MyIPScan
IP Ranges

PLDT IP Ranges

PLDT is the largest carrier in the Philippines, and AS9299 is the IP Gateway network that carries most of its subscriber traffic. APNIC files the number as IPG-AS-AP under Philippine Long Distance Telephone Company, organisation handle ORG-PLDT1-AP, with remarks on the same record reading Philippine Internet Exchange and PHIX IPG AS. APNIC Labs ranks it first in the country by estimated user population at 27,809,705 users, 37.96 percent of Philippine internet users, ahead of Converge on AS17639 and Globe Telecom on AS4775.

ISP
Provider
PLDT
Primary ASN
AS9299
Category
ISP
Headquarters
Makati, Philippines
Announced IPv4 prefixes
520
Registry
APNIC

Known IP ranges

These prefixes are currently announced to the global routing table by AS9299 (IPG-AS-AP - Philippine Long Distance Telephone Company). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.

124.104.0.0/14
180.192.0.0/15
115.147.0.0/16
58.69.0.0/16
124.105.0.0/16
124.107.0.0/16
124.106.0.0/16
119.111.0.0/16
124.104.0.0/16
27.110.128.0/17
2001:4450::/29
2001:4451::/32
2001:4455::/32 (IPv6)

What does a PLDT IP mean in a privacy test?

A PLDT address as your visible IP means the request reached the site over a PLDT line in the Philippines with nothing tunnelling it. What is unusual about this network is how much APNIC whois will tell you about which kind of line. PLDT registers labelled child objects inside its own allocations: a lookup inside 124.104.0.0/14 returns a /19 named Residential_DSL whose remarks read HOME_DSL and this space has been assigned as DYNAMIC. A lookup on 58.69.100.100 returns something quite different, a /29 named SR, marked ASSIGNED NON-PORTABLE and STATIC, whose remark names a regional Center for Health Development. So two PLDT addresses that look alike in a lookup can be a rotating consumer pool and a fixed eight-address block belonging to a named public body, and only the child record separates them. Neither is rented compute, which is why an AS9299 result points at the local access line rather than at a proxy.

What PLDT publishes about its own address space

PLDT publishes no geofeed. APNIC supports a geofeed: attribute on inetnum objects pointing at an RFC 8805 CSV over HTTPS, and none of PLDT's allocations carry one. What PLDT does maintain is a labelled whois hierarchy, and the two parent allocations behind this ASN are not maintained by the same group. 124.104.0.0/14 is netname: IPG with mnt-lower: PHIX-NOC-AP; 180.192.0.0/14 is netname: PLDT-PH with mnt-lower: MAINT-PH-PLDT-ENGG. Both are ALLOCATED PORTABLE under org ORG-PLDT1-AP with abuse to IRT-PLDT-PH, so the lower maintainer is the field that tells you which internal team hands the space out. Labelling is uneven below that: the IPG block carries product-named and customer-named children, while 115.147.0.0/16, registered 2019-12-30, is a bare PLDT-PH object with nothing beneath it. PeeringDB adds the routing side, giving the IRR as-set as AS-PLDT, a selective peering policy, and presence at 17 exchanges across 6 facilities.

Two things the records do not cover. There is no city or region data anywhere in them, so a lookup that places a PLDT address in the wrong province has nothing authoritative to be corrected against, and the country code PH is the operator's most specific published location claim. And the ASN registration date is not what it appears to be: APNIC's RDAP event for AS9299 reads 2008-09-04T06:40:32Z, seconds apart from AS7552 in Vietnam at 06:40:34Z and AS24560 in India at 06:40:39Z, so it timestamps a bulk database import rather than PLDT's original assignment. The allocation and assignment objects carry their own, later and more meaningful dates. On IPv6, PLDT engineering published its addressing plan through APNIC in December 2020: a /56 to each FTTH and DSL broadband customer, a /48 to each Enterprise I-Gate client, dual-stack rather than tunnelled, with half of PLDT's subscribers receiving IPv6 as of that article.

Telling a PLDT subscriber line from PLDT's own equipment

Reverse DNS is a weak signal here, and knowing that saves time. Addresses that answer at all answer with the dotted quad written forwards and the domain appended: 124.104.0.1 resolves to 124.104.0.1.pldt.net and 124.106.0.1 to 124.106.0.1.pldt.net. Sampled addresses in 180.192.0.0/14 and 124.105.0.0/16 returned NXDOMAIN instead, so the absence of a PTR is normal here and its presence carries no city, no product and no customer name. Nothing in that naming separates a home router from a PLDT aggregation interface.

The whois child object does the work the PTR does not, and there are three outcomes worth telling apart. If the most specific record covering the address is a large block marked DYNAMIC, you have a pool: the address is reassigned, so seeing it twice is poor evidence that it was the same household, and no end user is registered against it. If it is a small ASSIGNED NON-PORTABLE block marked STATIC with an organisation in the remarks, the opposite holds, and an inbound connection from it is that named subscriber's machine rather than PLDT's. If the lookup returns only the parent allocation, PLDT has published nothing finer and the honest answer is that you cannot tell. In all three cases this is access space rather than hosting, so a server answering on an AS9299 address is somebody's own equipment on a fixed line, not a rented instance.

Related tools

Frequently asked questions

What IP ranges does PLDT use?

PLDT announces its address space under AS9299, registered with APNIC as IPG-AS-AP to Philippine Long Distance Telephone Company under the organisation handle ORG-PLDT1-AP. The largest blocks currently in the routing table are listed above. The finer breakdown is in APNIC whois itself, where PLDT registers child objects inside those blocks and labels some of them by product or by customer.

Why does a PLDT address show up in my VPN or leak test?

Because the request reached the site over your PLDT line rather than through a tunnel. On a DNS leak test it means the resolver answering you sits on PLDT's network, which is the default on a PLDT connection. If you had a VPN running and expected a different exit, the tunnel is not carrying that traffic.

Does PLDT publish a geofeed for its address space?

No. APNIC supports a geofeed attribute on inetnum objects pointing at an RFC 8805 CSV, and PLDT has not filled one in on any of its allocations. That leaves the registry country code PH and whatever a commercial geolocation database has measured as the basis for placing a PLDT address, which is why lookups on the same block sometimes disagree about the province.

Is a PLDT address a home line or a business assignment?

The whois record will often tell you. PLDT registers residential space as large child objects marked DYNAMIC, with names such as Residential_DSL and remarks reading HOME_DSL, and registers business space as small assignments marked STATIC with the customer organisation named in the remarks. Check the most specific record covering the address rather than the parent allocation.

Why does one PLDT block return a product name and another return nothing?

Because PLDT has only labelled part of its space. The allocation at 124.104.0.0/14, netname IPG, has product-named and customer-named child objects registered inside it. The allocation at 115.147.0.0/16, netname PLDT-PH and registered 2019-12-30, has none, so the most specific record you can retrieve for an address in it is the /16 itself. Nothing about the connection differs; only the amount PLDT chose to publish does.