IP Logging Explained: What It Is, How It Works, and What a Logged IP Reveals

October 5, 2026 | 17 min read | Technology
Home / Blog / IP Logging Explained

Before you finished your coffee this morning, you were IP-logged somewhere between twenty and a few hundred times. Every website you opened recorded your address. So did the sites whose ads and fonts and analytics scripts loaded in the background without you ever seeing their names. If you opened an email with its images on, the sender almost certainly logged you too. None of it required a click on anything labelled "logger," and none of it is a breach. It is simply how the web works.

That is the part most explanations of "IP logging" skip, and skipping it is why the topic feels murkier than it is. People picture a hacker-ish trap, a special link that "steals" your IP. That thing exists, but it is a narrow and noisy corner of a much larger, mostly dull reality: logging an IP address is the default behaviour of every server on the internet, built in, on by default, and running right now.

This article separates the dull default from the deliberate trap, shows you exactly what a logged IP does and does not expose, puts real accuracy numbers on the location question, and walks through the single most famous case of an IP logger catching someone — the FBI's 2007 bomb-threat investigation — with the caveat that case usually gets stripped of. If you want to watch it happen on your own address rather than read about it, you can run our IP lookup at any point and see the same fields a logger sees.

The Two Things People Call "IP Logging"

Search "IP logging," "IP logger," and "IP grabber" and you will get the three terms used as if they were interchangeable. They are not describing three different technologies. They are describing one technology pointed in two different directions, and the direction is the whole story.

Here is the axis that actually matters. Not the tool — the targeting.

The machinery underneath is nearly identical. A web server writes down who connected. The difference is who gets caught in the net and whether it was aimed. Confusing the two is how you end up either paranoid about ordinary web browsing or complacent about a link that was built specifically to find you.

Two Directions of the Same Technology PASSIVE — logs everyone every visitor Web server (any site) access.log every line, every visitor nobody aimed at you TARGETED — aims at one Sender creates a bait link sent to one chosen person target one entry: that person's IP then redirected to a real page

What a Single HTTP Request Actually Exposes

To understand logging you have to understand what your browser hands over on every single request, before any tracking script runs, before you type anything, before cookies even enter the picture. Opening a connection to a server is itself an act of disclosure, because the server physically cannot reply to you without knowing where to send the reply.

The standard record of that disclosure is the access log. Apache and Nginx, which serve the large majority of the web, both default to a near-identical "combined" log format, and every mainstream host, CDN, and cloud platform produces an equivalent. One request becomes one line. Here is a real-shaped combined-log line with each field labelled:

# One request = one line in the access log (Apache/Nginx "combined" format) 203.0.113.47 - - [05/Oct/2026:08:14:22 +0000] "GET /pricing HTTP/2" 200 5841 "https://www.google.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5) ..." | | | | | | | client IP timestamp path status size referring page user-agent (device/OS/browser)

Read left to right, a single uneventful request to a single page already reveals: the IP address the request came from; the exact time down to the second; the page requested; the HTTP status and byte size of the response; the referring page (where you clicked from); and the user-agent string naming the browser, operating system, and device class. This is documented behaviour, not a trick — see any plain-language access-log guide or the Nginx logging documentation, and note that managed platforms log the same fields: Amazon's S3 server access log format records requester IP, time, operation, and status in exactly this shape.

Nothing in that log line required a special tool. A default install of the world's most common web server wrote it, for free, the instant you connected. "IP logging" at its base is not an app someone runs against you. It is the floor.

What's striking is how much of this is invisible to you as a visitor. You see a page load. The server sees a structured, timestamped, attributable record. Multiply that by every third-party resource embedded in a modern page — the analytics beacon, the ad exchange, the embedded video, the web font — and a single page view can quietly write your IP into a dozen different companies' logs, each on a server you never chose to visit.

The Three Mechanisms: Logs, Links, and Pixels

Essentially all IP logging happens through one of three mechanisms. The first is passive; the second and third are the toolkit of targeted logging.

