CorporateWebsiteMarketing.com logoCorporate Website MarketingB2B website marketing since 2003
Website & ConversionMeasurement & Optimization

B2B Website Visitor Tracking

Reverse-IP identifies the organisation assigned an IP range. That is not a person, and not necessarily the visitor's employer.

What is actually being identified

B2B website visitor tracking, in its mainstream form, matches the public IP address of an anonymous visit to an organisation, then joins that organisation to a firmographic record so a dashboard can report that a named company viewed particular pages. It is account-level identification. Nothing in the mechanism identifies a person.

That distinction matters more than anything else here, because two different products are sold under overlapping names. Account-level identification infers an organisation from network data. Person-level identification, marketed as anonymous website visitor identification or website deanonymization in b2b marketing, tries to resolve a visit to a named individual with a contactable email address by querying a third-party identity graph. The mechanisms differ, the accuracy profiles differ, and the legal exposure differs materially.

What is true by construction of the first technique: reverse-IP identifies an organisation that owns or is assigned an IP range. Whether that organisation is the visitor's employer is an inference, and often a poor one.

The mechanism, step by step

The chain is short, and every weakness in it appears in your report.

  1. The browser makes a request. A server log or JavaScript tag records the public IP address of the connection.
  2. That address is looked up against a database mapping IP ranges to organisations. The authoritative raw inputs are Regional Internet Registry records from ARIN, RIPE NCC, APNIC, LACNIC and AFRINIC: WHOIS and RDAP allocation records and the organisation name or netname on an allocated block, plus autonomous system number ownership, BGP routing data and reverse DNS hostnames.
  3. Vendors augment that picture with their own crawling, DNS heuristics, leased-block tracking, and inference where registry data is stale.
  4. The output is a company guess, usually a name and a domain, joined to a firmographic database to produce the line in the dashboard.

Most tools here are an interface over IP intelligence data licensed from a few providers: IPinfo, Digital Element, MaxMind, IP2Location, DB-IP.

Where the accuracy goes

The degradations are well understood and none is controversial.

  • Remote and hybrid work. The largest single problem. An employee at home appears on a residential ISP range, so the honest answer is the ISP. Vendors return the ISP, return nothing, or guess, and the guessing is where false positives come from.
  • Mobile and carrier-grade NAT. Mobile networks place thousands of unrelated users behind shared addresses, so mobile traffic is unidentifiable at company level.
  • VPNs, proxies and zero-trust egress. A consumer VPN makes the visitor look like a datacentre; a corporate VPN can resolve a home worker correctly to the employer, the one case where it helps.
  • Shared and serviced offices, universities and hospitals. These resolve to the landlord or parent institution, not the tenant.
  • Stale registry data. Blocks are sold, leased and reassigned while the registered organisation name lags.
  • IPv6. Allocation is frequently per-ISP-customer and less consistently annotated than legacy corporate IPv4 blocks.
  • Datacentre and bot traffic. Scanners, previewers and AI crawlers generate volume that unfiltered tools report as visits from cloud providers.

No vendor here publishes an independently audited accuracy or match rate. Every figure quoted to you is vendor-defined.

Person-level identification is a different product

The aggressive end of the market promises to identify anonymous website visitors by name and personal email with no form submitted. The mechanism is not reverse-IP. A pixel passes a device or browser signal, such as hashed identifiers, cookie syncs, or IP combined with device characteristics, to a third-party identity graph assembled from data brokers, publisher logins, loyalty schemes, app software development kits and previous form fills. If the graph already holds a persistent identifier for that browser, a match can be returned.

That explains the accuracy pattern. It works best on desktop Chrome where third-party storage is available, worse in Safari and Firefox because of their tracking protections, worse again on iOS, and not at all where the visitor has never entered the graph. Match rates therefore depend on the composition of your traffic, and vendor denominators are rarely defined. These services are generally sold for United States traffic only, for legal rather than technical reasons.

What the law requires you to disclose

None of this is legal advice, and counsel should review any deployment.

Europe and the United Kingdom. The Court of Justice held in Breyer (Case C-582/14, judgment 19 October 2016) that a dynamic IP address held by an online media services provider is personal data where the provider has the legal means to identify the individual with ISP-held data. Storing or reading information on a visitor's device engages Article 5(3) of the ePrivacy Directive, PECR regulation 6 in the UK, which requires prior consent for anything not strictly necessary; legitimate interests is not a substitute. The EDPB's final Guidelines 2/2023, adopted 16 October 2024, extend that analysis to pixel tracking and to tracking based on IP address alone. Where you obtain personal data about someone from a third party rather than from them, GDPR Article 14 duties apply, and they include telling the person the source.

