What an address does and does not tell anyone
The questions people actually arrive with, answered plainly — including the ones whose honest answer is "no, and here is why people think otherwise".
The short version
An address identifies a connection rather than a person, it usually places you no better than a city, it changes more often than people expect, and the browser details alongside it are frequently more identifying than the address itself.
Questions
What is my IP address?
It is on the home page before you click anything — both the IPv4 and the IPv6 your browser reached us on, plus the network they belong to. That address is what every site you visit sees; it identifies a connection, not a person.
Can someone find my home address from my IP?
No. An IP maps to whoever operates the network — usually your internet provider, and usually only to the level of a city or a region, often wrongly. Anyone selling a precise location from an address alone is selling a guess. The organisation that could connect an address to a subscriber is the provider, and they need a legal order.
Why does my IP change?
Most home connections get a dynamic address that the provider can reassign — on a reboot, on a lease expiry, or whenever it suits them. Mobile connections change more often still, and a VPN replaces it entirely for as long as it is connected.
What can a website see about me?
Your address, and whatever your browser volunteers: its user agent, language, screen size, time zone and a long list of capability flags. Together those are often distinctive enough to recognise a returning visitor without a cookie. The home page shows you what we can see, which is what any site can see.
Am I behind a VPN, and can you tell?
Sometimes. If your address belongs to a network registered to a hosting or VPN provider rather than to a consumer ISP, that is a strong signal, and we say so when we have it. It is a signal and not proof — plenty of legitimate traffic comes from datacentres.
Is port scanning legal?
It depends where you and the target are, and scanning a host you are not authorised to test is unlawful in many jurisdictions regardless of intent. That is why scanning here needs an account and a per-scan statement that you are authorised to test that target — and why every scan is logged against the account that ran it.
Why do I have to sign in to run a scan?
Because an abuse report has to reach somebody. A scan that cannot be attributed to an account cannot be answered for, cannot be rate-limited meaningfully, and cannot be stopped by suspending anything. There is deliberately no anonymous allowance.
What will you refuse to scan?
Private, loopback and link-local ranges, the cloud metadata address, our own infrastructure, and anything on the denylist. Those refusals are not configurable by a customer, and a range larger than the per-scan cap is refused before any packet is sent.
Do you respect robots.txt when scraping?
Yes. The scraper identifies itself honestly, honours robots.txt, holds itself to a couple of requests a second per host, and will not touch anything behind a login. A scraper that ignores those is a scraper that gets our address blocked, which would end the product.
Do you store what I look up?
A lookup is answered and not kept against you. A scan is kept — the account, the target, the time and the authorisation statement — because that record is what an abuse report is answered with, and keeping it is the condition of offering the feature at all.