1. Plain server logs (passive)

The default described above. The server records every request to a flat log file. The owner never sent you anything; you came to them. This is the overwhelming majority of all IP logging by volume, and the least interesting, because it is not aimed at anyone. It exists to debug outages, measure traffic, and — as the EU's top court explicitly blessed, which we will get to — defend against attacks.

2. Tracking / redirect links (targeted)

A short URL that points at a server the sender controls. When you open it, that server logs your request, then issues a redirect that forwards your browser to a harmless destination — a YouTube video, a news article, an image — so the hop feels like a normal link. As one plain walkthrough of the technique puts it, you get the target to click a link and the intermediate page quietly records where they came from. This is the classic "IP logger link." We break the receiving-side mechanics down further in IP tracker vs. IP logger vs. IP grabber.

3. The tracking pixel (targeted, no click required)

A one-by-one transparent image embedded in an email or a web page. It is invisible, but loading it is a request to the sender's server, so it logs your IP and user-agent and signals that the content was opened — all without you clicking a thing. This is the quiet workhorse of email open-tracking, and it is the reason "we see you opened our email" is a thing marketers can truthfully say. We cover its email-specific behaviour in the IP logger guide.

The critical thing about mechanisms 2 and 3 is that the redirect and the invisible image are misdirection, not capability. They do not add any power to the logging. They exist purely so the target does not notice the logging is happening. The actual data captured is the same access-log line as mechanism 1. If you want to see the creating side of mechanisms 2 and 3 for yourself, that is exactly what our IP Logger does: it generates a tracking link or an invisible pixel and shows you the visitor data each one records.

Observed Facts vs. What the Client Just Tells You

Here is the precision point almost every "IP logging explained" article gets wrong, and it changes how you should read any log. Not every field in that log line is equally trustworthy. Some are observed facts of the connection. Others are simply whatever your browser chose to say, and can be changed freely.

The IP address and timestamp are observed facts. The server read the source address off the actual network connection and stamped it with its own clock. You cannot fake those from your browser without routing through something else — a VPN, a proxy, Tor — which doesn't forge the address so much as substitute a different real one (the exit server's). Short of that, the IP in the log is genuinely the address your packets came from.

The user-agent and often the referrer are client-supplied. The user-agent is a string your browser volunteers, and anything that sends an HTTP request can send any string it likes. It is trivially spoofable — which is why the user-agent header is considered self-reported identification, not proof. A scraper can claim to be an iPhone; a bot can claim to be Chrome on Windows. Treating the user-agent as a fact is a classic analyst mistake.

How Much to Trust Each Field in a Log Line OBSERVED FACTS — hard to fake read off the live connection by the server IP address the real source of the packets (or your VPN's exit) Timestamp stamped by the server's own clock changing these needs a proxy/VPN/Tor, not a setting CLIENT-SUPPLIED — spoofable whatever your browser chose to say User-Agent browser/OS/device — any string the client sends Referrer the "where you came from" page — can be forged or blank evidence of intent, not proof of identity

Why does this matter for a real reader? Because it tells you precisely what a logged IP is good for and what it isn't. The IP plus the timestamp is a solid anchor: it is the thing law enforcement subpoenas a provider about, the thing a fraud team keys on, the thing that genuinely ties a connection to a network at a moment in time. Everything the client volunteered on top — the device, the browser, the referring page — is useful context and a liar's playground in equal measure.

What a Logged IP Can — and Can't — Reveal

This is where both the paranoid and the dismissive get it wrong. The logged IP is not a home address, and it is not "just a meaningless number" either. It is an approximate locator plus a reliable pointer to your internet provider. The key word is approximate, and the accuracy collapses the more precise you try to get.

The database industry is unusually candid about this. The leading commercial geolocation providers publish their own accuracy figures, and they are a ladder that falls off a cliff. Per the published geolocation accuracy figures from MaxMind, a major provider:

>99%
country-level accuracy — especially once VPN traffic is excluded. Country is the one level you can mostly trust. Everything below it degrades fast.
The Accuracy Ladder: It Falls Off Fast Below "Country" 0% 50% 100% Country >99% Region / state ~55–80% City ~20–75% Accuracy varies widely by country and connection type; city-level is highest on dense, residential, fixed-line networks.

