Documentation

Schema reference

Every column in the ProdIPData monthly release files, in published order.

Which releases this covers

ReleaseSchema
2026-10 onwardAll 44 columns, as listed below.
2026-08 and 2026-09The first 40 columns. RegionCode, CityNameAscii, CityGeonameId and CityFeatureCode were appended in 2026-10.
2026-06 and 2026-07The same column names, without the cloud, VPN and threat-intelligence columns.
2026-03 and 2026-04An older schema with different column names. This page does not describe it.

Conventions

  • CSV and Parquet carry the same 44 columns in the same order, for the per-country, ALL, EDU and GOV packages. New columns are only ever appended at the end, so reading by position keeps working.
  • CSV is all text. In Parquet every column is text except Latitude and Longitude (double) and AccuracyRadius and CityGeonameId (int32).
  • Yes/no columns hold Y or N.
  • When absent says what a missing value looks like: - (a literal dash), null (an empty CSV cell), or never empty.
  • The MMDB file holds one record per network with 42 of these fields. The network itself is the lookup key, so IP24Prefix is not stored, and AccuracyRadius is not included.
  • The BOG (bogon) package uses a reduced schema: snapshot_month, IP24Prefix, BogonType, IsCoreBogon, IsSecurityOverlay, RIR, RIRStatus.

Columns

# Field Definition Parquet type When absent In MMDB Example
1snapshot_monthDataset snapshot month, YYYY-MM. Identifies the monthly publication release the row was produced from.textneveryes2026-10
2IP24PrefixIPv4 /24 network in CIDR notation. The primary network key of every exported row.textnevernetwork key95.111.141.0/24
3ContinentCodeTwo-letter continent code, derived from the country ISO.textnullyesEU
4CountryCodeTwo-letter ISO country code for the geolocated country.textnullyesAD
5IsInEUWhether the country is on the European Union list.text (Y/N)neveryesY
6RegionNameResolved first administrative subdivision name.textnullyesAndorra la Vella
7CityNameResolved city or locality name.textnullyesles Escaldes
8LatitudeLatitude of the resolved geolocation point.doublenullyes42.5078
9LongitudeLongitude of the resolved geolocation point.doublenullyes1.5211
10AccuracyRadiusEstimated accuracy radius in kilometres, from whether the match resolved to city, region or country precision.int32nullno25
11TimeZoneIANA time zone for the resolved geolocation point.textnullyesEurope/Andorra
12ASNIDAutonomous System Number associated with the prefix at snapshot time.text-yes3215
13ASNNameAutonomous system descriptive name.text-yesAkamai Technologies
14ASNOrgOrganisation that operates the ASN (IPLocate, falling back to MaxMind GeoLite2).text-yesAmazon.com, Inc.
15ASNDomainWeb domain of the ASN operator (IPLocate, falling back to IPInfo Lite).text-yesamazon.com
16ASNTypeAutonomous system type label.text-yesHosting
17IsCloudProviderY if the /24 overlaps an official published IP range of AWS, Azure, Google Cloud or Oracle Cloud, else N.text (Y/N)neveryesY
18CloudProviderCloud provider whose published range covers the /24: AWS, Azure, GCP or OCI.text-yesAWS
19CloudServicesEvery matching service label from the provider's range file, comma-separated.text-yesAMAZON,EC2
20CloudRegionsEvery matching cloud region from the provider's range file, comma-separated.text-yesus-east-1
21CompanyCompany, organisation or network operator linked to the prefix.text-yesOrange S.A.
22CompanyCountryRegistrant country in the block's WHOIS record. RIPE NCC, APNIC and AFRINIC space only - ARIN and LACNIC publish no bulk WHOIS.text-yesJP
23WhoisNetNamenetname of the most specific WHOIS record covering the /24. RIPE NCC, APNIC and AFRINIC space only.text-yesKORNET
24AbuseContactAbuse e-mail from the block's WHOIS record (abuse-c / IRT). RIPE NCC, APNIC and AFRINIC space only. APNIC's public dump redacts addresses, so APNIC blocks carry ********.text-yesabuse@microsoft.com
25RIRRegional Internet Registry.textnullyesripe
26RIRAllocationDateDate the registry allocated or assigned the containing block, from the RIRs' delegated statistics, as YYYYMMDD text.textnullyes19921201
27RIRStatusallocated or assigned, from the RIRs' delegated statistics.textnullyesallocated
28RouteOriginValidationRPKI route origin validation (RFC 6811) of the ASN seen announcing the /24: Valid; Invalid-Origin (that ASN is not authorised); Invalid-Length (right ASN, announced more specifically than the ROA allows); NotFound (no ROA covers the block); Unknown (a ROA exists but no announcement was seen).textneveryesValid
29PossibleBgpHijackY exactly when RouteOriginValidation is Invalid-Origin. A signal, not proof - a stale ROA also triggers it.text (Y/N)neveryesN
30RpkiAuthorizedASNsASNs authorised by RPKI at the most specific covering ROA, comma-separated.text-yes16509
31CaidaObservedASNsASNs seen originating the prefix in global BGP (CAIDA prefix-to-AS, from RouteViews), comma-separated. More than one means multi-origin.text-yes16509
32HasC2Y if abuse.ch Feodo Tracker lists a botnet C2 server in the /24.text (Y/N)neveryesN
33C2MalwaresMalware family of the C2 server(s) in the /24, from Feodo Tracker.text-yesQakBot
34HasThreatIntelY if any IP in the /24 is listed by Blocklist.de, CINS Army or ThreatFox.text (Y/N)neveryesN
35HasMultiSourceThreatY if one IP in the /24 is flagged by two or more of those sources independently.text (Y/N)neveryesN
36ThreatIntelCategoriesCategories reported by those sources, comma-separated.text-yesCobalt Strike
37IsVPNY if the /24 overlaps a known commercial VPN provider network (X4BNet list). No provider name is available.text (Y/N)neveryesN
38IsTorY if the /24 contains a Tor exit node.text (Y/N)neveryesN
39AnonymizationY if ASNType is Hosting (datacenter), or IsTor or IsVPN is Y.text (Y/N)neveryesN
40AnonymizerCategoriesWhich of those apply: VPN, Tor, Hosting, comma-separated.text-yesHosting
41RegionCodeFirst-level subdivision code: the GeoNames admin1 code (join on CountryCode.RegionCode in GeoNames admin1CodesASCII.txt, e.g. FR.11). Not ISO 3166-2. Where no GeoNames city matched (about 50,000 blocks in 2026-10) the location provider's code is used instead.textnullyes11
42CityNameAsciiASCII-normalised city or locality name.textnullyesles Escaldes
43CityGeonameIdGeoNames identifier for the city or locality. Makes the row joinable to GeoNames. Null where the city name could not be matched to a GeoNames place - 3,813,940 of the 14,262,775 named-city blocks in 2026-10.int32nullyes3040051
44CityFeatureCodeGeoNames feature code describing place type and granularity: PPLC capital, PPLA* admin seat, PPL ordinary, PPLQ abandoned, PPLW destroyed.textnullyesPPLC