Whoer
Whoer.net is a browser-based network and privacy diagnostic website. When you open it, the service displays the public IP address seen by its server and adds context such as approximate location, internet service provider (ISP), autonomous system number (ASN), proxy or VPN signals, DNS and WebRTC test results, blacklist status, and browser-visible characteristics.
Whoer is useful for checking what one browser session and network connection reveal at that moment. It does not certify that a connection is private, that an IP address is trusted everywhere, or that an account or workflow will be accepted by another platform. Its combined score is a Whoer-specific summary, not a universal security or platform-risk rating.
Quick Answer
- Whoer shows the public IP and technical signals visible from a web session.
- It combines request data, IP databases, browser-side information, and active leak tests.
- A warning or mismatch is a clue to investigate, not proof of abuse or a guaranteed explanation for a platform decision.
- Whoer’s score is different from an IP risk score based on reputation, fraud, or abuse intelligence.
- Browser diagnostics cannot inspect every signal available to a native Android app.
What Whoer Checks
Whoer brings several types of checks into one interface. They do not all come from the same source, so it helps to read them as separate layers.
|
Check area |
Examples shown by Whoer |
What the result can tell you |
|
Connection and IP information |
Public IP, hostname, country or city, ISP, organization, ASN |
How the current request appears to Whoer’s server and how its data sources classify the network |
|
VPN, proxy, Tor, and blacklist signals |
Tunnel or proxy indicators, network type, known Tor exit nodes, blacklist status |
Whether Whoer’s rules or data sources associate the connection with one of these categories |
|
Leak and consistency tests |
DNS resolvers, WebRTC results, IP differences, timezone or language differences |
Whether information exposed through different browser and network paths appears inconsistent |
|
Browser and system signals |
User-Agent, HTTP headers, language, timezone, screen information, JavaScript and WebRTC status, plugins |
A partial view of the characteristics the browser shares with a website |
Connection and IP Information
Every website you visit receives a network request, and that request includes a source address visible to the destination. Whoer starts with this public IP, then uses network and geolocation data to label it with an approximate country or city, ISP, organization, and ASN.
A public IP is not the same as the private address used inside a home or office network. The IP Address glossary explains that distinction in more detail. Location should also be treated as an estimate: an IP may map to an ISP gateway, mobile carrier exit point, data center, or another network location rather than a person’s exact physical position.
VPN, Proxy, Tor, and Blacklist Signals
Whoer applies its own checks and data sources to look for signs associated with VPNs, proxies, Tor exit nodes, data-center networks, and blacklisted addresses. These labels are not interchangeable. A network can be recognized as a hosting provider without appearing on an abuse blocklist, while another address may have reputation history without being part of a VPN service.
Detection is also not absolute. Providers update infrastructure, databases refresh at different times, and classification rules vary. Treat the label as Whoer’s current assessment of the connection, not a permanent fact about the address.
DNS, WebRTC, and IP Leak Tests
A DNS test looks at the resolver path used to translate domain names. In a VPN or proxy context, a result may be called a “leak” when DNS requests follow a path that differs from the route the user expected. A WebRTC test examines network information exposed through browser communication features. Depending on the browser, operating system, and network configuration, those tests may reveal additional addresses or produce a mismatch.
The useful question is not simply whether a row is red or green. Ask what route you expected, which resolver or address appeared, and whether the result can be reproduced in the same setup. Whoer can report the observation, but it cannot know the purpose, authorization, or policy context of the session.
Browser and System Signals
Websites can observe more than an IP address. Browser version, operating system, language, timezone, screen properties, rendering behavior, and other values can contribute to a browser fingerprint. Whoer displays a subset of these values and highlights combinations it considers unusual or inconsistent.
These signals also have ordinary uses. A website may read language to localize content, screen size to choose a layout, or browser capabilities to decide which features it can run. The W3C’s fingerprinting guidance recognizes both legitimate security uses and privacy risks. A diagnostic result therefore needs context; the presence of a signal is not, by itself, evidence of harmful behavior.
How Whoer Produces Its Results
Whoer’s public pages and privacy policy confirm several kinds of input, but they do not disclose every data provider or the complete scoring formula. The report can be understood as a combination of:
- Server-visible request data. The service can see the public IP and HTTP headers sent with the browser request.
- IP-derived labels and heuristics. It adds location, network ownership, ASN, VPN/proxy/Tor, and blacklist assessments to the observed address. The sources and rules behind every label are not fully public.
- Browser-side signals. JavaScript and browser APIs may expose values such as User-Agent, language, timezone, screen information, WebRTC status, and other environment details.
- Test-specific network requests. DNS and WebRTC checks may generate requests that reveal which addresses or resolvers appear through those paths. Whoer’s separate port-scanner utility instead probes a target supplied by the user and should be treated as a different test.
