Privacy, without
the fine-print fog.
IP Yellow answers network questions without accounts, advertising profiles, or a database of visitor activity. Here is exactly what gets processed, where it goes, and when it disappears.
Connection data
Every web request necessarily exposes an IP address to Cloudflare and the IP Yellow server. IP Yellow uses the address, request protocol, browser-supplied user agent and platform claims, and Cloudflare-supplied country, approximate city/region, and time zone to render connection details, protect the service, and answer API requests. These environment details are informational and may be inaccurate. The application does not currently store a request history or visitor profile in a database.
ASN results are cached in application memory for up to 12 hours and reverse-DNS results for up to one hour. Failed ASN lookups may be cached for 10 minutes. These caches are shared lookup results, are not user histories, and disappear when the application restarts.
Network tools
Inputs are used only to run the tool you requested. Select any item below for the exact processing and retention details.
- Port checker: the host, port, protocol, and timeout you submit are used to perform that check. Attempt counts are held in memory for up to 10 minutes to prevent abuse.
- IP lookup: the public address you submit is sent to RIPEstat and the system DNS resolver. Results and unsuccessful provider responses are cached in memory for up to 12 hours; per-connection attempt counts expire after five minutes.
- CIDR calculator: the network and optional split prefix you submit are processed transiently by IP Yellow. The calculation makes no third-party request and is not saved.
- CGNAT detector: the optional router WAN address you submit is compared transiently with the address already visible to IP Yellow. It is not sent to another provider or saved.
- DNS lookup: the DNS name and record type you submit are sent over HTTPS to Cloudflare's 1.1.1.1 recursive resolver. Answers are cached in memory for up to 15 minutes; negative answers and per-connection attempt state expire sooner.
- DNS propagation: the DNS name and record type you submit are sent concurrently to Cloudflare and Google Public DNS. Comparisons are cached in memory for two minutes; no visitor network information is sent as EDNS Client Subnet data.
- Reverse DNS: the public IP address you submit is converted into a reverse-DNS name and sent to Cloudflare's 1.1.1.1 resolver. PTR results are cached in memory for up to one hour; when forward confirmation is enabled, the resulting hostname is also sent to that resolver.
- DNSSEC validator: the DNS name you submit is sent to Cloudflare's validating 1.1.1.1 resolver. Supporting DS and DNSKEY questions may also be sent, and a checking-disabled diagnostic is used only after SERVFAIL. Results expire from memory after five minutes or sooner when indeterminate.
- SPF checker: the mail domain you submit and static domains referenced by its SPF includes or redirect are sent to Cloudflare's 1.1.1.1 resolver. Expansion is bounded by domain, depth, and time limits; underlying DNS answers use the resolver cache described above.
- DMARC analyzer: the mail domain you submit is used to query its exact
_dmarcTXT owner through Cloudflare's 1.1.1.1 resolver. Report destinations are parsed for display but are not contacted or saved by IP Yellow. - DKIM inspector: the signing domain and selector you submit are combined into a fixed
selector._domainkey.domainTXT query sent to Cloudflare's 1.1.1.1 resolver. Public keys are decoded transiently for format and strength checks and are not saved. - DNS blacklist checker: the public IPv4 address you submit is reversed into fixed DroneBL, PSBL, and Blocklist.de DNS questions sent through Cloudflare's 1.1.1.1 resolver. Providers receive the resolver query, and IP Yellow does not contact provider web pages unless you open a details link.
- TLS inspector: the public host and allowed direct-TLS port you submit are resolved through the system DNS resolver, then IP Yellow connects directly to one validated public address to perform TLS 1.2 and 1.3 handshakes. Results are cached in memory for up to 10 minutes; private or mixed public/private answers are blocked.
- CSR decoder: the PEM request you submit is posted to IP Yellow, decoded transiently in server memory, and cleared from the form model after processing. CSR contents are not logged, cached, saved, or sent to a third party.
- Certificate expiry monitor: the host, port, alert window, check history, and deduplicated in-app alerts are held in application memory for up to 24 hours and tied to a random HTTP-only owner cookie. Checks use the TLS inspector's public-address controls. A restart erases all monitors; no external notification is sent.