Region or state accuracy runs roughly 55–80%, varying heavily by country. City accuracy is the wild one: anywhere from about 20% to 75%, highest in large, dense cities on residential fixed-line connections, and poor everywhere else. The provider's own framing is the honest one: the output is "an approximate location, not a precise one." A logged IP gives you a dot on a map that is often the centre of a city or an ISP hub, not a pin on a rooftop. We go deep on why these numbers swing so much in how accurate IP geolocation really is.

A logged IP cannot produce a street address or a person's name. It produces an approximate area and the name of an internet provider. Turning that into a named human requires the provider's subscriber records — which, in most of the world, only a court order or subpoena can pry loose.

The CGNAT problem: why mobile logging is especially blurry

There is a structural reason mobile IPs are nearly useless for pinpointing anyone, and it deserves its own paragraph because it quietly breaks a lot of naive assumptions. It is called carrier-grade NAT (CGNAT). Because the world ran out of IPv4 addresses, mobile carriers no longer give each phone its own public address. Instead, thousands of unrelated subscribers share a single public IPv4 at the carrier's gateway (the reserved 100.64.0.0/10 range in RFC 6598 exists specifically for this). The address a server logs is the carrier's gateway, not the device.

How badly does that distort location? A vivid illustration comes from a walkthrough of mobile CGNAT geolocation: subscribers physically in Kisumu (about 265 km from Nairobi) and in Mombasa (about 440 km away) can all "surface on the internet meters apart in the same Nairobi data center." Three people hundreds of kilometres apart, logged at the same point. If you have ever looked up a mobile visitor's IP and gotten a city they swear they've never been to, this is why.

How Common Is This, Really?

Passive logging is universal — because it is the default server behaviour, effectively every website on the internet logs visitor IPs. That is not a figure of speech; it's a consequence of how the protocol works. The more interesting question is how common targeted logging is in the one place it reaches you without a click: your inbox.

The best data here comes from a rigorous academic study, not a vendor blog. In "I never signed up for this!" (Englehardt, Han, and Narayanan, Proceedings on Privacy Enhancing Technologies, 2018), researchers analysed a corpus of roughly 12,600 mailing lists from about 900 senders. The findings, also reported by CSO Online, are stark:

70%
of the emails studied embedded at least one tracker, and about 85% contained embedded third-party content. Roughly 30% leaked the recipient's email address to a third party at the moment the message was opened.

Sit with that 30% for a second. In nearly a third of cases, simply opening the email — not clicking anything — handed the recipient's email address to an outside company, via a tracking pixel firing on open. That is targeted IP logging operating at industrial scale, inside a channel most people treat as private. The single most effective defence is unglamorous: stop your mail client from auto-loading remote images.

Who Logs IPs, and Why

Logging has a reputation problem because the one dramatic use case — someone trying to find you — crowds out the mundane majority. Here is the honest spread of who does it and why.

Who Why they log IPs Passive or targeted
Every website operator Debugging, traffic analytics, abuse prevention, and — per the EU court — defending against cyberattacks Passive
Marketers & analytics Measuring campaigns, attributing conversions, and confirming email opens via pixels Both
Security & fraud teams Rate-limiting, blocking attackers, flagging logins from unexpected networks, detecting VPNs and proxies Passive
Law enforcement Attributing a connection to a subscriber via the provider, under legal process Both
Individuals Verifying a contact's claimed location, catching a catfish, or — the abuse case — trying to locate someone Targeted
Scam-baiters Volunteer communities who turn loggers back on scammers to gather location evidence Targeted
The abuse case is real but is a thin slice of total logging volume. Most IP logging is a server quietly doing its job.

The individual use cases are where legitimate and abusive blur, and it's worth being plain about it. Confirming that a supplier who claims to be in Rotterdam is actually connecting from the Netherlands is reasonable. Sending a stranger a disguised link to find out where they live is the behaviour regulators and courts care about. The tool is the same; the context is everything. Our practical walkthrough of the legitimate side is how to track an IP address — including what you genuinely can and can't learn.

