WorldIP.io has carried 12 hidden easter eggs for more than six months. In that time one has been found and reported. The other 11 are still unclaimed, and the image above shows one of them running.
The egg in the screenshot
The infrastructure page reports live numbers from the systems behind the site. A map draws the replication mesh: regional hubs on three continents form a continuously replicated backbone, and every point of presence connects through its nearest hub. Below the map, cards list the 12 locations in the fleet, a mix of reverse-DNS scanner nodes and ClickHouse database replicas. The counters refresh every 15 minutes.
With the egg active, green Matrix-style characters fall down both sides of the page and an Exit the Matrix button appears in the lower right corner.
What WorldIP.io does
WorldIP.io looks up who owns an IP address: the organization, ASN, regional internet registry, CIDR block, reverse DNS and geolocation. It is free, covers all 4.3 billion IPv4 addresses and needs no account. The search box also takes a domain, CIDR range, ASN, organization, country or state.
The data comes from three layers. MaxMind GeoLite2 supplies the country, city and ASN blocks, and each new release is imported as soon as it is published. The delegation files of the five regional internet registries, checked every six hours, show which registry manages each block. Reverse DNS comes from WorldIP.io's own scanner fleet.
The scanner behind the reverse DNS
Scanner nodes in North America, Europe and Asia-Pacific each run a continuous PTR scan over their own slice of the allocated address space, and the results stream into a globally replicated ClickHouse cluster. Scanner v4, released in July 2026, completes a sweep of the routable IPv4 space in under 24 hours.
The scanner sends DNS PTR queries only. It opens no TCP connections, scans no ports and sends no HTTP requests to the addresses it resolves. Every scanner address has a forward-confirmed hostname under worldip.io, so a reverse lookup on a querying address identifies it:
dig -x <querying-IP>
Lookups from the command line
The keyless API answers a single curl call with no key or signup. The IP address is the path:
curl worldip.io/8.8.8.8
The reply is a JSON profile of the address:
{
"ip": "8.8.8.8",
"ptr": "dns.google",
"asn": { "number": 15169, "name": "Google LLC" },
"org": { "name": "Google, LLC" },
"country": { "code": "US", "name": "United States" },
"cidr": "8.8.8.0/24",
...
}
Run curl worldip.io with no address and it profiles your own IP. Keyless requests are rate-limited per IP, and the _meta block in each reply reports the limit and how much of it remains.
The REST API adds VPN and proxy classification, trust scores, IPv6 and live BGP routing events. API keys come with the subscription plans, and the public Pulse BGP feeds need no key.
Inside an AI assistant
WorldIP.io runs a Model Context Protocol server at https://worldip.io/mcp, so an assistant can look up an address in the middle of a conversation. It needs no key. To add it to Claude Code:
claude mcp add --transport http worldip https://worldip.io/mcp
The server exposes two read-only tools: lookup_ip for any public IPv4 or IPv6 address, and whats_my_ip for the caller's own address.
The rest of the site
The lookup is one part of WorldIP.io. The site also has a 3D globe of every IPv4 allocation, rankings of IPv4 holdings for all 250 countries, pages for the five regional internet registries, an IPv4 exhaustion counter with a per-registry breakdown, and a news section.
How to report a find
When you trigger an egg, take a screenshot, write down the steps that led to it, and send both through the WorldIP.io contact form.