It is not legal advice and does not describe how to evade an investigation.

What an IP address record actually shows

An Internet service can normally record the network endpoint that connected to it. For a direct residential connection, that may be the public address assigned by the access provider. For a company, mobile network, carrier-grade NAT gateway, proxy, VPN, or Tor connection, the service may see a shared or intermediary address instead.

The record describes one observed connection at one time. It does not contain a name, street address, browsing history, or device owner. Public registration and geolocation databases may suggest the network operator and an approximate service area, but they do not reveal the subscriber record and cannot establish who controlled a device. The IP information guide separates public network data from private provider records in more detail.

What the evidence can and cannot establish

Evidence used in IP attribution and its limits
EvidenceWhat it can help establishWhat it does not prove by itself
Service connection logThe observed source IP, source port, protocol, timestamp, account, request, and correlation identifier recorded by a website or appThe originating person, precise device, or subscriber when an intermediary or shared address was used
RIR, RDAP, routing, and network recordsThe registered resource holder, announcing network, route origin, and public contacts for an address rangeThe end subscriber, physical user, exact location, or responsibility for an event
ISP assignment or CGN mappingThe subscriber account or internal address mapped to a public address, port, protocol, and time if the necessary records existWhich household member, employee, guest, application, or compromised host generated the traffic
Platform or account recordsLogins, recovery details, session identifiers, devices, linked accounts, messages, or payment records retained by that serviceThat the named account holder personally performed every recorded action
Device and network evidenceLocal logs, browser or app state, files, malware, authentication artifacts, and timing that may corroborate or contradict the network recordsA complete history when data was never recorded, was overwritten, or belongs to another user
Witness, transaction, and communication evidenceContext, control, intent, relationships, and continuity across eventsTechnical source attribution unless it is checked against reliable event records

The strength of a conclusion depends on whether independent records align. One address appearing in a log is not the same as a verified chain from event to connection, account, device, and person.

How an IP-tracing investigation works

  1. Preserve the original event. The service or victim retains the relevant logs and records the time zone, clock source, source and destination details, account or session identifiers, and how the evidence was collected. A screenshot without the underlying event data may omit the fields needed later.
  2. Validate the network tuple. Analysts check the source IP address, source port, timestamp, protocol, destination, and clock accuracy. Under address sharing, RFC 6269 identifies the source IP address, source port, and timestamp as the key tuple for distinguishing subscribers. A broad time window or missing port can produce several possible users.
  3. Identify the relevant network layer. Registration and routing data can show which organisation administers or announces the range. Investigators also look for signs that the address belongs to hosting, mobile access, a corporate gateway, a VPN, proxy, Tor exit, or another intermediary.
  4. Request records through the applicable lawful process. The correct provider may have account, assignment, authentication, NAT mapping, or preservation records. What may be requested, what the provider can disclose, and the legal threshold depend on the jurisdiction and data type. US readers can consult the Department of Justice CCIPS documents and reports for official electronic-evidence resources.
  5. Follow the next documented hop. A residential ISP record may lead to a subscriber. A VPN or cloud address may lead to an account or upstream connection record. A company gateway may require internal DHCP, authentication, endpoint, proxy, or NAT logs. Each hop must be supported by compatible timestamps and identifiers.
  6. Corroborate attribution. Investigators compare the network path with account activity, device evidence, communications, payments, access history, witnesses, and other case facts. Conflicts and gaps must remain visible; the IP evidence should not be stretched beyond what it establishes.

Dynamic IP addresses, NAT, and CGNAT

A dynamic public address can move from one customer to another. The address is useful only with a sufficiently precise time and the provider's assignment history. Local NAT adds another mapping: several devices in a home or office use private addresses while the router presents one public address to the Internet. The access provider may identify the subscriber connection, but internal router, DHCP, Wi-Fi, authentication, or endpoint records may still be needed to distinguish devices and users.

Carrier-grade NAT (CGNAT) shares a public IPv4 address across many subscribers at the same time. In that case, the public address and time alone may be ambiguous. The external service should retain the source port as recommended by RFC 6302, while the carrier needs a compatible mapping or port-allocation record. RFC 6269 explains the traceability problem, and RFC 6888 describes common CGN requirements. Clock synchronization matters because mappings and ports can change quickly.

If a service did not record the port and the provider did not retain a mapping that can disambiguate the event, a technically honest result may be a set of possible subscribers rather than one answer. Missing evidence should not be replaced by certainty.

What changes when a VPN, proxy, or Tor is used?

A VPN or proxy changes the address visible to the destination service. The destination normally sees the intermediary's exit address, not the access connection used to reach that intermediary. Whether a further link can be established depends on records that actually exist, compatible timing, account or payment evidence, provider location, lawful access, and other corroboration. A marketing statement such as “no logs” is a policy claim, not a technical proof about every system, data type, or time period.

Tor is designed to separate a user's access connection from the destination. The Tor Project glossary states that the destination sees the exit relay's IP address. An exit address therefore identifies the relay observed by the service, not the originating user. Investigations involving anonymising networks may rely on evidence outside the destination IP log, but no guide should promise automatic deanonymisation or guaranteed anonymity.