Short version: yes, logging is legal everywhere, but in Europe it is regulated, and the legal status of the address itself differs sharply between the EU and the US. This is general information, not legal advice, but the landmarks are clear.

The EU: an IP is personal data, and logging needs a basis

The defining case is Breyer v. Germany (C-582/14), decided by the Court of Justice of the EU in October 2016. The court ruled that a dynamic IP address recorded by a website operator is personal data in that operator's hands — but only if the operator has a legal means to identify the visitor using additional information the internet provider holds. In the same ruling, and just as importantly, the court found that a website operator has a legitimate interest in storing IP addresses to protect its systems against cyberattacks. The official CJEU press release on Breyer lays out both halves.

That dual holding is the whole EU framework in miniature: an IP can be personal data, and you are allowed to log it to defend yourself. GDPR codifies the first half — Recital 30 names IP addresses explicitly as "online identifiers" that can make a person identifiable. The practical upshot for anyone operating in the EU or UK: logging IPs is lawful, but you need a lawful basis (legitimate interest or consent), and you must treat the logs as personal data — retention limits, disclosure, the lot.

The US: log freely, but only the provider can name the subscriber

The United States takes a markedly different posture. There is no general rule against logging, and under the third-party doctrine, information you voluntarily hand to a third party — such as the subscriber details your ISP holds — generally does not carry Fourth Amendment protection. As a legal analysis of the doctrine explains, that means law enforcement can typically obtain the subscriber behind an IP by subpoena rather than a full warrant.

The line that matters in practice: anyone can log an IP. But turning a logged IP into a named person runs through the internet provider — and only law enforcement or a litigant armed with a subpoena or court order can compel that disclosure. A logger link gives its creator an address, never an identity.

For the full statute-by-statute breakdown across scenarios — website logging, tracking links, workplace monitoring, and more — see our dedicated guide to whether IP tracking is legal.

Case Study: The Fake News Link That Caught a Bomb Threat

The most instructive real case of targeted logging is also the one most often retold inaccurately, so here it is with the caveat intact.

In June 2007, someone using an anonymous MySpace profile sent a string of bomb threats to Timberline High School in Lacey, Washington, forcing repeated evacuations. The suspect was careful: he routed his connection through proxy servers, which defeated ordinary passive logging. The school's and the platform's logs would only ever show the proxy, not him. This is exactly the scenario passive logging cannot solve — the observed IP was a real address, just not his.

So the FBI switched from passive to targeted. Agents created a fake news link — a counterfeit Associated Press / Seattle Times story about the threats — and sent it to the suspect's MySpace account. When he clicked it, FBI software called CIPAV (the Computer and Internet Protocol Address Verifier) reported his real IP address and location back to investigators, cutting straight through the proxies. According to the documented account of CIPAV, the tool captured the IP address, MAC address, open ports, running programs, operating system, installed-application info, the default browser, and the last URL visited — then logged outbound IP addresses with timestamps.

The trail led to Josh Glazebrook, a 15-year-old student at the school, who pleaded guilty to the bomb threats along with identity theft and felony harassment. The operation was first reported by Wired's Kevin Poulsen in July 2007 and is recounted in archived coverage from Governing and NPR.

The caveat this story usually loses. CIPAV was more than a plain IP logger. A consumer "IP logger link" records the fields in an access-log line — IP, time, user-agent — and nothing more. CIPAV was software the FBI deployed onto the target's machine that pulled far deeper system data (MAC address, open ports, running programs, installed apps). Do not read this case as "an IP logger link can do all that." It can't. What the case demonstrates is the shared core principle: get the target to load something you control, and you can reveal a real address that proxies were hiding. CIPAV was the invasive, warrant-backed law-enforcement cousin of the same idea.

That shared principle is the honest lesson. Passive logging failed against a careful suspect because he never connected to the investigators directly. Targeted logging worked because it made him come to them. The entire difference between the two halves of this article, demonstrated in a single investigation.