- Whoer’s own scoring rules. The site combines selected findings into a summary score or warning display. Its complete formula is not public and should not be assumed to match another service.
This combination explains why one page can show an IP address, a network category, several browser attributes, and a single score. It also explains why the score should never be read without the underlying rows.
How to Read a Whoer Result
Start with the raw observations, then work toward the summary.
Confirm What You Expected to Test
Record the browser profile, network route, and time of the check. If you expected a direct connection, the ISP and approximate region should describe that route. If you were testing an authorized VPN or proxy setup, the visible endpoint should reflect that setup. Compare the same conditions when repeating a test; otherwise, a changed result may simply come from a different network or browser state.
Treat Mismatches as Diagnostic Clues
A language, timezone, DNS, WebRTC, or header mismatch can have many causes, including normal travel, remote work, corporate networks, browser settings, disabled scripts, stale data, or a configuration problem. It does not automatically prove deception, fraud, or policy abuse.
Investigate the specific row rather than changing unrelated settings. Random changes made only to improve a checker result can make troubleshooting harder and create new inconsistencies.
Separate the Whoer Score From an IP Risk Score
A high value can mean different things on different services. Whoer’s combined score summarizes its own privacy, leak, and consistency checks. An IP reputation or fraud service may instead score abuse reports, spam history, hosting classification, transaction patterns, or threat intelligence. On some services, a higher number means a better result; on others, it means greater risk.
Do not compare two numbers until you know what each service measures, which direction the scale runs, and when its data was updated. A good-looking Whoer score does not guarantee that an IP has a clean reputation elsewhere.
Do Not Treat 100% as a Goal or Guarantee
The purpose of a diagnostic check is to understand what is visible, not to engineer a perfect label. A 100% result cannot guarantee privacy, security, compliance, or account safety. A social platform may consider account history, permissions, behavior, payment information, app data, device identifiers, policy compliance, and many other signals that a public browser checker cannot see.
Why IP Checkers Can Disagree
Two tools can inspect the same connection and still return different answers. Common reasons include:
- Different datasets. Services may license different geolocation, ASN, proxy, VPN, or reputation databases.
- Different update times. An IP allocation or network classification may change before every provider refreshes its records.
- Different categories. One service may call a network “hosting,” another “business,” and another “VPN” based on its own taxonomy.
- Different test surfaces. A basic IP lookup may not run DNS, WebRTC, or browser tests at all.
- Different scoring formulas. A privacy score, leak score, fraud score, and abuse-confidence score answer different questions.
- Different browser conditions. Script blocking, permission settings, extensions, and embedded-versus-top-level pages can change what a test observes.
For comparison, the EFF’s Cover Your Tracks focuses on browser tracking and fingerprinting rather than reproducing Whoer’s complete network report. Neither result should be treated as the single authoritative view of a device or connection.
Privacy and Responsible Use
A diagnostic website must receive technical information to produce a report. Whoer’s current privacy policy says its tools process data that can include IP address, coarse location, User-Agent, operating system and browser details, language, website activity, tool-specific networking signals, cookies, and local storage. It also describes advertising and measurement partners.
That does not support a blanket “safe” or “unsafe” verdict. Before using any checker, review its current privacy terms, cookie controls, retention statements, and third-party disclosures. Avoid entering unnecessary personal information. Only run port, host, or network tests against systems you own or are authorized to assess.
What Whoer Cannot Tell You About a Native App
Whoer runs in a browser. It can show the network and browser signals available to its webpage, but it cannot inspect every part of a native mobile workflow. Subject to Android permissions and platform rules, a native app may observe app data, device services, identifiers, and app-specific telemetry that are outside a public webpage’s view. Separately, the platform behind that app may evaluate account history and other server-side signals.
This is also why a browser check should not be used as a substitute for app testing. If a workflow moves between websites and native apps, test each environment on its own terms. Our guide to cloud phones versus multi-account browsers explains why browser profiles and Android environments solve different operational problems.
Where Whoer Fits in a GeeLark Workflow
For teams using GeeLark, Whoer can serve as one browser-based observation during an authorized setup or troubleshooting check. It can confirm which public IP and browser-visible signals appear in that session. It cannot validate the entire Android environment or predict how a third-party platform will evaluate an account.
GeeLark’s Cloud Phone provides persistent Android environments for native apps, along with profile organization, proxy configuration, automation tools, and team permissions. Those capabilities help teams organize mobile work; they are not a promise to pass a checker, remain anonymous, or avoid platform enforcement.
Frequently Asked Questions
Final Takeaway
Whoer is most useful as a snapshot of what one browser and network session reveal. Read the individual IP, DNS, WebRTC, proxy, blacklist, and browser results before looking at the combined score. When another checker disagrees, compare what each service actually measures instead of assuming one number is universally correct. For mobile teams, keep Whoer’s browser diagnostics separate from the broader task of organizing and testing persistent Android app environments.
Image to video