- Certificate Transparency search: the normalized domain and subdomain-scope choice you submit are sent to SSLMate's fixed Cert Spotter API. First-page results are cached in application memory for 15 minutes; failed provider responses and per-connection attempt state expire sooner.
- Multi-region ping: the public hostname or IP address you submit is resolved first by IP Yellow and then sent to Globalping, whose selected probes send three ICMP echo requests to the target. The target can observe those probe addresses. Results are cached in application memory for five minutes; request and shared-provider budget state expire automatically.
- Traceroute: the public hostname or IP address you submit is resolved first by IP Yellow and then sent to Globalping, whose selected probes run ICMP traceroutes to the target. The target and intermediate networks can observe probe traffic. Structured results are cached in memory for five minutes; IP Yellow hides non-public hop topology and does not render raw command output.
- HTTP header viewer: the URL you submit is resolved and fetched directly by IP Yellow without visitor cookies, authorization, referrer, or browser headers. Each redirect is revalidated, response bodies are not buffered, and Set-Cookie values are redacted. Successful URLs without query strings may be cached in application memory for five minutes; query-string URLs are not cached.
- User-agent parser: the user-agent string you submit is bounded and parsed transiently by checked-in IP Yellow rules. It is not cached, saved, combined with other fingerprinting signals, or sent to another provider.
- URL encoder and decoder: the text or URL you submit is transformed transiently by checked-in IP Yellow rules. It is not fetched, cached, saved, logged by the transformer, or sent to another provider.
- JWT decoder: the token is decoded by checked-in JavaScript in your browser. The decoder does not submit it to IP Yellow, include it in a URL or analytics event, cache it, save it, or contact another provider. Clearing the page removes the token and decoded output from the page.
- Public API: API requests use the same connection data as the website. Per-address rate-limit state lasts up to one minute; aggregate API counters do not include submitted content.
- Speed test: measurements run between your browser and Cloudflare's edge. IP Yellow disables the engine's result logging and does not receive or save your test results.
- WAN map: your browser requests approximate coordinates from FreeIPAPI and map tiles from OpenStreetMap. Those providers receive the network request directly.
Service providers
IP Yellow relies on a small set of providers to operate specific features:
- Cloudflare provides DNS, proxying, security, country metadata, the speed-test edge, and the 1.1.1.1 resolver used by DNS tools.
- RIPE NCC receives an address from the server when IP Yellow requests ASN and network-owner information.
- Google Public DNS receives DNS questions submitted to the propagation comparison.
- SSLMate receives domain searches sent to its Cert Spotter Certificate Transparency index.
- Globalping receives multi-region measurement targets and coordinates the distributed probes that contact them.
- FreeIPAPI provides approximate WAN map coordinates through a browser request.
- OpenStreetMap provides the map tiles and receives tile requests from your browser.
Each provider processes data under its own privacy terms. Links open the provider's current policy.
Analytics and cookies
IP Yellow uses Google Analytics 4 to understand page views, referrals, device/browser categories, approximate geography, and tool usage.
Google Analytics sets first-party _ga cookies to distinguish browsers and sessions; its documented default expiration is up to two years.
Google processes IP addresses during collection and says raw addresses are discarded after use rather than exposed in Analytics reports.
You can block analytics with browser privacy controls or Google's Analytics opt-out add-on. See Google's privacy policy for its retention and processing terms.
Operational logs and retention
The application does not enable a request-by-request access log and does not intentionally write full visitor IP addresses to its normal logs. It emits health, startup, warning, and error events needed to operate the service. Container logs are operational data and are removed through host log rotation or when the container data is removed; they are not used to build visitor profiles.
Cloudflare may independently retain security and request information under its policy. IP Yellow may preserve a narrow record longer when reasonably necessary to investigate abuse, protect the service, or comply with a valid legal obligation.
Your choices and questions
You can use browser controls to block cookies or JavaScript; the core IP page remains server-rendered, while analytics, the WAN map, copy controls, and the speed test may be limited. Because IP Yellow has no accounts or saved visitor histories, it usually has no reliable way to identify data as yours.
Privacy and security contact[email protected]