We monitor route announcements from multiple locations and providers. A prefix is sometimes announced by several disparate networks, usually because of multihoming. That is normal. Depending on your view of the topology and the originating network's policies, one of those networks will be the preferred path. We show you every one we know about.
Most likely there are at least two announcements in play: a larger prefix matching the first query, and a more specific route from someone else matching the second. That is normal, and usually reflects routing policy choices made by the originating networks to influence traffic delivery.
Some routes we learn from partners contain leaked or otherwise bogon routes. The originating network is likely using them internally and did not intend them to be publicly reachable. Everything we publish through this service is unfiltered, so those routes appear here even though other networks may filter them out of traceroutes and route collectors.
Keep each bulk run to a few thousand addresses, which keeps overall load manageable for everyone using the service. For regular, recurring bulk queries, use the DNS interface instead.
Yes. More specific routes are unlikely below a /24 or a /64, so aggregating removes unnecessary load and improves your own query performance.
No. Country codes here come from regional registry records and often differ significantly from where an IP is actually used. Use a dedicated geolocation provider for that, several of which are listed above.
Every interface reads from the same BGP feeds, drawn from more than 50 BGP peers and updated at four hour intervals. Country code, registry, and allocation date come from ARIN, RIPE, AFRINIC, APNIC, and LACNIC. AS descriptions come from cidr-report.
Free, forever. IP to ASN mapping is part of Team Cymru's community services, underwritten by Team Cymru. The only ask is that you use bulk mode or DNS at volume so the service stays fast for everyone.