Explainer29 September 20268 min read

What is an ASN? Autonomous system numbers for proxy buyers

What is an ASN? The number that names the network behind an IP. Who assigns it, how BGP ties IPs to it, and three free ways to run an ASN lookup.

An ASN (autonomous system number) is the number that identifies one network on the internet: a home broadband provider, a hosting company, a university, a large platform. Every public IP address is announced by one of these networks, so an ASN lookup tells you who is responsible for an address and what kind of network it is.

For anyone buying proxies, that matters more than it first appears. The residential, ISP and datacenter labels on a proxy are mostly worked out from which network announces the IP. Understand the ASN and you can check the label yourself. This page covers what the number is, where it comes from, and three free ways to look one up.

What is an autonomous system?

An autonomous system (AS) is a group of IP address blocks run by one operator with one routing policy. In plain terms, it is one organisation's network as the rest of the internet sees it. Cloudflare's network is one AS. Google's is another. So is your broadband provider's, and so is the cloud company that hosts your favourite website.

The internet is tens of thousands of these networks joined together. Each one decides how traffic enters and leaves it, and each one tells its neighbours which addresses it can deliver traffic to.

Some organisations run more than one AS: one per region, or one inherited from each company they bought. So "one company, one number" is a useful first picture, not a rule.

What is an ASN, and who assigns them?

The autonomous system number is the label that identifies an AS in routing. Cloudflare's is 13335, usually written AS13335. Google's main one is AS15169.

Numbers are handed out in a chain:

  1. IANA keeps the global pool and passes blocks of numbers to the five Regional Internet Registries (RIRs).
  2. The RIRs each cover a region: AFRINIC (Africa), APNIC (Asia-Pacific), ARIN (North America), LACNIC (Latin America and the Caribbean) and RIPE NCC (Europe, the Middle East and parts of Central Asia).
  3. An organisation that needs its own routing policy, usually because it connects to more than one other network, applies to its RIR (or a local registry acting for it) and receives an ASN.

The registry record stores the holder's name, which is what lookup tools show as the "AS name" or "holder". ASNs started as 16-bit numbers, which allowed fewer than 65,536 of them. In 2007 the format was widened to 32 bits (RFC 4893), which allows over four billion. A few ranges are set aside for private networks and for documentation, and never appear in public routing.

How BGP ties an IP address to an ASN

Networks exchange routes with BGP, the Border Gateway Protocol. Each network announces the address blocks, called prefixes, that it can deliver: 1.1.1.0/24, for example, which covers 1.1.1.0 to 1.1.1.255. As the announcement spreads from network to network, each one adds its own ASN to a list called the AS path. The network at the start of that path, the one that first announced the block, is the origin AS.

So "IP to ASN" means: find the most specific announced prefix that contains the address, and read its origin AS. Lookup services do this from BGP data gathered by route collectors, which listen to announcements from many networks around the world.

There are two records behind every address, and it helps to keep them apart:

  • The registration. The RIR's whois database says which organisation the block was allocated to.
  • The routing. BGP says which network announces the block today.

Most of the time the two agree. Sometimes they do not: a block can be leased to another company, a transit provider can announce a customer's space, or a block can change hands before every database catches up. Block owners can publish RPKI records that say which ASN is allowed to announce their space, which makes the routing side more trustworthy, but not everyone does. When the two records disagree, the routing is what a website sees in practice.

Why proxy buyers care about ASNs

The label comes from the network

The three proxy labels map onto the origin network:

  • Datacenter: the announcing network is a hosting or cloud company.
  • ISP: the announcing network is a consumer internet provider, and the address runs on a server.
  • Residential: the announcing network is a consumer internet provider, and the address belongs to a household connection.

The ASN entry in our glossary puts it in one sentence, and IP labelling covers the rest. Commercial IP databases start from the same place and add their own flags on top.

Sites read it too

Many anti-bot systems score an address partly by the type of network it comes from. A single rule can slow down or challenge every address from a hosting network, which is why datacenter IPs tend to get blocked in bulk while a consumer network's addresses are judged one at a time. If a target that worked yesterday is refusing you today, why your scraper started getting blocked walks through the likely causes.

What the ASN cannot tell you

The ASN tells you the network. It cannot tell a home connection from a server inside the same consumer provider, which is exactly the difference between residential and ISP proxies. It also cannot see a lease: a hosting company can end up announcing space registered to a telecom, and the other way round. Treat the ASN as the strongest single signal, check it across several addresses, and do not read one lookup as proof.

How to do an ASN lookup

All three methods below are free, and none of them needs to run through the proxy. Look up the exit IP from your own connection. To find the exit IP in the first place, send one request through the proxy to an echo service, as shown in how to check what kind of IP you were sold.

Team Cymru whois, from a terminal

whois -h whois.cymru.com " -v 1.1.1.1"

The leading space inside the quotes is part of the query. The reply is one table row per address:

AS      | IP               | BGP Prefix          | CC | Registry | Allocated  | AS Name
13335   | 1.1.1.1          | 1.1.1.0/24          | AU | apnic    | 2011-08-11 | CLOUDFLARENET - Cloudflare, Inc., US

1.1.1.1 is Cloudflare's public DNS resolver. The row shows the origin ASN, the announced prefix, the registry and the AS name. The CC column is where the block is registered, not where the address is used: 1.1.1.1 shows AU because APNIC allocated the block, yet Cloudflare answers on it worldwide. The same query works for IPv6 addresses.

