The skills library is open: 86 files, one email

Website Visitor Identification: What It Really Resolves

Reverse-IP tools resolve a company from an IP address, sometimes. Honest match rates, why they keep falling, and what the signal is good for.

Mert · Founder7 min read
Post Share

The demo is always the same. A wall of company logos, a timeline of page views, a rep's face lighting up at a target account on pricing at 14:12 yesterday. Nobody asks what share of the traffic those logos represent. The answer is usually between a tenth and a quarter of sessions, and the vendor is under no obligation to volunteer it.

Visitor identification is a real capability with a narrow but genuinely useful output. It is sold as something much larger.

What the vendor is actually doing

A browser requests a page, the server sees an IP address, and that address sits in a block allocated by a regional internet registry, RIPE NCC in Europe, to an organisation: a company, a host, a mobile carrier, a consumer ISP. The vendor keeps a database of those allocations, enriched with autonomous system numbers, reverse DNS and WHOIS data, and the lookup returns an organisation name and a confidence score.

That is the whole mechanism: no cookie, no fingerprint, no inference about the person. Everything else in the product, the firmographics, the intent score, the buying-committee panel, inherits that guess and its error rate.

Why the match rate fell, and keeps falling

Ten years ago most B2B traffic came from a person at a desk behind a corporate gateway, on a block registered to their employer. That world is gone and it took the accuracy with it.

Remote work moved knowledge workers onto residential connections, and a Telekom consumer range resolves to Telekom, which is not a sales signal. Mobile traffic resolves to a carrier, and carrier-grade NAT puts thousands of subscribers behind one address. VPNs relocate the origin entirely. The most damaging development is enterprise security architecture: when a company routes all egress through Zscaler or Netskope, every employee appears to come from the security vendor, and a good tool will correctly and uselessly report that Zscaler read your pricing page.

Apple's iCloud Private Relay hides the originating address for Safari users who enable it. None of this was aimed at reverse-IP lookup and all of it erodes the method, so a business case assuming today's match rate holds for three years is built on a declining asset.

The honest range, and why the vendor's number is bigger

For a typical B2B site in DACH, expect 8 to 25 percent of sessions to resolve to a named company that is not an ISP, carrier, host or crawler. Enterprise audiences on on-premise networks sit at the top of that range; sites with heavy mobile traffic, or buyers in small companies, sit at the bottom and sometimes below it.

When a vendor quotes 60 percent, they are counting something else: ISPs counted as matches, matched sessions expressed as a share of matched rather than total traffic, or a denominator with mobile and bots already removed. Match rate has no standard definition, so two vendors' claims cannot be compared and both must be measured against the same traffic.

Person-level identification and where the law sits

A second category of vendor promises the individual: a name and a work email for an anonymous visitor. These do not work by reverse IP. They match a device or browser identifier against pools assembled from other sites, publisher networks and hashed email databases, mostly on US supply.

In the EU the position is tighter than the marketing pages suggest. An IP address is personal data where the holder has means reasonably likely to be used to identify the person behind it, which the Court of Justice established in Breyer. Reading or storing information on a subscriber's terminal equipment, which identifier matching requires, falls under the ePrivacy rules transposed in Germany as the TDDDG and needs consent that is prior, informed and specific. The profiling then needs its own lawful basis under the DSGVO, and legitimate interest is a hard argument when the person had no relationship with you.

So person-level de-anonymisation without consent is a position most German legal departments will not sign. Company-level reverse IP is more defensible, because the output is an organisation rather than a person. This is not legal advice: put the tool in front of your data protection officer and get sign-off in writing before the script goes live.

What the resolved signal is actually good for

Prioritisation and timing, for accounts you already care about. If a company on your target list appears three times in a week on pricing and the integration documentation, that is a reason to move it up the queue. The signal is not "this company is in-market". It is "this is a better use of the next hour than the account above it".

What it cannot do is tell you who the person was, separate a buyer from a job applicant or a competitor, or justify an email to someone who never gave you an address. Treating a guess as a lead and opening with a reference to the visit burns the tool and the sender reputation. The signal belongs in a signal ledger beside your first-party events, weighted low, decayed fast, and never routed on its own.

The two-week test that settles it

Do not evaluate on demo data. Install the script, capture a week, then check the resolved sessions against three things.

Your known-account sessions first: visits where someone clicked an email link with a parameter, filled a form or logged into the product. For those you know the truth, so you can measure how often the vendor agreed, disagreed or said nothing. Then a seeded test: ask five people at five customer organisations to visit a named page at a noted time, and count how many appear. Then the denominator: total sessions minus known bots, against sessions resolved to a real company. That is the match rate, and it belongs in the business case.

The seeded test takes ten minutes and disqualifies a vendor on its own: if those visits do not appear, nothing else in the product matters.

When to build it instead of buying it

The traffic you most want to identify is often already identifiable from first-party signals, because those people have touched you before. An email click carrying a parameter you persist, a form fill, a product login: each ties a session to an account with certainty, and back-fills the anonymous sessions from the same browser. Teams routinely buy identification while leaving their own email clicks unstitched, paying for a probabilistic answer to a question they could answer exactly.

Build the first-party path first. It costs engineering time rather than a subscription and does not decay as networks change. Then, if a meaningful share of target accounts still arrives anonymously and reps will act within two days, add reverse IP as a widener. That ordering is what a specification fixes before any signal infrastructure gets built.

Frequently asked questions

How accurate is website visitor identification?

At company level it typically resolves 8 to 25 percent of sessions on a B2B site to a named organisation that is not an ISP, carrier or host, with enterprise audiences at the top and mobile-heavy or SME audiences below. A tool can also return a name and still be wrong, particularly where a company routes traffic through a cloud security provider. Quoted rates above 50 percent count ISPs as matches or use a different denominator, so the only figure worth anything is one measured on your own traffic.

Can you identify the individual person visiting your website?

Not from an IP address, which resolves to a network allocation rather than a human. Tools promising a name and email for anonymous visitors match device identifiers against data collected elsewhere, which in the EU engages the ePrivacy rules transposed in Germany as the TDDDG and needs a lawful basis under the DSGVO for the profiling. Most German legal departments will not approve person-level de-anonymisation of visitors who gave no consent. Company-level identification is more defensible. This is not legal advice: have a data protection officer review it first.

Why have visitor identification match rates dropped?

Because the assumption underneath reverse IP has eroded. Remote work moved employees onto residential connections that resolve to consumer ISPs, carrier-grade NAT hides mobile subscribers behind shared addresses, VPNs relocate the apparent origin, and enterprise security stacks such as Zscaler or Netskope route corporate egress through the security vendor's ranges, while browser and operating system privacy features remove what is left. Each change is permanent, so the decline is structural.

What is website visitor identification actually useful for?

Account-level prioritisation and timing. When an account on your target list shows repeat visits to pricing or technical documentation, that is a reason to work it sooner. It is not a lead, does not identify a person, and cannot separate a buyer from a candidate or a competitor. Routed to a rep on its own as if it were intent, it produces bad outbound and gets switched off within a quarter.

see where you stand

Twelve questions. Then your build order.

The diagnostic returns your operating stage, the three widest gaps in your motion and what to build first. Two minutes, no sales sequence, one human reply.

Keep reading

All articles →