Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsNo—one reverse-IP lookup cannot reliably reveal every domain associated with an IP address. It can surface names in a provider’s dataset, but results may be incomplete, especially on shared hosting. Treat them as leads to verify, not a definitive inventory or proof that the domains have the same owner.
Reverse IP lookup is not the same as reverse DNS
These terms describe different operations:
- Reverse DNS (rDNS) asks DNS for the PTR record configured for an IP address. For IPv4, the query uses the
in-addr.arpanamespace; for IPv6, it usesip6.arpa. As Microsoft Learn explains, it is essentially asking, “Can you tell me the DNS name of the computer that uses this IP address?” A PTR record is optional, so no PTR result does not mean no domains use the address. - A reverse-IP lookup searches a provider’s indexed DNS or infrastructure data for domain names associated with an address. For example, DomainTools describes its Reverse IP API as accepting a domain and returning other names that share its IP. That is a dataset search, not a request for one PTR record.
Passive DNS is a collected record of DNS observations. It can help investigate past as well as recent associations, whereas a live DNS query shows records visible at the time of the query. DomainTools describes DNSDB as a historical and near-real-time global DNS database, available through a web application, API, CLI, and bulk exports. Its documentation states that it contains 300+ billion records; that is a vendor-stated dataset figure, not an independent measure of completeness for a particular search.
Why a single lookup cannot map a whole domain fleet
A reverse-IP result is bounded by the provider’s observations, indexing, and search behavior. DomainTools specifically cautions that results for shared hosting may show only part of the domains on an address. A single response therefore should not be read as either a full list or proof that no other names are present.
There are two separate sources of incompleteness:
- Many domains can share one IP. Hosting providers commonly serve unrelated customers from shared infrastructure. Co-location indicates an infrastructure association in a particular dataset or at a particular time; it does not establish common ownership, control, or intent.
- One organization can use many IPs. A domain fleet may span multiple addresses and services. Looking up one address cannot identify every address used by an organization.
Current and historical data also answer different questions. A current DNS result can omit former associations; passive DNS may show a domain that no longer points to the address. Keep the observation date or period and label each result as current or historical. SecurityTrails documents current IPv4/IPv6 A-record filtering separately from DNS-history lookups in its domain search documentation and API examples.
#1 Best Overall
How to find and validate domains associated with an IP
- Choose the question you need to answer. For the configured reverse name, query the IP’s PTR record. For domains associated with an address, use a reverse-IP search. For earlier associations, use a passive-DNS or DNS-history source.
- Search the exact IP in a dataset. Record the provider, query date, and whether the result represents current records or historical observations. A result from one vendor is evidence of what its dataset contains, not a universal inventory.
- Retrieve all available result pages or exports. SecurityTrails documents an IP statistics endpoint that can return a website count, as well as domain search and scroll mechanisms for obtaining result pages. A count is not a domain list, and one unpaginated response should not be assumed to contain every result. Check the provider’s current documentation for filters and pagination behavior.
- Expand the time range when the investigation calls for it. Use DNS history or passive DNS to find former associations, and preserve the dates shown. A historical observation is not evidence that the domain currently resolves to the address.
- Verify the relationship independently. Before claiming that listed names belong to one organization, confirm ownership or control using evidence beyond a shared IP. The IP association alone cannot establish that relationship.
Which lookup approach fits the task?
| Approach | What it can show | Access or scale documented | Key limitation |
|---|---|---|---|
| PTR reverse-DNS query | The PTR name configured for an address | DNS query | PTR records are optional; this is not a search for every domain using the IP. Microsoft Learn |
| Reverse-IP search | Names associated with an address in a provider’s data | DomainTools documents a Reverse IP API | Shared-hosting results may be partial. DomainTools |
| Passive DNS / DNS history | Recorded DNS observations over time | DNSDB documents web, API, CLI, and bulk-export access | Historical results may no longer be current; coverage is provider-dependent. DomainTools |
| SecurityTrails search and API | Current address filters, DNS-history lookups, IP statistics, and paginated domain results | Search and API mechanisms, including scrolling through results | A count or single page is not a complete inventory. Check the current DSL documentation and API examples. |
| Microsoft Graph passive-DNS endpoint | Reverse passive-DNS data retrieval | API endpoint | Microsoft documents an active Defender Threat Intelligence Portal license and an API add-on license for the tenant. Microsoft Graph documentation |
How to report the results accurately
Describe what the lookup establishes, not more than it does. For example: “Provider X returned these domains associated with IP address Y on [date]. The results may be incomplete, and the shared IP does not establish common ownership.” If the source includes historical observations, state the relevant observation dates and avoid presenting them as current DNS.
For a repeatable investigation, retain the query, provider, retrieval date, result pages or export, and any record dates. Those details let another reader distinguish a current resolution from a historical association and understand which dataset produced the list.
Quick Recap
Rank #4
Rank #3
Rank #2
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