Shared Wi-Fi, public hotspots, corporate gateways, remote desktops, hosting platforms, and compromised machines create a similar attribution boundary: the visible address can identify infrastructure while saying little about the human actor. The question is always which layer produced the observed address and which independent records connect that layer to the event.

Can a spoofed IP address hide the source?

Source-address spoofing places a forged source address in an IP packet. It is important in reflection and other one-way attacks, but it is not a general way to create an ordinary interactive web session. TCP and TLS normally require replies to reach the participant that completes the connection, so off-path spoofing does not provide that return path. The IP spoofing guide explains this distinction and the role of source-address validation.

For an attack or abuse report, analysts should therefore preserve the protocol and connection context instead of assuming every suspicious address is either genuine or spoofed. A packet capture, flow record, application log, and upstream observation answer different parts of that question.

Can an IP address reveal a person's location or identity?

Public IP geolocation is an estimate produced by a particular database. It may indicate a country, region, city, network, or service area, but accuracy varies and mobile, cloud, VPN, anycast, and recently transferred ranges can be misleading. It is not GPS and it does not encode a home address. A provider's private subscriber record is a different source and normally requires the applicable legal authority for disclosure.

An identified subscriber still may not be the actor. Family members, guests, employees, tenants, customers, malware, and remote access can share or control the connection. Device and account evidence can strengthen attribution, while inconsistent timestamps, impossible travel, a compromised endpoint, or a known exit service can weaken it.

How long are IP address logs kept?

There is no universal retention period. A website, cloud provider, ISP, employer, VPN, or public body may collect different fields for different operational, security, privacy, contractual, or legal reasons. Policies and laws can change, and a published retention statement may not describe backups, security events, fraud records, or a preservation request.

For an authorised incident response, preserve relevant records promptly through the organisation's approved legal and security process. Do not assume data will remain available, and do not collect more personal data than the documented purpose requires. Evidence handling should protect integrity, access, confidentiality, and an auditable chain of custody.

Logging checklist for network and service operators

Organisations responsible for public services or shared IPv4 space can make legitimate abuse response and incident investigation more reliable without turning logs into an unrestricted surveillance store. NIST SP 800-86 describes how network and system records support incident response and forensic analysis.

  • Synchronize clocks: use a documented time source, record time zone and precision, monitor drift, and preserve the original timestamp.
  • Capture the complete event: retain source address and port, destination or service context, transport protocol, account or session identifier, outcome, and a correlation ID where appropriate.
  • Keep assignment context: map dynamic addresses, DHCP leases, customer assignments, and NAT or CGN port allocations to stable internal identifiers for the documented operational period.
  • Separate facts from conclusions: record what the system observed and which clock produced it; do not label a subscriber, resource holder, or shared address as the attacker without corroboration.
  • Protect and limit access: define collection purpose, retention, access roles, integrity controls, deletion, legal holds, and review. Network logs can be highly privacy-sensitive.
  • Prepare the response path: publish monitored abuse contacts, define evidence-preservation and escalation steps, and involve qualified security and legal owners before disclosure.

The network abuse handling guide covers the operational response from intake through containment and closure. For leased address space, holder authority, assignment records, routing, monitored contacts, customer boundaries, and return procedures should be agreed before activation. Managed IPv4 leasing can support that address lifecycle, but it is not an investigative or identity-attribution service.

Frequently asked questions

Can the FBI or police trace an IP address?

They can use an IP record as a lead and, with the applicable legal authority, request relevant provider records. A reliable conclusion normally needs a precise timestamp, a source port when the address is shared, and evidence that connects the resulting account or infrastructure to a device or person.

Does an IP address identify a person?

No. It identifies a network endpoint observed at a particular time. It may lead to a subscriber account, organisation, gateway, or intermediary, but those are not automatic proof of the person who performed an action.

Can police find an exact home address from an IP lookup?

Not from a public lookup. Public registration and geolocation data may show an operator and approximate area. A provider may hold private subscriber records, but access and disclosure depend on the applicable law and process.

Why are the timestamp and source port important?

Dynamic assignments change over time, and CGNAT can let many subscribers share one public address simultaneously. The source IP address, source port, protocol, and synchronized timestamp allow provider records to distinguish mappings when those records exist.

Does incognito mode hide an IP address?

No. Private or incognito browsing mainly limits local browser history and some stored site data. The destination service and network intermediaries still handle the connection and can observe the address visible at their layer.

Can a VPN or Tor prevent an IP from being traced?

They change which address the destination sees and can separate parts of the path. The visible address may identify an exit service rather than the user. What can be established beyond that depends on available records and corroborating evidence; neither guaranteed anonymity nor automatic deanonymisation is a sound claim.

Can a hacker frame someone by spoofing their IP address?

A forged source address can appear in one-way packets, but ordinary interactive TCP and TLS sessions need a working return path. Investigators examine the protocol, connection state, logs, and other evidence rather than treating the source field alone as proof.

What should a business preserve after suspicious activity?

Follow the approved incident and legal process. Preserve original service, identity, network, NAT, and security records with synchronized timestamps, source ports, correlation identifiers, integrity controls, and documented access. Avoid informal collection or disclosure beyond the authorised purpose.

Primary technical and official sources

Tags

  • #How does the government track ip addresses?