Intelligence analysis was conducted on IP 17.166.25.211. Ownership records identified the address as belonging to Apple Inc. (ASN 714) within the 17.0.0.0/8 block. Geolocation data associated the infrastructure with Cupertino, US.
Reverse DNS resolution returned 17-166-25-211.applebot.apple.com, indicating an Applebot service identity. Forward resolution confirmed the address against the apple.com domain. Network scanning detected no open ports, and the service purpose was recorded as firewalled with no active services exposed.
Threat assessment assigned a Low Risk reputation score of 25. The IP was not flagged as a known attacker, spam source, or Tor exit node. Control plane analysis showed the IP was listed on one DNSBL out of eight checked, though the neighborhood classification remained clean with zero threat siblings. Behavioral analysis recorded no honeypot hits, enumeration strikes, or WAF violations.
The recommendation was to monitor the IP at low severity due to its location in a clean neighborhood. Overall confidence in the ownership attribution was moderate, and data freshness remained live as of the latest observation.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
π’ Ownership & Registration
| Organization | Apple Inc. |
| ASN | AS714 |
| Network Name | APPLE-WWNET |
| CIDR Block | 17.0.0.0/8 |
| RIR | ARIN |
| Country | United States |
| Abuse Contact | Available via RDAP |
π DNS Intelligence
| PTR | 17-166-25-211.applebot.apple.com |
| Forward Confirmed | Yes β FCrDNS verified |
| Forward Hostnames | 17-166-25-211.applebot.apple.com |
π DNS Hygiene
| Hygiene Score | 80% (Excellent) |
| SPF | Present |
| DMARC | Present |
| FCrDNS | Verified |
| DNSSEC | Not signed |
| CAA | Present |
βοΈ Network Classification
| Infrastructure | Unknown |
| Service Purpose | Firewalled / No Services |
| Network Tier | Unknown β Insufficient routing data to classify |
π Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | β |
| HTTP Title | β |
π TLS Certificate
| SANs | None |
| Valid From | β |
| Valid Until | β |
π― Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 25% | 1 | 1 |
| routing | 25% | 1 | 1 |
| services | 25% | 1 | 1 |
| ownership | 0% | 0 | 0 |
| reputation | 0% | 0 | 0 |
| geolocation | 0% | 0 | 0 |
| Overall | 12% | 3 | 3 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
π Observation Timeline π Live
| First Seen | 2026-09-24 07:08:11 UTC |
| Last Seen | 2026-09-24 07:08:11 UTC |
| Profile Built | 2026-09-24 07:30:25 UTC |
| Data Freshness | Live |
| Signal Types | 22 |
| Total Observations | 22 |
Full dossier details are available via our API.