If whois is missing, it is usually one package away (sudo apt install whois on Debian and Ubuntu). An address nobody announces comes back as NA in every column. 203.0.113.10, from a range reserved for documentation, is an example. An exit IP that shows NA usually means it was copied wrong.

A DNS lookup, when port 43 is blocked

Some networks block the whois port. Team Cymru answers the same question over DNS: reverse the four parts of the IP, add origin.asn.cymru.com, and ask for the TXT record. A second query turns the ASN into a name.

IP=1.1.1.1
dig +short TXT "$(echo "$IP" | awk -F. '{print $4"."$3"."$2"."$1}').origin.asn.cymru.com"
dig +short TXT AS13335.asn.cymru.com
"13335 | 1.1.1.0/24 | AU | apnic | 2011-08-11"
"13335 | US | arin | 2010-07-14 | CLOUDFLARENET - Cloudflare, Inc., US"

RIPEstat, in a browser or a script

RIPEstat is run by RIPE NCC and covers addresses worldwide, whichever registry allocated them. Open this in a browser, or call it from code:

curl -s "https://stat.ripe.net/data/prefix-overview/data.json?resource=1.1.1.1"

The reply is JSON. Trimmed to the useful part:

{
  "status": "ok",
  "data": {
    "announced": true,
    "asns": [{ "asn": 13335, "holder": "CLOUDFLARENET - Cloudflare, Inc." }],
    "resource": "1.1.1.0/24",
    "block": { "resource": "1.0.0.0/8", "desc": "APNIC (Status: ALLOCATED)" }
  }
}

announced says whether any network routes the address, asns gives the origin, and resource is the prefix it sits in. For an unannounced address, announced is false and asns is empty.

Check twenty exits at once

One address tells you little about a pool. Twenty tell you a lot. With a rotating product such as our residential line set to Randomize IP, collect a batch of exits first:

for i in $(seq 1 20); do
  curl -s -x http://USERNAME:PASSWORD@HOST:PORT https://api.ipify.org; echo
done > exit-ips.txt

HOST, PORT, USERNAME and PASSWORD are placeholders; the dashboard shows the real values on each service's page. Then look them all up in one go with Team Cymru's bulk mode, using only the Python standard library:

import socket
import sys
from collections import Counter


def cymru_bulk(ips):
    query = "begin\nverbose\n" + "\n".join(ips) + "\nend\n"
    with socket.create_connection(("whois.cymru.com", 43), timeout=30) as conn:
        conn.sendall(query.encode())
        reply = b""
        while chunk := conn.recv(4096):
            reply += chunk
    rows = []
    for line in reply.decode().splitlines():
        parts = [part.strip() for part in line.split("|")]
        if len(parts) == 7 and parts[0] != "AS":
            rows.append(parts)
    return rows


ips = [line.strip() for line in open(sys.argv[1]) if line.strip()]
rows = cymru_bulk(ips)
for asn, ip, prefix, cc, registry, allocated, name in rows:
    print(f"{ip:<16} {prefix:<18} AS{asn:<8} {name}")

print()
networks = Counter(f"AS{row[0]}  {row[6]}" for row in rows)
for network, count in networks.most_common():
    print(f"{count:>4}  {network}")

Save it as asn_bulk.py and run python3 asn_bulk.py exit-ips.txt. The first block lists each address; the second counts addresses per network, most common first.

How to read the counts

  • Sold as residential: expect a spread of consumer internet providers. Twenty exits from one or two hosting networks is a relabelled pool.
  • Sold as ISP or datacenter: a few networks is normal, since static IPs come in blocks. The holder names should match the label: consumer providers for ISP, hosting or cloud companies for datacenter. ISP or datacenter proxies explains which you need.
  • An unfamiliar holder name: search the ASN on RIPEstat or in PeeringDB, where many networks describe themselves with a type such as "Cable/DSL/ISP" or "Content". That description is self-reported, so read it as a hint.

When a label does not hold up, keep the output. On our lines, a mislabelled IP is covered by the promise on the honesty page. The ASN is also the first of the four checks in how to check proxy IP quality, which adds blocklists and geolocation.

Quick answers

Is an ASN the same as an IP address? No. An IP address identifies one connection point. An ASN identifies the network that announces a block of addresses, and one ASN can announce millions of them.

Can one company have more than one ASN? Yes. Large operators often have several, by region or from companies they bought. Two ASNs with similar names usually belong to the same group.

Does an ASN tell me where an IP is located? Not reliably. The country in a lookup is where the block or the network is registered. Where the address is in use can be somewhere else entirely.

Can a proxy provider fake the ASN? Not the routing data. Which network announces an address comes from BGP, and a provider cannot edit that for addresses it does not route. What a provider controls is where its addresses come from, which is why sampling many exits matters.

Next step

Take a few exits from the line you are considering, run them through the lookups above and keep the output. A small top-up is enough for that; rates are on the pricing page. If a holder name puzzles you, paste the lookup into Discord and we will read it with you.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord