Skip to content
ArticleUpdated 4 min read

How to identify website visitors without cookies

You can identify which companies visit your website without cookies by looking up who owns the IP address each visit comes from, using public internet registry data. It works only for organisations that own their network: larger companies, universities, public bodies. Visitors on home broadband, mobile data or shared office networks cannot be identified, and should not be guessed.

How it works, step by step

Every visit to your site arrives from an IP address. Blocks of IP addresses are allocated by regional internet registries, and the registry records who each block was assigned to. That record is public.

  1. A visitor loads a page. Your server, or a small script, sees the connecting IP address.
  2. The address is looked up against registry data to find the organisation that holds the block it belongs to.
  3. The organisation is classified. Is it a company or institution that runs its own network, or an internet provider, mobile carrier, cloud host or VPN?
  4. Only the first kind is shown, with the pages read during the visit.
  5. Nothing needs to be stored on the visitor's device, and the IP address itself does not need to be kept once the lookup is done.

This is reverse IP lookup in its honest form. The glossary entry on reverse IP lookup has the short version.

Who you will and will not see

This is the part vendors are least clear about, so here it is plainly.

VisitorIdentifiable?Why
Employee at a large company, on the office networkUsually yesLarge companies often hold their own IP ranges
University or hospital staff on siteUsually yesInstitutions commonly run their own networks
Government or public body staff on siteUsually yesSame reason
Employee at a 20-person company in a shared officeUsually noThe traffic comes from the building's or ISP's range
Anyone working from homeNoIt is the home ISP's address
Anyone on mobile dataNoIt is the carrier's address, shared by many
Anyone on a VPNNoIt is the VPN provider's address
Traffic from cloud hostsNot a personUsually bots, crawlers or monitoring

The consequence: if you sell to small businesses, most of your visitors will be invisible. If you sell to enterprises, a meaningful share will show up, but only when they browse from the office.

Be wary of guessing

Some tools fill the invisible gap by mapping ISP addresses to a nearby company, or by matching visitors against other datasets to claim named individuals. The result looks impressive and is often wrong: you see "Acme Ltd visited your pricing page" when it was someone at the café downstairs on the same ISP. Ask any vendor what share of their identifications come from organisation-owned ranges, and what they do with the rest.

What about cookies and consent?

In the UK, regulation 6 of PECR covers storing information on, or accessing information from, a visitor's device. The ICO's guidance says it applies to cookies, tracking pixels, link decoration, web storage, fingerprinting, and scripts and tags, and that consent is needed unless an exemption applies (such as something strictly necessary for a service the visitor asked for).

A lookup of who owns an IP address does not store or read anything on the device. That is why the approach is called cookieless. But it is the whole implementation that matters: a snippet that also sets an identifier, reads device characteristics or fingerprints the browser is back inside the rule. Check what your snippet actually does against the ICO guidance, and say what you do in your privacy notice. This is general information, not legal advice.

A worked example of what to expect

Say your site gets 3,000 visits a month and you sell project software to architecture firms. Illustrative numbers, not measurements:

  • Many visits are from people at home, on mobile or on small-office broadband: invisible.
  • Some are bots and cloud traffic: filtered out.
  • A minority come from organisation-owned networks. Say 150 visits from 60 organisations.
  • Of those 60, say 15 are a plausible fit for your profile, and 5 read your pricing page.

Five companies a month that read your pricing page, with no form filled in. That is useful, as long as you do not expect it to be 3,000.

What to do with an identified company

The company is not a lead yet. A person is.

  1. Check fit. Is the company the right industry and size? If not, ignore it.
  2. Look at the pages. Pricing and comparison pages are stronger signals than a blog post.
  3. Find the right person, by role, at that company. The visit does not tell you who it was, so do not pretend it does.
  4. Write without referring to the visit. "I saw someone from your company on our pricing page" is unsettling. Write as you would to any well-fitting prospect, perhaps about the topic of the page they read.
  5. Suppress customers. Your own customers visit your site constantly. See stop pitching your own customers.

Where Sluice fits

Sluice's website visitor source is a one-line snippet. Companies that own their network appear with the pages they read, worked out from registry data on who owns the IP range. There is no cookie and no stored IP. Visitors on home broadband or mobile cannot be identified and are not guessed, which means most small companies on shared ISPs stay invisible. "People there" then turns an identified company into a directory search for the people who decide, scored against your profile. More at website visitors as a lead source; for a dedicated visitor-identification tool with a different approach, see Sluice vs Warmly.

Decide this first

If most of your buyers are companies with their own networks, cookieless identification is worth adding. If most are small businesses or remote workers, spend the effort on signals they leave in public instead, such as competitor reviews.

Questions people ask

Can you identify individual people who visit your website?
Not from the IP address alone. IP ownership tells you an organisation's network, not a person. Tools that claim to name individual visitors rely on other data and deserve close questions about how.
Why can't small companies be identified?
Most small companies use a shared broadband connection from an ISP, so their traffic appears to come from the ISP, not from them. The same applies to anyone working from home or on mobile data.
Does cookieless visitor identification need a cookie banner?
PECR's consent rule covers storing or accessing information on the visitor's device, including cookies, scripts and fingerprinting. A lookup of who owns an IP address does not store anything on the device, but how your snippet works matters, so check it against the ICO's guidance.
How accurate is reverse IP lookup?
Accurate for organisations that register their own IP ranges. Misleading if a tool maps shared ISP or cloud addresses to whichever company happens to be nearby.

Sources

  1. ICO: Cookies and similar technologies
  2. ICO: What are the PECR rules? (storage and access technologies)

Try it on your own market

Sluice quotes the worst-case price before anything runs and charges only for lookups that found something, so finding out costs close to nothing.

Get started