DAC | Digital Asset Claims

Infrastructure Intelligence · 12 February 2026 · 8 min read

IP Intelligence and Evidential Limitations

By Digital Asset Claims Research Desk·Investigation Team

  • IP Intelligence
  • Infrastructure
  • Evidence Limits

IP address intelligence is a genuinely useful investigative signal, but it is also one of the most commonly overstated forms of digital evidence. This article sets out what an IP address can support and where its evidential limits lie.

An IP address places a network connection at a point in time. It does not, on its own, place a specific person at a keyboard.

Network topology map showing IP allocation and routing paths
IP data is most useful as one signal among several, not as a standalone identifier.

What an IP Address Actually Encodes

An IP address encodes an allocation made by a regional internet registry to a service provider, which in turn assigns it, often temporarily, to a specific connection or device on its network.

Geolocation derived from an IP address is typically an approximation based on the registered location of the allocating provider, not a precise physical location, and accuracy varies considerably by region and connection type.

The connection type itself, whether data centre, mobile, or residential broadband, materially affects how much can reasonably be inferred, with data centre addresses offering the least identifying signal.

Dynamic Allocation and Timestamp Sensitivity

Because many residential IP addresses are dynamically reassigned, any claim linking an address to a subscriber must be tied to a precise timestamp matched against the provider's allocation logs.

Allocation logs are not retained indefinitely, and retention periods vary by provider and jurisdiction, which limits how far back a meaningful correlation can be established.

An investigation that cites an IP address without a corresponding precise timestamp has effectively cited an incomplete data point that cannot be independently verified.

Autonomous system topology diagram showing shared hosting infrastructure
Shared infrastructure across ostensibly unrelated platforms is a stronger signal than any single address.

Anonymising Infrastructure and Misattribution Risk

VPNs, proxies and Tor deliberately interpose infrastructure between a user and the destination server, meaning the visible IP address reflects the intermediary rather than the user's actual connection.

Failing to check for known VPN or proxy ranges before drawing conclusions from an IP address is a documented source of investigative error, occasionally leading to unrelated third parties being wrongly implicated.

Reputable IP intelligence datasets flag known anonymising infrastructure, and this flag should always be checked and disclosed before any geographic or identity-related inference is drawn.

Combining IP Signals With Other Evidence

IP intelligence gains real investigative value when combined with hosting and domain records, on-chain timing patterns, and any available account-level metadata from platforms involved in the case.

Consistency across these independent signals supports a stronger inference about common operational control than any single signal could support alone, even without identifying a specific individual.

The final report distinguishes between what the combined evidence supports, such as common infrastructure, and what remains unproven, such as the specific identity of an operator.

IP evidence types and their typical evidential weight

SignalWhat it suggestsLimitation
Static residential IPApproximate household-level locationRequires subscriber records to attribute to a person
Data centre IPHosting or server activityRarely tied to an individual user
VPN/proxy IPDeliberate obfuscationVisible address is not the user's true location
Shared hosting patternCommon operator across platformsDoes not identify the specific operator

Frequently asked questions

Can an IP address alone prove who committed a fraud?

No. An IP address indicates a network connection at a point in time. Attribution to a specific individual generally requires subscriber records obtained through formal legal process, plus corroborating evidence.

How is a VPN or proxy address identified?

Commercial and open IP intelligence datasets maintain lists of known VPN, proxy and hosting ranges, which are checked against any address observed during an investigation before conclusions are drawn.

Why does connection type matter so much?

Residential, mobile, and data centre connections carry very different evidential weight. A data centre address, for example, typically reflects server infrastructure rather than an individual user's device.

Is IP evidence still worth collecting if it cannot identify a person?

Yes. Patterns across multiple IP addresses, particularly shared infrastructure across incidents, can support strong inferences about common operational control even without identifying an individual.

IP intelligence is a valuable but frequently misunderstood evidence type. Used with an accurate understanding of its limitations, and corroborated with other signals, it strengthens an investigation considerably. Presented as a standalone identifier, it risks producing a confident conclusion the underlying data does not actually support.

More in Infrastructure Intelligence