Check suspicious IPs from Slack
Add an anonymization check to the conversation where a questionable IP was raised.
Trigger
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Action
IP2Proxy: Get Proxy Detection
Tool to detect if an IP is a proxy, VPN, or TOR exit node. Use when verifying anonymizing services.
Why this helps
A security concern can sit unresolved while someone switches tools to check whether an IP uses anonymizing services.
- Check a shared IP for proxy, VPN, or TOR indicators.
- Keep the result with the original Slack discussion.
- Reduce the steps needed to triage a flagged address.
Setup
Build it in a few focused steps.
- 1Connect Slack and Ip2location to Notis once.
- 2Create an automation in the portal and write one plain-language instruction to check suspicious IPs posted in the selected channel with IP2Proxy.
- 3Choose Channel Message Received as the trigger and select a channel for run reports.
- 4Test with a real example IP that your team is authorized to assess.
Questions about this workflow
Does this determine whether an account is compromised?
No. The action checks whether an IP is identified as a proxy, VPN, or TOR exit node; it does not establish account compromise.
Can the prompt focus on a security channel?
Yes. Select the channel message trigger and describe the intended channel and reporting behavior in your instruction.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Slack to Ip2location. A trigger fires from one place; an action lands in another.
Slack triggers
Ip2location actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Bulk IP Geolocation
Tool to retrieve geolocation information for multiple IP addresses in bulk. Use when you need batch processing of up to 1000 IPs per request.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Check IP2Location API Credits
Tool to check remaining IP2Location API credits. Use after setting up authentication to monitor usage.
New Channel Created Trigger
Triggered when a new channel is created in Slack.
IP2WHOIS Hosted Domains Lookup
Tool to retrieve hosted domains for a given IP address. Use when you need to list domains hosted on an IP.
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
IP2Location Get IP Geolocation
Tool to retrieve geolocation data for an IP address. Use when detailed IP location info is needed.
Direct Message Received
Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.
IP2Proxy: Get Proxy Detection
Tool to detect if an IP is a proxy, VPN, or TOR exit node. Use when verifying anonymizing services.
Message Reaction Added
Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.
IP2Location Distance Calculator
Tool to calculate distance between two IPs. Use when geographic separation between two IP addresses is needed.
Message Reaction Removed
Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.
IP2WHOIS Domain WHOIS Lookup
Tool to retrieve WHOIS information for a domain. Use when you need domain registration details.
Reaction Added Trigger
DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.
IP2Location List IPs
Tool to list a curated set of test IPv4 and IPv6 addresses. Use when sample IPs are needed for IP2Location or IP2Proxy lookups during development or testing.
Connect any two apps with Notis in the middle.
Slack and Ip2location, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Ip2location.