MyIPScan
IP Ranges

Naver IP Ranges

Naver is South Korea's largest search and internet services company, and AS23576 is the autonomous system its machines answer from. The aut-num object is held at KRNIC, Korea's national internet registry, rather than at APNIC directly, which is why an RDAP query to rdap.apnic.net for this AS number returns a 301 to krnic.rdap.apnic.net. It is described there as NAVER Cloud Corp., with an administrative and a technical contact at dl_noc@navercorp.com in Bundang-gu, Seongnam. The object's own name is older than the company's: nhn-AS-KR-KR preserves NHN Corporation, which is what Naver called itself from 2001 until 2013, when the Hangame business split off as NHN Entertainment and the rest took the Naver Corporation name that October. The same AS number announces the blocks Naver runs its own services on and the space Naver Cloud Platform hands to paying tenants.

Tech
Provider
Naver
Primary ASN
AS23576
Category
Tech
Headquarters
Seongnam, South Korea
Announced IPv4 prefixes
169
Registry
APNIC

Known IP ranges

These prefixes are currently announced to the global routing table by AS23576 (nhn-AS-KR-KR - NAVER Cloud Corp.). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.

110.234.64.0/18
175.158.0.0/19
61.97.176.0/20
182.162.192.0/20
210.89.160.0/20
220.230.112.0/20
175.158.0.0/20
117.52.128.0/20
211.249.48.0/20
175.158.16.0/20

What does a Naver IP mean in a privacy test?

A Naver address as your visible IP is not a consumer line. Nothing on AS23576 is sold as a home connection, so the readings worth considering are a server or proxy running on Naver Cloud Platform, a corporate link routed through this space, or a geolocation database that has placed the block badly. In inbound logs an address from this network is far more often Naver or one of its tenants fetching something than a person browsing. Which of the two it is depends on which block the address sits in, and the registry record is the only thing that will tell you.

What Naver publishes, and what the KRNIC record actually carries

Naver publishes no prefix list. There is no geofeed on Naver's own registry objects, no allowlist file named from them, and nothing in its PeeringDB entry that points at a machine-readable set of addresses. What it does maintain is that entry itself, peeringdb.com/net/5282, filed under the name NAVER with Naver Cloud Corp. as the alternate name. It classes AS23576 as a content network with a global scope, self-reports 500-1000Gbps of traffic and a mostly outbound ratio, states an open peering policy, lists its internet exchange connections, and gives AS-NBP as the IRR AS-SET. That AS-SET is the closest thing to a published statement of what this network announces, though it resolves to AS numbers rather than to a file of addresses, and the NBP in it is the company's older name, NAVER Business Platform, which is also the stem of every netname Naver registers below.

For a single address the checkable source is RDAP, and the answer comes back from KRNIC rather than APNIC. It is thinner than the ARIN records these pages usually quote: the aut-num carries no registration date and no last-changed date of its own, and the only dated event anywhere on the object belongs to the abuse contact, IRT-KRNIC-KR, last changed on 19 October 2017. A date for this AS has to be read from APNIC's own copy of the same object, which that redirect returns in its body: the APNIC copy is named nhn-AS-KR and carries a registration event of 4 September 2008 and a last change of 2 April 2021. What the KRNIC record gives is the name nhn-AS-KR-KR, the description NAVER Cloud Corp., country KR and an active status. RIPEstat's announced-prefixes data supplies the other half, and two things in it are worth knowing before reading the count in the table below: this AS number announces IPv4 only, with no IPv6 prefix at all, and it announces the same space at several lengths at once - 175.158.0.0/19 is in the table alongside 175.158.0.0/20 - so the figure counts announcements rather than distinct blocks.

