Documentation
Schema reference
Every column in the ProdIPData monthly release files, in published order.
Which releases this covers
| Release | Schema |
|---|---|
| 2026-10 onward | All 44 columns, as listed below. |
| 2026-08 and 2026-09 | The first 40 columns. RegionCode, CityNameAscii, CityGeonameId and CityFeatureCode were appended in 2026-10. |
| 2026-06 and 2026-07 | The same column names, without the cloud, VPN and threat-intelligence columns. |
| 2026-03 and 2026-04 | An older schema with different column names. This page does not describe it. |
Conventions
- CSV and Parquet carry the same 44 columns in the same order, for the per-country, ALL, EDU and GOV packages. New columns are only ever appended at the end, so reading by position keeps working.
- CSV is all text. In Parquet every column is text except
LatitudeandLongitude(double) andAccuracyRadiusandCityGeonameId(int32). - Yes/no columns hold
YorN. - When absent says what a missing value looks like:
-(a literal dash), null (an empty CSV cell), or never empty. - The MMDB file holds one record per network with 42 of these fields. The network itself is the lookup key, so
IP24Prefixis not stored, andAccuracyRadiusis not included. - The BOG (bogon) package uses a reduced schema:
snapshot_month,IP24Prefix,BogonType,IsCoreBogon,IsSecurityOverlay,RIR,RIRStatus.
Columns
| # | Field | Definition | Parquet type | When absent | In MMDB | Example |
|---|---|---|---|---|---|---|
| 1 | snapshot_month | Dataset snapshot month, YYYY-MM. Identifies the monthly publication release the row was produced from. | text | never | yes | 2026-10 |
| 2 | IP24Prefix | IPv4 /24 network in CIDR notation. The primary network key of every exported row. | text | never | network key | 95.111.141.0/24 |
| 3 | ContinentCode | Two-letter continent code, derived from the country ISO. | text | null | yes | EU |
| 4 | CountryCode | Two-letter ISO country code for the geolocated country. | text | null | yes | AD |
| 5 | IsInEU | Whether the country is on the European Union list. | text (Y/N) | never | yes | Y |
| 6 | RegionName | Resolved first administrative subdivision name. | text | null | yes | Andorra la Vella |
| 7 | CityName | Resolved city or locality name. | text | null | yes | les Escaldes |
| 8 | Latitude | Latitude of the resolved geolocation point. | double | null | yes | 42.5078 |
| 9 | Longitude | Longitude of the resolved geolocation point. | double | null | yes | 1.5211 |
| 10 | AccuracyRadius | Estimated accuracy radius in kilometres, from whether the match resolved to city, region or country precision. | int32 | null | no | 25 |
| 11 | TimeZone | IANA time zone for the resolved geolocation point. | text | null | yes | Europe/Andorra |
| 12 | ASNID | Autonomous System Number associated with the prefix at snapshot time. | text | - | yes | 3215 |
| 13 | ASNName | Autonomous system descriptive name. | text | - | yes | Akamai Technologies |
| 14 | ASNOrg | Organisation that operates the ASN (IPLocate, falling back to MaxMind GeoLite2). | text | - | yes | Amazon.com, Inc. |
| 15 | ASNDomain | Web domain of the ASN operator (IPLocate, falling back to IPInfo Lite). | text | - | yes | amazon.com |
| 16 | ASNType | Autonomous system type label. | text | - | yes | Hosting |
| 17 | IsCloudProvider | Y if the /24 overlaps an official published IP range of AWS, Azure, Google Cloud or Oracle Cloud, else N. | text (Y/N) | never | yes | Y |
| 18 | CloudProvider | Cloud provider whose published range covers the /24: AWS, Azure, GCP or OCI. | text | - | yes | AWS |
| 19 | CloudServices | Every matching service label from the provider's range file, comma-separated. | text | - | yes | AMAZON,EC2 |
| 20 | CloudRegions | Every matching cloud region from the provider's range file, comma-separated. | text | - | yes | us-east-1 |
