About the founder

Alan Keister

Alan Keister is a 20 year cybersecurity veteran. His expertise spans malware detection, infrastructure security, and real-time threat detection and response. He earned Computer Science degrees from Johns Hopkins University and Ohio University


SourceIP emerged from his work analyzing IP infrastructure attribution: distilling years of security operations experience into a tool that answers the questions well — who operates this address, and how much should that answer weigh?


Alan holds multiple patents in malware detection and security sandboxing.

Attribution you can
check for yourself.

SourceIP answers one question well: which operator runs this address, and how much should that answer weigh?

The problem

A large share of what lands in a SOC queue is infrastructure doing its job. A CDN edge node fetching an origin. An update server checking in. A monitoring probe. A SaaS webhook. These generate volume that looks like activity, and analysts burn hours confirming that yes, that was Cloudflare.

There are datasets that address this, but they tend to be priced for large enterprises and built from methods you cannot inspect: traffic observation, inference, and aggregation from other feeds. If you cannot see where a range came from, you cannot judge how much to trust the answer.

How the data is built

Every range in SourceIP comes from a source the operating organisation published itself. In practice that means one of:

  • a machine-readable IP range endpoint the provider maintains for its customers
  • a documented allow-list page in the provider's own help centre
  • an SPF record or other DNS-published declaration
  • a published API returning current infrastructure ranges

Each source is re-fetched on a schedule and the result is recorded with a timestamp. When a provider changes what they publish, the dataset follows within a day. Nothing is inferred from observed traffic, and nothing is copied from another aggregator. If a range cannot be traced to the organisation that operates it, it does not go in.

Every provider is reviewed by hand

Collection is automated; admission is not. Before a provider enters the dataset, a security analyst checks the source against the operating organisation's own domain, confirms who actually runs the infrastructure behind it, and splits ranges that mean different things (a provider's own control plane versus a block it rents to customers) into separate entries rather than filing them under one name. That review is also where the trust level is assigned. No provider is added unreviewed, and none is inherited from another feed's judgement.

What trust levels mean

A match is not one thing. An address in a provider's own control plane is a different claim from an address in a block that provider rents to whoever signs up. Most datasets flatten that into a single score; SourceIP keeps it explicit, because the distinction is usually the entire question. The levels are documented and returned on every lookup.

What this is not

SourceIP is not a threat feed or a reputation score. It does not tell you whether traffic was malicious, only who operates the address and how they claim the addresses are used.

Coverage today is 300+ providers across 20 categories, weighted toward the services that actually generate console noise: cloud, SaaS, security scanners, monitoring, CDNs and public DNS. It is not exhaustive and does not claim to be. If something you depend on is missing, tell us.

Read the docsGet in touch