get_network_entity_info
Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (resolved_ip, when resolution succeeds); an IP gets a reverse DNS lookup (hostname, when a PTR exists).
whois comes from whois.iana.org and nowhere else. For an address IANA returns the RIR referral record, so its organisation is the regional registry that administers the block (ARIN, RIPE, APNIC, LACNIC, AFRINIC) — NOT the ISP, hosting company or assignee. For a hostname it is the TLD registry, not the domain owner. Never report either as the operator; a refer or whois field only names the RIR's own whois server, which this tool does not query.
geoip is the geolocation provider's response passed through verbatim, so the key set varies with provider tier and with whether the answer came from cache. Treat every field as optional — including isProxy, asn and asnOrganization, which may simply be absent. The whole geoip key is omitted for addresses that are not globally routable and when the lookup is unavailable.
To judge hosting/datacenter versus residential or small-business ISP, reason from the evidence actually returned:
The
hostnamePTR pattern: a provider-branded label under a hosting or cloud domain reads as datacenter, whereas the address itself embedded in the name under a consumer ISP's domain reads as subscriber. A missing PTR is weak evidence in either direction.geoip.isProxywhen present: true points to a VPN, proxy or hosting exit.geoip.asnOrganization(andasn) when present: a cloud, colocation or hosting provider points to a datacenter; an access or eyeball ISP points to residential.
Label that classification as a heuristic and name the evidence you used for it. If no PTR came back and no ASN fields are present, say the evidence is insufficient rather than guessing.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| entity_identifier | Yes | The IP address or hostname to query. |