Location, ISP, ASN, timezone and coordinates for 40.87.20.23.
This is Microsoft Corporation (United States Virginia Washington, AS8075), a datacenter / cloud address.
Datacenter addresses are used for server hosting, API calls and automated crawling — they do not represent real end-users. Evaluate using request frequency, user-agent and behavioral chains; do not allow or block based on IP ownership alone.
Independent offline databases (ip2region vs GeoLite2) may disagree on an IP's location; both are third-party judgments for reference only. The page's primary location prefers ip2region.
Data source: ip2region+GeoLite2 (local offline databases)
Security Assessment & Risk
Local Weather
Loading weather…
IP History Archive
- 2026-09-16 美国 弗吉尼亚州 华盛顿 Microsoft Corporation · AS8075 Botnet / compromised Datacenter / Cloud
- 2026-09-15 美国 弗吉尼亚州 华盛顿 Microsoft Corporation · AS8075 Botnet / compromised Datacenter / Cloud
- 2026-09-14 美国 弗吉尼亚州 华盛顿 Microsoft Corporation · AS8075 Botnet / compromised Datacenter / Cloud
- 2026-09-07 美国 弗吉尼亚州 华盛顿 Microsoft Corporation · AS8075 Botnet / compromised Datacenter / Cloud
- 2026-09-04 美国 弗吉尼亚州 华盛顿 Microsoft Corporation · AS8075 Botnet / compromised Datacenter / Cloud
Deep Analysis
AS8075 (Microsoft Corporation) manages the 40.87.0.0/17 prefix block (approximately 32768 addresses) in the Datacenter / Cloud category. Microsoft Azure / Microsoft 365 infrastructure, the world's second-largest cloud. The IP 40.87.20.23 resides in United States Virginia Washington (timezone America/New_York); its position within this block determines routing behavior and connectivity characteristics.
No reverse DNS (PTR) record is configured, which is common for dynamically assigned or CGNAT'd addresses but limits reverse verification capability. Datacenter IPs generally have properly configured PTR records; the absence here is unusual and may indicate a legacy allocation or misconfiguration.
Spamhaus has listed this IP (XBL: 僵尸网络 / 被攻陷主机), which suggests it has been involved in spam or compromised activity. While a listing does not guarantee ongoing abuse, it can impact deliverability and trust score. As a datacenter address, risk-control focus should be on request patterns (user-agent, frequency, behavior chains) rather than the IP alone.
Recommendation: 40.87.20.23 is a datacenter/cloud IP — it may host legitimate services (APIs, CDNs, bots) or serve as an attack vector. Evaluate each request context: allow known API integrations, challenge or block unknown automated traffic, and never trust the client-reported IP for geo-based decisions.
Datacenter IPs are frequently used for legitimate API integrations, automated monitoring and infrastructure tasks — evaluate each request context before blocking. If you need to distinguish automation from real-user traffic, focus on request headers (User-Agent, Accept) and behavioral patterns rather than IP reputation alone.
Online Tools
Port Scan
Network Diagnostics
Supports connectivity testing, port scanning and DNS latency comparison.
Open Tool →WHOIS Info
Querying WHOIS registration info...
Location Map
The red marker shows the IP location. Drag to pan, scroll to zoom.