← Back to IP Drills

Privacy Policy

Last updated: July 2026

1. Overview

IP Drills ("we", "our", or "us") operates this website to provide users with publicly available network, geolocation, and domain information, as well as browser-side privacy diagnostic tools such as leak tests and a fingerprint test. We are committed to protecting your privacy and being transparent about how this service works.

2. Information We Collect

When you visit IP Drills, our server receives your public IP address as part of the standard HTTP request process. This is inherent to how the internet works - your IP address is transmitted to every web server you connect to.

We use your IP address solely to look up and display the following publicly available information to you:

  • Approximate geolocation (city, region, country)
  • Internet Service Provider (ISP) and ASN
  • Reverse DNS (PTR) record
  • Connection type flags (proxy, VPN, hosting, mobile detection)
  • CGNAT detection (whether your IP is in a shared carrier-grade NAT range)

We also collect browser-derived information that your browser exposes to any website you visit, including browser type, operating system, screen resolution, and language settings. This information is read locally in your browser and is never stored on our servers.

When you use the optional lookup tools, we process the inputs you provide:

  • Port Checker: the IP address you enter is forwarded to the Shodan InternetDB API to retrieve open port data.
  • Blacklist Check: the IP address you enter is used to perform DNS lookups against up to 12 DNS blacklist (DNSBL) providers.
  • Proxy / VPN Detection: the IP address you enter is forwarded to ip-api.com to retrieve proxy and network type data.
  • DNS Lookup: the domain name you enter is forwarded to the public DNS resolver you select (Google, Cloudflare, Quad9, or OpenDNS) to retrieve DNS records.
  • WHOIS Lookup: the domain name you enter is used to query the authoritative RDAP registry for that domain's TLD, via the IANA RDAP bootstrap registry, to retrieve registration metadata.
  • SSL/TLS Check: the domain name you enter is used to open TLS connections directly from our server to the domain in order to inspect the certificate and supported protocol versions.
  • DNS Leak Test: your browser sends encrypted DNS-over-HTTPS (DoH) queries directly to several public resolvers (Google, Cloudflare, Quad9, DNS.SB) and identifies the egress network for each response via whoami.akamai.net. Those results are compared against your public IP's ISP/ASN on our server to determine whether a leak is likely.
  • WebRTC Leak Test: your browser opens a local WebRTC connection and gathers ICE candidates using public STUN servers (Google STUN) to reveal any IP addresses your browser exposes outside your VPN tunnel. Candidate discovery happens entirely client-side; only your already-public IP (via the existing IP lookup) is used for comparison.
  • Browser Fingerprint Test: your browser computes canvas, WebGL, and audio rendering signatures, detects installed fonts, and reads screen/hardware/locale details, combining them into a fingerprint hash. This entire computation runs locally in your browser - none of these signals or the resulting hash are ever sent to or stored on our servers.

None of these inputs are stored, logged, or associated with your identity after the response is delivered.

3. How We Use Information

Your IP address and any domain or IP inputs you provide are used exclusively to perform real-time lookups and display results to you. We do not store, log, or retain any IP addresses or domain names after the response is sent. We do not link any lookup input to any account, identity, or persistent record.

4. Third-Party Services

Depending on which features you use, your inputs may be forwarded to the following third-party services. Please review their respective privacy policies for details on their data handling practices.

  • ip-api.com - used for geolocation, ISP/ASN data, and proxy/VPN/hosting detection. Your IP address is transmitted to ip-api.com as part of these lookups.
  • Shodan InternetDB - used for open port data. The IP address you enter in the Port Checker is forwarded to Shodan's InternetDB API (no API key or account required).
  • DNS blacklist providers - up to 12 DNSBL providers (including Spamhaus, SORBS, Barracuda, and others) are queried via standard DNS when you use the Blacklist Check. The IP you enter is embedded in DNS query hostnames sent to these services.
  • Public DNS resolvers (Google 8.8.8.8, Cloudflare 1.1.1.1, Quad9 9.9.9.9, OpenDNS, DNS.SB) - used both for the DNS Lookup tool (the domain name you enter is forwarded to whichever resolver you select) and, via encrypted DoH queries, for the DNS Leak Test.
  • IANA RDAP bootstrap / authoritative domain registries - the domain name you enter in the WHOIS Lookup is forwarded to the registry responsible for that TLD (e.g. Verisign for .com) via RDAP.
  • Akamai (whoami.akamai.net) - queried by the DNS Leak Test to identify which network answered each DoH resolver query, so it can be compared against your ISP.
  • Google STUN servers - used by the WebRTC Leak Test to gather ICE candidates directly from your browser via the standard WebRTC protocol. No data is sent to IP Drills' own servers during this step.
  • OpenStreetMap - map tiles on the home page are served by OpenStreetMap contributors. Tile requests may include your IP address as part of standard HTTP communication with their servers.

The Browser Fingerprint Test does not involve any third-party service - all signals are computed and displayed entirely within your own browser.

5. Data Export Feature

The DNS Tools page includes an Export button that lets you download your query results as a .txt file. This export is performed entirely within your browser - the file is assembled in memory, downloaded directly to your device, and the temporary in-browser URL is revoked immediately. No file is created or stored on our servers at any point.

6. Cookies and Storage

IP Drills uses localStorage solely to remember your light/dark theme preference. No tracking cookies, session cookies, or third-party advertising cookies are used.

7. Data Retention

We do not maintain any database of user IP addresses, domain names, or lookup history. Each lookup performs a fresh, stateless request. No personally identifiable information is retained on our infrastructure after your session ends.

8. Children's Privacy

This service is not directed at children under 13 years of age. We do not knowingly collect personal information from children.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by an updated date at the top of this page. Continued use of the service after changes constitutes acceptance of the revised policy.