What an ASN Is, and Why It Shows Up in Your IP Lookup
IP Lookup
Look up almost any address with our IP lookup and, alongside the city and the provider name, you will find a field reading something like AS15169. It is not part of the address and it is not a serial number for your connection.
It is the identifier of a network, and more precisely the identifier of a network’s routing policy. That distinction sounds academic and turns out to be the entire point.
An autonomous system is a unit of policy, not of ownership
The definition everything else rests on is thirty years old. RFC 1930, published in March 1996 and still a Best Current Practice, puts it in one sentence: “An AS is a connected group of one or more IP prefixes run by one or more network operators which has a SINGLE and CLEARLY DEFINED routing policy.”
Read that with the emphasis where the authors put it. Not one company, not one building, not one country. One routing policy. The same document quotes the older definition from the BGP specification, “a set of routers under a single technical administration”, and then spends a whole section warning against the reading you would expect. “The term AS is often confused or even misused as a convenient way of grouping together a set of prefixes which belong under the same administrative umbrella, even if within that group of prefixes there are various different routing policies. Without exception, an AS must have only one routing policy.”
The grouping exists for a practical reason. Routing decisions between networks are not made address by address. As RFC 1930 puts it, “Policies are not configured for each prefix separately but for groups of prefixes. These groups of prefixes are ASes.” The autonomous system is the container that makes inter-network routing tractable, and the number is simply its label.
The number, and the space that had to grow
RFC 1930 describes the identifier plainly: “An AS has a globally unique number (sometimes referred to as an ASN, or Autonomous System Number) associated with it; this number is used in both the exchange of exterior routing information (between neighboring ASes), and as an identifier of the AS itself.”
Originally that number was a 16-bit integer, which RFC 1930 describes as limiting the space to 65,535 unique AS numbers. The same document recorded where things stood at the time: “some 5,100 ASes have been allocated and a little under 600 ASes are actively routed in the global Internet”, and concluded there was “no immediate danger of AS space exhaustion”. Sixteen years later the position had changed enough that RFC 6793 extended the field to four octets, in its own words, “to prepare for the anticipated exhaustion of the two-octet AS numbers”. The practical consequence for anyone reading a lookup today is that AS numbers come in two very different lengths, and a number in the hundreds of millions is as legitimate as a four-digit one.
Some numbers are reserved and are not meant to appear as the source of a route at all. RFC 6996 sets aside 64512 to 65534 in the old space and 4200000000 to 4294967294 in the new one for private use, and it is blunt about the consequence: private numbers “MUST be removed from AS path attributes … before being advertised to the global Internet”, because they are not globally unique. RFC 7300 reserves the last number in each range, 65535 and 4294967295. And IANA’s own registry reserves AS 0 outright and records 23456 as AS_TRANS, the placeholder RFC 6793 defined so that routers which only understood the old two-octet format could still carry paths containing the new ones.
How your address gets attached to one
An address becomes associated with an autonomous system because some network announces a route to it, and BGP records who did.
RFC 4271, the BGP-4 specification, defines the attribute that carries this. “AS_PATH is a well-known mandatory attribute. This attribute identifies the autonomous systems through which routing information carried in this UPDATE message has passed.” When a network first advertises a block of addresses to another network, “the originating speaker includes its own AS number in a path segment, of type AS_SEQUENCE, in the AS_PATH attribute”. Every network that passes the announcement onwards then prepends its own number to the front of that list.
The number you see in a lookup is normally the origin, the network that first announced the block, rather than any of the networks that relayed the announcement onwards. That is also why one address should not belong to two of them. RFC 1930 is explicit that a prefix generally belongs to a single autonomous system, and gives the reason in one line: “at each point in the Internet there can be exactly one routing policy for traffic destined to each prefix.”
Why having one is the exception
If you have never had a reason to want your own AS number, that is the expected outcome rather than a gap, and RFC 1930 says so directly.
For a site connected to a single provider, whether it has one block of addresses or several, the guidance is the same: “A separate AS is not needed; the prefix should be placed in an AS of the provider.” Your traffic follows your provider’s routing policy because you have not asked for a different one. The case that does justify a number is connecting to more than one provider, and the document is emphatic that it is nearly the only case: “This is ALMOST THE ONLY case where a network operator should create its own AS number.”
The registries apply that test directly. IANA allocates blocks of AS numbers to the five regional internet registries, which then assign them to network operators under their own policies. The RIPE NCC, the registry for the UK, states that “Current RIPE Policy requires a network to be multi-homed, and have a unique routing policy for an ASN to be assigned”, and that requests “must show the routing policy of the AS”. Any organisation can hold one, through membership or a sponsoring local registry, but it has to show that it needs it. RFC 1930 anticipated the failure mode back in 1996, noting that “all too often ASes have been created purely because it was seen as ‘part of the process’ of connecting to the Internet”.
What the number tells you, and what it does not
Start with the part that is solid. The mapping from number to organisation is public on purpose, which RFC 1930 notes in its security section: “AS number to owner mappings are public knowledge (in WHOIS).”
You can check one yourself. Look up 8.8.8.8 and the ASN field reads AS15169. Query that number against ARIN’s registry and you get a record named GOOGLE, handle AS15169, registered to Google LLC under the organisation handle GOGL since 30 March 2000. Nothing there is inferred. The registry record for the address block is a separate lookup, which the registry record behind an IP will run for you, and reading an IP WHOIS record walks through what comes back.
What the number cannot tell you is where you are. A routing policy has no geography. A single autonomous system can announce addresses in use on several continents at once, and nothing in the definition ties a number to a place, which is one of several reasons your IP location can be wrong.
It also does not have to match who the addresses are allocated to. The registry record for a block of addresses records an allocation. The AS number records who is announcing a route to it. Those are two separate systems recording two different facts, which is why a lookup can show a hosting company’s registry record alongside a transit provider’s network, or the reverse.
Where the number actually earns its keep
Two places, both practical.
Classification systems work at the level of the network rather than the address. Whether a connection looks residential or like a datacentre is a judgement made about the network announcing it, not about you, which is most of the explanation for why a connection gets flagged as a VPN or proxy. One address inherits the reputation of the network it sits in.
And it makes a support conversation precise. “My internet is blocked” is a sentence nobody can act on. “Addresses announced by this AS are being refused” identifies a specific network, and it is checkable by whoever reads it. If you are ever in that conversation, your starting point is your own visible address and the number attached to it.
The honest summary is narrow. An AS number tells you which network is announcing a route to an address, and that is worth something precisely because it is a claim a network has made in public and can be held to. Everything else people read into it, a location, an identity, an owner, is either inference or somebody’s database, and those are the parts most likely to be wrong.