| 21 | Company | Company, organisation or network operator linked to the prefix. | text | - | yes | Orange S.A. |
| 22 | CompanyCountry | Registrant country in the block's WHOIS record. RIPE NCC, APNIC and AFRINIC space only - ARIN and LACNIC publish no bulk WHOIS. | text | - | yes | JP |
| 23 | WhoisNetName | netname of the most specific WHOIS record covering the /24. RIPE NCC, APNIC and AFRINIC space only. | text | - | yes | KORNET |
| 24 | AbuseContact | Abuse e-mail from the block's WHOIS record (abuse-c / IRT). RIPE NCC, APNIC and AFRINIC space only. APNIC's public dump redacts addresses, so APNIC blocks carry ********. | text | - | yes | abuse@microsoft.com |
| 25 | RIR | Regional Internet Registry. | text | null | yes | ripe |
| 26 | RIRAllocationDate | Date the registry allocated or assigned the containing block, from the RIRs' delegated statistics, as YYYYMMDD text. | text | null | yes | 19921201 |
| 27 | RIRStatus | allocated or assigned, from the RIRs' delegated statistics. | text | null | yes | allocated |
| 28 | RouteOriginValidation | RPKI route origin validation (RFC 6811) of the ASN seen announcing the /24: Valid; Invalid-Origin (that ASN is not authorised); Invalid-Length (right ASN, announced more specifically than the ROA allows); NotFound (no ROA covers the block); Unknown (a ROA exists but no announcement was seen). | text | never | yes | Valid |
| 29 | PossibleBgpHijack | Y exactly when RouteOriginValidation is Invalid-Origin. A signal, not proof - a stale ROA also triggers it. | text (Y/N) | never | yes | N |
| 30 | RpkiAuthorizedASNs | ASNs authorised by RPKI at the most specific covering ROA, comma-separated. | text | - | yes | 16509 |
| 31 | CaidaObservedASNs | ASNs seen originating the prefix in global BGP (CAIDA prefix-to-AS, from RouteViews), comma-separated. More than one means multi-origin. | text | - | yes | 16509 |
| 32 | HasC2 | Y if abuse.ch Feodo Tracker lists a botnet C2 server in the /24. | text (Y/N) | never | yes | N |
| 33 | C2Malwares | Malware family of the C2 server(s) in the /24, from Feodo Tracker. | text | - | yes | QakBot |
| 34 | HasThreatIntel | Y if any IP in the /24 is listed by Blocklist.de, CINS Army or ThreatFox. | text (Y/N) | never | yes | N |
| 35 | HasMultiSourceThreat | Y if one IP in the /24 is flagged by two or more of those sources independently. | text (Y/N) | never | yes | N |
| 36 | ThreatIntelCategories | Categories reported by those sources, comma-separated. | text | - | yes | Cobalt Strike |
| 37 | IsVPN | Y if the /24 overlaps a known commercial VPN provider network (X4BNet list). No provider name is available. | text (Y/N) | never | yes | N |
| 38 | IsTor | Y if the /24 contains a Tor exit node. | text (Y/N) | never | yes | N |
| 39 | Anonymization | Y if ASNType is Hosting (datacenter), or IsTor or IsVPN is Y. | text (Y/N) | never | yes | N |
| 40 | AnonymizerCategories | Which of those apply: VPN, Tor, Hosting, comma-separated. | text | - | yes | Hosting |
| 41 | RegionCode | First-level subdivision code: the GeoNames admin1 code (join on CountryCode.RegionCode in GeoNames admin1CodesASCII.txt, e.g. FR.11). Not ISO 3166-2. Where no GeoNames city matched (about 50,000 blocks in 2026-10) the location provider's code is used instead. | text | null | yes | 11 |
| 42 | CityNameAscii | ASCII-normalised city or locality name. | text | null | yes | les Escaldes |
| 43 | CityGeonameId | GeoNames identifier for the city or locality. Makes the row joinable to GeoNames. Null where the city name could not be matched to a GeoNames place - 3,813,940 of the 14,262,775 named-city blocks in 2026-10. | int32 | null | yes | 3040051 |
| 44 | CityFeatureCode | GeoNames feature code describing place type and granularity: PPLC capital, PPLA* admin seat, PPL ordinary, PPLQ abandoned, PPLW destroyed. | text | null | yes | PPLC |