The Limits of IP Geolocation: What City-Level Accuracy Really Means for Fraud Rules
An IP geolocation database will confidently tell you a user is in a specific city, and it will be wrong often enough to matter. The honest picture is that IP location is excellent at the country level and increasingly unreliable the more precise you ask it to be.
Teams get burned when they treat a city or a set of coordinates as ground truth. Geolocation is an inference built from registry data, routing information, and observed latency, not a GPS fix. Understanding where it breaks is the difference between fraud rules that catch attackers and rules that flag your best customers.
Why geolocation degrades with precision
The data behind IP location is coarse and lumpy:
- Registry allocation tells you which organization holds a block and its rough region, not where a specific address is used today.
- Routing and latency inference narrows things down but is distorted by backbone paths and peering.
- Reassignment lag means databases trail real-world changes by days or weeks.
The result is a reliable country signal, a shakier region signal, and a frequently wrong city signal. Coordinates returned to several decimal places imply a precision the underlying data simply does not have.
Network types that wreck city accuracy
Certain topologies make city-level location nearly meaningless:
- Mobile carriers. Regional egress gateways place subscribers at the gateway, not their real location. A phone user can geolocate a hundred miles from where they stand.
- CGNAT and shared IPs. One address fronts users across a wide area, so any single “location” is an average of many.
- Corporate and VPN egress. Traffic exits where the network egresses, often a different city or country from the user.
- Satellite and fixed-wireless ISPs. These can anchor huge coverage areas to a single registration point.
In all of these, a city-level geo lookup returns a plausible-looking but effectively random point within a large area.
Building rules that respect the real accuracy
The fix is to use geolocation at the resolution it actually supports and to lean on device identity for the rest. Prynt returns geolocation alongside the owning ASN and its type, plus a stable visitorId, so you can size your geo tolerances to the network and confirm suspicious location changes against a device that does not lie about who it is. See how the network signals pair geolocation with ASN context so you know when a city reading is trustworthy and when it is a gateway artifact.
Practical guidance:
- Enforce at country level, advise at city level. Use country for hard geo rules (sanctions, licensing). Treat city as a soft, low-weight signal.
- Size tolerance bands by ASN type. Give mobile and CGNAT ASNs wide impossible-travel radii; tighten only for fixed broadband where location is more stable.
- Never act on a single geo jump. Confirm a suspected account takeover with a new-device signal or behavioral change, not one fuzzy hop between cities.
- Prefer consistency over precision. A device that reliably geolocates to the same metro is more informative than the exact city, which may be an artifact.
Communicating accuracy to your rules team
A surprising amount of geolocation trouble is organizational: an analyst sees a city name in a database and treats it as a fact, then writes a rule that assumes it. Fix this by carrying an accuracy expectation alongside every location, coarse for mobile and CGNAT ASNs, finer for fixed broadband, and making that expectation visible in your tooling. When a reviewer sees “region-level estimate, mobile carrier” instead of a deceptively precise pin on a map, they build rules that respect the error bars. The technology matters less here than the shared understanding that a city reading is an estimate with real uncertainty, not a coordinate to be trusted blindly.
Where geolocation still earns its keep
Despite the limits, IP location remains valuable when used correctly:
- Country-level compliance and licensing, where accuracy is genuinely high.
- Coarse anomaly detection, spotting a login from an entirely different continent than a user’s established pattern.
- Corroboration, adding weight to a case already built on device and behavioral signals rather than standing alone.
The mistake is not using geolocation, it is trusting it beyond its resolution. City-level readings are estimates with error bars measured in tens or hundreds of miles, and any rule that treats them as exact will manufacture false positives on mobile users, travelers, and anyone behind shared infrastructure.
Match your geo rules to real accuracy and back them with device identity. Start free on the pricing page and test country and ASN-aware geo signals against your own traffic.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.