Web analytics8 min read

How to identify companies visiting your website

Reverse-IP tools can put company names on part of your anonymous B2B traffic - genuinely useful for sales, structurally incapable of naming everyone. How the identification works, what coverage really looks like, and the legal lines.

By The Bigdelta team
How to identify companies visiting your website

The mechanism: an IP address with a company name on it

Companies of any size connect to the internet through IP addresses that are registered, bought or leased - and those registrations are partly public. Regional registries like RIPE and ARIN record which organization holds which ranges; vendors layer ISP data and their own databases on top. When someone browses your site from an office network, their IP can be looked up against that map, and the visit gets labeled: someone at Siemens read your pricing page twice this week.

That's the whole trick. No cookies from the visitor's employer, no login - just the network they happened to connect through, matched against a database of who owns what.

What you get - and what you never get

A match produces firmographics: company name, industry, size, location, plus the pages viewed and when. What it never produces is the person. "Someone at Siemens" might be a procurement director or an intern killing time, and the technology cannot tell you which - the anonymous-individual wall stands here exactly as it does everywhere else in analytics.

That shapes what the data is for. Sales and account-based marketing teams use it as an early-warning system - which target accounts are researching us, which cold outreach to warm up. As general analytics it adds little: your traffic questions are already answerable in aggregate without knowing employers.

Coverage: honestly, under half

The structural problem is that fewer and fewer visits come from identifiable office networks. Remote workers arrive on home connections that resolve to their ISP; phones sit behind carrier-grade NAT that pools thousands of users onto shared addresses; VPNs mask origins entirely. Leadfeeder - one of the category's oldest vendors - declines to publish a match rate at all, saying results vary by audience. One vendor benchmark across 1.2 million B2B sessions in 2026 matched about 47% of visits to a company, with only around a fifth of visits matched at high confidence - a vendor's own number, but directionally consistent with everything else in the category.

The practical read: expect company names on a meaningful minority of your B2B traffic, more if your audience sits in offices in well-mapped markets like Europe, less if it's remote-heavy, mobile-heavy or American. Any vendor promising to identify "all" your visitors is describing a product that cannot exist.

The tool landscape

The established names do company-level identification: Leadfeeder (now part of Dealfront, European roots and a strong European database), Albacross (similar, Nordic-leaning), and Clearbit, which HubSpot acquired in December 2023 and folded into its CRM as the enrichment layer. Most offer free tiers or trials generous enough to learn what your own match rate actually is before paying.

A newer, spikier corner claims person-level identification - naming the individual visitor, not the company - for US traffic only, via identity graphs joined to device signals. Those products restrict themselves to the US by their own account because the approach doesn't survive GDPR, and they're controversial well beyond Europe: plenty of teams refuse them on principle whatever the legal position. Worth knowing they exist, if only to recognize the category's claims.

The legal position, briefly

In the EU, the starting point is that IP addresses can be personal data - the Court of Justice settled that in the Breyer ruling back in 2016. Company-level identification generally operates on a legitimate-interest basis in B2B contexts, which still obliges transparency: the practice disclosed in your privacy policy, an opt-out available, the assessment documented. Person-level identification is a different animal - consent territory in the EU, and contested in the US state by state. None of this is legal advice; it's the map of where the questions live, and a conversation with counsel belongs before a person-level tool ever ships.

The free DIY route

If you just want a taste, your server logs already contain visitor IPs, and a reverse DNS lookup on them surfaces the offices whose networks announce themselves - universities, agencies, enterprises with configured PTR records. Coverage is worse than any paid database and the workflow is manual, but the price is zero and it demonstrates the mechanism on your own traffic in an afternoon.

The practical takeaway

Company identification is a sales tool wearing analytics clothing: genuinely useful for spotting which accounts are warming up, structurally limited to the minority of traffic that arrives on identifiable networks, and legally workable at the company level if you're transparent about it. For knowing your visitors in the analytics sense, the better instrument is the one that scales to everyone: aggregate behavior, and identity offered voluntarily - the visitor who signs up and becomes a person in your data because they chose to be.