(Volunteer scam-baiting communities use the same get-them-to-click principle against scammers to gather location evidence. It's a real practice and a useful mental model for targeted logging, though reliable, citable accounts of specific unmaskings are thin on the ground — so treat the colourful war stories you'll read with caution.)

See It on Your Own Connection

The fastest way to make all of this concrete is to look at what a logger would see if you clicked. Three tools on this site let you do exactly that, from the safe side:

None of these do anything to anyone else. They point the same lens the rest of this article described back at your own connection, which is the only IP you're entitled to inspect freely.

Frequently Asked Questions

IP logging is the recording of the IP address of any device that connects to a server — done passively and automatically by every web server for every visitor, and done in a targeted way by a logger link or tracking pixel aimed at one specific person. Same mechanism, two very different intents.
Yes. The moment your browser opens a connection, the server can see the address it came from — it needs that address to send the page back — and recording it is the default. There is no click of consent and no network-level off switch. A VPN doesn't stop the logging; it only changes which address gets logged, because the server then sees the VPN's exit server instead of your own connection.
An approximate location and your internet provider — not your name or street address. Country-level accuracy is above 99%, but region accuracy runs roughly 55–80% and city accuracy anywhere from about 20% to 75%. On mobile, carrier-grade NAT means the logged address is often the carrier's gateway, which can be hundreds of kilometres from the device. Only the provider holds the record linking an address to a named subscriber.
The mechanism is the same; the targeting isn't. Normal logging records everyone who visits a site, as a side effect of running a server. A logger link is a short URL or invisible pixel, hosted on infrastructure the sender controls and sent to one chosen person, usually redirecting them to a harmless page so they don't notice. Passive logging asks "who came to my site?" A logger link asks "where is this specific person?" Our tracker vs. logger vs. grabber guide breaks down the terminology.
Yes, via a tracking pixel — an invisible one-by-one image in the message. If your mail client auto-loads remote images, opening the email fetches that image from the sender's server, which logs your IP and the time and signals the message was opened. A Princeton study found about 70% of the mailing-list emails it examined carried at least one tracker. Blocking or proxying remote image loading is what defeats it.
Logging is legal, but in the EU and UK it's regulated. The EU Court of Justice ruled in Breyer v. Germany (2016) that a dynamic IP recorded by a site operator is personal data when the operator can legally identify the visitor through the provider — and that operators have a legitimate interest in storing IPs to defend against cyberattacks. GDPR therefore requires a lawful basis. In the US the logging itself is unrestricted, and under the third-party doctrine law enforcement can usually compel the subscriber behind an IP with a subpoena. This is general information, not legal advice.
It changes what gets logged rather than stopping it. With a VPN active, servers and logger links record the VPN exit server's address, so the logged location points at the datacenter. Two gaps remain: WebRTC can leak your real address through the browser unless disabled, and a browser location-permission prompt reads GPS and nearby Wi-Fi rather than the IP, ignoring the VPN entirely. Confirm your VPN is actually masking you with our VPN detector.

See exactly what a logger would record about you

Run a lookup on your own address and read the same fields a logger captures — provider, network owner, connection type, and how far off the location estimate actually is for your connection.

Look Up My IP Address

A note on our tools: the IP lookup and IP Logger on this site resolve network and location data using a commercial-grade geolocation database. The accuracy limits described above — strong at country level, far weaker at city level, and especially blurry on mobile — apply to every geolocation provider, ours included.

Sources: Last9 (access-log format), Edge Delta (Nginx logging guide), AWS (S3 server access log format), How-To Geek (tracking links), Wikipedia (User-Agent header), MaxMind (geolocation accuracy figures), Ipregistry (mobile CGNAT geolocation), RFC 6598 (shared CGNAT address space), Englehardt, Han & Narayanan, "I never signed up for this!" (PETS 2018), CSO Online (email tracker reporting), CJEU (Breyer v. Germany press release), GDPR Recital 30, Lexology (third-party doctrine), Wikipedia (CIPAV), Governing (Timberline case), and NPR (Timberline case).

Need more lookups? View Pricing