Naver's own machines, cloud tenants, and blocks registered to other operators

The split between Naver's own traffic and a customer's is written into the netnames, so RDAP against the address answers it. Blocks named NBP-NET-KR are allocated portable to NAVER Cloud Corp. and are Naver's own Korean space; 223.130.192.0/20, which holds the addresses naver.com itself answers on, is one of them. The largest single block on the AS, 110.234.64.0/18, is not: its netname is NBP-NCP-NET, its description is Naver Business platform Cloud Service, and APNIC registered it on 24 July 2019, so traffic from it can be any Naver Cloud Platform customer's workload rather than Naver. A third family, netname NBP-NET and described as Naver Business Platform Naver & Line Service, carries country codes that are not KR - US, JP, SG, DE and HK across the objects it covers, registered from September 2017 onward - though that field records where the space is registered as being used, not where a given machine sits. The two APNIC-registered families send abuse to Naver's own team, IRT-NBPAP-KR at dl_security_whois@navercorp.com, while the Korean blocks send it to the registry's own team, IRT-KRNIC-KR at hostmaster@nic.or.kr, so where a complaint should go depends on the block too.

Two things this network will not tell you. A whois can name a company that is not Naver and never was: 182.162.192.0/20 and 117.52.128.0/20 fall inside LG DACOM's KIDC-KR record, 220.230.112.0/20 and 211.249.48.0/20 inside Dreamline's DREAMX-KR, 1.255.50.0/23 inside SK Broadband's broadNnet-KR, and 38.77.206.0/24 inside ARIN's direct allocation to Cogent, whose only published word on that /24 is a row in the geofeed its ARIN record links, placing it in San Jose. Those are addresses Naver announces out of other operators' delegations, and an attribution built on the whois name alone will credit the wrong company. Reverse DNS narrows it barely: the reverse zones under this space are delegated to Naver Cloud's own nameservers, ns1-1.ns-ncloud.com and ns1-2.ns-ncloud.com, but the records behind them are sparse - a sweep of 125.209.222.0/24 returned four names, all mail hosts, two of them resolving back to the address that produced them - and a PTR query against the live addresses naver.com resolves to returns NXDOMAIN, so the forward-confirmed reverse lookup that verifies a Googlebot claim has almost nothing to work with here.

Related tools

Frequently asked questions

What IP ranges does Naver use?

Naver announces its addresses under AS23576, described at KRNIC as NAVER Cloud Corp. and named nhn-AS-KR-KR after the company's pre-2013 name. The blocks above are the largest currently in the routing table. Naver publishes no prefix file of its own, so the two checkable sources are RIPEstat's announced-prefixes list for AS23576 and the RDAP record behind each block. Note that the network announces IPv4 only, with no IPv6 prefix under this AS number at all.

Why does a Naver IP appear in my privacy test?

Because something on this network was in the path, not because you are browsing from a home line on it. Nothing on AS23576 is sold as a consumer connection, so a Naver address showing as your visible IP points to a server or proxy running on Naver Cloud Platform, a corporate link routed through this space, or a geolocation database that has placed the block badly. In a DNS or leak test it more often means a Naver service was the endpoint you reached than that anything of yours was routed through it.

Does an address on AS23576 belong to Naver or to one of its cloud customers?

It depends on the block, and the netname says which. Space named NBP-NET-KR is allocated to NAVER Cloud Corp. and carries Naver's own services. The largest block on the AS, 110.234.64.0/18, is registered instead as NBP-NCP-NET with the description Naver Business platform Cloud Service, so an address there can be any Naver Cloud Platform tenant's machine. Run RDAP against the address itself and read the netname before attributing anything on this network to Naver.

Why does a whois on a Naver IP return LG DACOM or Dreamline?

Because AS23576 announces space out of other Korean operators' delegations as well as its own. 182.162.192.0/20 and 117.52.128.0/20 sit inside LG DACOM's KIDC-KR record, 220.230.112.0/20 and 211.249.48.0/20 inside Dreamline's DREAMX-KR, and 1.255.50.0/23 inside SK Broadband's broadNnet-KR. One /24, 38.77.206.0/24, falls inside ARIN's direct allocation to Cogent. The routing says Naver, the registration says someone else, and both are correct.

How do I check whether an address is really Naver's?

Look it up in the registry rather than by name or hostname. RDAP on the address returns the netname and the organisation the block is registered to, which is what separates Naver's own space from a cloud tenant's and from another operator's delegation. Reverse DNS barely helps: the reverse zones sit on Naver Cloud's own nameservers, but the PTR records behind them are sparse - a full sweep of one /24 returned four names, all mail hosts - and the addresses naver.com answers on have none. Nor does checking the address your browser used to reach Naver - www.naver.com is a CNAME into Akamai edge space, so the front page is served from a different network entirely.