United States. IP addresses, device identifiers and online activity are personal information under the CCPA as amended and the newer state statutes. The exposure points are notice at collection; opt-out of sale, sharing and targeted advertising; honouring Global Privacy Control, which California's regulations require to be treated as a valid opt-out and which is the only mechanism on Colorado's recognised list, mandatory there since 1 July 2024; and data-broker registration in California, Texas, Oregon and Vermont.

What has to be true before it is worth buying

This category fails more often from missing prerequisites than from bad data. Four things must already exist.

  • A named account list. Company-level signals are actionable only against companies you have decided to pursue. Without a list, the output is a directory of organisations you have no plan for.
  • Sales capacity and a defined play. Somebody must act, and the action must be proportionate to the evidence. An account viewing three technical pages over two weeks justifies a referenced approach. A single pageview justifies nothing.
  • A CRM that can hold account-level engagement. Data living only in a vendor dashboard is ignored within weeks.
  • A privacy notice and consent configuration that describe what you are doing. For EU and UK traffic the consent gate decides whether the script may fire at all.

Filter aggressively before anyone sees the report: exclude datacentre ranges, known bots, your own offices, your agencies and existing customers' support traffic.

Where this goes wrong in practice

  • Treating identified companies as leads. They are weak signals about organisations. Passing a raw list to sales as an enquiry queue produces cold calls referencing a visit the recipient never made.
  • Mentioning the visit on the call. Telling somebody you noticed their company reading your pricing page is legally awkward and commercially unnerving. Use the signal for timing and relevance; do not narrate it.
  • Counting ISPs as accounts. If the top ten rows are telecoms carriers and cloud providers, the tool is describing network topology, not your market.
  • Running person-level identification against European traffic. The prior-consent requirement and the Article 14 duty to disclose the source make it unworkable in practice, which is exactly why vendors restrict it to US traffic.
  • Buying it for a market it cannot see. If your buyers are sole traders, small firms on consumer broadband, or field staff on mobile connections, reverse-IP will return a list of ISPs, whatever the sales demonstration showed.

When to skip it, and what good looks like

Skip it when your addressable market is small companies, when your traffic is mostly mobile or residential, when you have no target account list, or when nobody can act on a signal within a few days. Skip it too when the only use is a slide of recognisable logos for the board; that is expensive decoration.

It earns its place in one configuration: a defined list of larger organisations with their own registered address space, a sales team already working those accounts, and a few high-intent pages whose viewing genuinely changes what happens next. There it is a timing signal layered onto an account-based programme, not a lead source.

What good looks like: a filtered feed limited to target accounts, alerts only on defined page combinations, engagement written back to the CRM account record, a documented consent decision for EU and UK visitors, a working opt-out that honours Global Privacy Control, and a quarterly review asking how many opportunities this actually started.

Frequently Asked Questions

How accurate is B2B website visitor identification?

Nobody can tell you in a way you should believe. No vendor in this category publishes an independently audited accuracy or match rate, there is no shared benchmark, and the denominators behind vendor figures are chosen by the vendor.

What can honestly be said is directional: reverse-IP works best for on-premises traffic from large organisations with their own registered address space, and degrades sharply for small companies, remote workers, mobile visitors and anyone behind a consumer ISP or VPN.

Can we identify anonymous website visitors legally in the EU or UK?

Reading identifiers from a visitor's device engages Article 5(3) of the ePrivacy Directive, PECR regulation 6 in the UK, which requires prior consent for anything not strictly necessary; legitimate interests cannot be substituted. The EDPB's Guidelines 2/2023 apply that analysis to pixel tracking and to IP-based tracking.

If you then resolve a visitor to a named person using third-party data, GDPR Article 14 requires you to inform them, including the source. That is why person-level services are sold for US traffic.

Do we have to disclose visitor tracking in our privacy policy?

Yes, and in plain terms. Under US state law the duties include notice at or before collection, disclosure of the categories of personal information collected and of recipients, an opt-out of sale and sharing where applicable, and honouring Global Privacy Control; California's regulations require a conforming opt-out preference signal to be processed as a valid request.

Note that the CCPA exemption for business-to-business contact data expired on 1 January 2023.

Why does our visitor report show Comcast and Amazon instead of company names?

Because that is what the addresses resolve to. Residential ISP ranges mean somebody worked from home; datacentre ranges usually mean a bot, a scanner, a link previewer, an AI crawler or a visitor on a VPN. Reverse-IP can only report the organisation assigned the range.

The response is filtering rather than a different vendor. If carriers and cloud providers dominate the report, the technique does not fit your audience.