Matching IP class to the risk you are actually managing
Buy the amount of address separation that defeats the observer you actually expect, and stop there. Sites that differ only in the final octet are visible as neighbours to anyone who pastes a domain into a public reverse lookup. Separating at the third octet takes a deliberate check to unpick. Separating at the second octet takes somebody who has decided your network is worth mapping. Most buyers are defending against the first case while shopping for the third.
Name the observer before you name the tier
The useful question is not "how far apart can I get these addresses" but "who do I not want joining these dots, and what will that person realistically do?" In ascending order of effort:
- The curious visitor. A client, a competitor, or a journalist who runs one reverse-IP lookup on a domain, reads the list of other names on that address, and stops there. Zero cost, zero skill, very common.
- The analyst with an afternoon. Pulls your linking domains out of a backlink tool, resolves them all, sorts the results by network block, and looks for stacks. Costs a tool subscription and a couple of hours.
- The systematic mapper. Works from routing and registration data rather than single lookups, treats whole allocations as one entity, and does not care that your addresses look different at a glance. Rare, deliberate, and aimed at a specific target.
What each step buys, honestly
| Separation | Defeats | Reasonable fit |
|---|---|---|
| Last octet only | Nothing. Neighbours are one query apart | Sites that are openly one operation anyway |
| Third octet | The casual lookup and the eyeball scan | The default for client estates and properties meant to read as independent |
| Second octet | Cluster-sorting in a backlink tool | A portfolio big enough that a whole block would stand out as yours |
| First octet | Anything short of registry-level mapping | Narrow cases where the mapping itself is the threat |
The honest default is one step down
For a single operator with a handful of properties, third-octet separation is almost always the right purchase. The jump to second-octet diversity starts paying for itself when the count is high enough that your addresses form a recognisable mass on their own, or when a client contract states the requirement. First-octet diversity answers a threat model most people never meet. If you cannot describe the observer who would defeat the cheaper tier, you do not need the expensive one yet; addresses can be added later without a migration.
No tier fixes an obvious footprint
Address diversity hides one signal: shared hosting location. It does nothing about the signals that are easier to read. If your sites run the same template with the same section order, repeat the same phrasing, share a contact form, link to each other in the same footer slot, and all launched the same fortnight, a reader sees one operation in about ninety seconds without touching a lookup tool. Separation is a footprint control, not a ranking input, and it will not make near-identical sites look independent.
Before you order
- Write the observer down in one sentence. If the sentence is vague, drop a tier.
- Check whether anything other than the address already connects the sites. Fix that first.
- Confirm nobody has promised a client a specific level of separation in writing.
- Decide the tier for the whole estate, not per site, so one carelessly placed address does not undo the rest. Sizing the count is a separate exercise, covered under sizing and selection.
Still not sure which way to go?
Tell us what you are building. If it needs less than you think, we will say so.