Intel8/30/2026 · 7 min read

How to Audit Your Unused IP Address Blocks

A step-by-step internal audit for IP holders: pull your RIR records, compare them with BGP announcements, measure real usage, separate NAT-hidden capacity, and turn the result into consolidation, leasing or a sale.

How to Audit Your Unused IP Address Blocks

Allocation is not usage

Every one of the roughly **4.3 billion IPv4 addresses** is allocated. The free pools exhausted between **2011 and 2020**, and since then the only way to get address space is from someone who already holds it. That makes your registered blocks a genuine asset — and, for most organisations, an unaudited one. Registration records say what was assigned to you years ago. They say nothing about whether the space is still in use. Companies that grew through acquisitions, changed data centres, migrated services to the cloud, or switched to NAT years ago routinely hold blocks that are fully "assigned" on paper and nearly empty in practice. The audit below turns that guesswork into a number.

Step 1 — Pull your RIR records

Start with the registry, not the network. Export every allocation and assignment held under your organisation name from your RIR's portal. The **RIPE region — Europe and Türkiye — carries the highest transfer volume in the world**, and its registration data is a good model for what you want from any registry: prefix, size, allocation date, and the organisational object it is tied to. Pay special attention to legacy space and blocks acquired with company purchases. Those are the ones nobody updates, and they are exactly where unused space hides.

Step 2 — Compare with BGP announcements

Now ask the network what it actually sees. Pull the prefixes announced for your ASNs from a route collector or your own edge routers, and match them against your registry export. You will get three buckets: - **Announced and active** — your working space. - **Announced but quiet** — routed, yet carrying little or no traffic. - **Unannounced** — registered to you, but not visible on the internet at all. The third bucket deserves your attention immediately. A block that is not announced is not necessarily empty — and an unannounced block that still answers to something, or carries an old firewall config or a forgotten server, is a **silent attack surface in your name**. Dormant space does not stop being your responsibility when you stop using it.

Step 3 — Measure actual usage

Routing says a prefix exists; measurement says it works. For each announced prefix, look at flows, NAT session counts, DNS queries and syslog volume over a representative window — two to four weeks catches weekly cycles without dragging the audit out. A /24 with five active servers and 250 addresses that never answer is not "nearly full". It is 250 idle addresses. When you sum that across dozens of prefixes, most organisations find tens of thousands of unused addresses without touching a single production system.

Step 4 — Separate NAT-hidden capacity

NAT is the auditor's blind spot. Whole office networks sit behind a handful of public addresses, so a block can look busy in the logs while serving only a fraction of its potential. Separate your space into three classes: - **Infrastructure** — routers, VPN endpoints, mail servers, monitoring. Must stay. - **NAT and service pools** — real, measured utilisation that justifies the allocation. - **Everything else** — spare capacity with no owner, no traffic, and no plan. The third class is your audit result: the unused IP address blocks you can act on today.

Three actions from the result

Your options, in order of increasing commitment: - **Consolidate.** Merge scattered fragments into clean, contiguous blocks. Clean space is easier to manage, easier to route, and worth more per address if you ever monetise it. - **Lease.** Idle space earns roughly **$0.40 per IP per month** — over $1,200 a year for a single /24, from addresses that currently cost you attention and risk. Leasing keeps ownership while making the space productive. - **Sell.** If the space is genuinely surplus to your needs, transfers still price near **$27 per IP for a /24** — around $6,900 for that block, with larger blocks cheaper per address. A sale converts an idle asset into cash and ends the maintenance burden permanently. None of these are possible without the inventory. And if the audit reveals space you cannot explain — registered, unannounced, and talking to the internet — treat it as a security finding before you treat it as revenue. The blocks that are simply dark, documented and clean are the ones worth putting to work. That is exactly the kind of space IPDORM maps. --- *See where your registered space really sits — dark, dormant, or in use — on the IPDORM dark space map: [ipdorm.com](https://ipdorm.com).*