Technical possibilities and limitations for law enforcement
In the practice of criminal proceedings, cases increasingly arise in which access to internet services – including cloud services such as Microsoft 365 – was carried out using Starlink satellite Internet access. This model differs significantly from classic fixed and mobile connections, which has a direct bearing on the possibilities of identifying users and interpreting telecommunications data.
The specifics of the Starlink architecture
The Starlink service is provided on the basis of a global satellite infrastructure managed by SpaceX. The user's connection to the Internet is made via a satellite terminal that communicates with a constellation of satellites in low Earth orbit, then with ground base stations (gateways) and the operator's points of presence (POP).
Unlike traditional DSL, fibre or mobile (LTE/5G) operators, the IP address is not assigned from a regional pool linked to specific ground infrastructure or the subscriber's location. Addressing in Starlink is global and centralised.
The significance of the IP address in the logs of external systems
The IP address visible in the logs of external systems – such as Microsoft 365 – is not an address assigned directly to the user's terminal in a local sense. It is an address representing a network session in the Starlink operator's infrastructure, coming from global IPv4 pools managed centrally.
In practice this means that:
- the IP address identifies the point at which traffic exits to the Internet within the Starlink network,
- it does not identify the user's physical location,
- it is not permanently assigned to a single subscriber or a single terminal.
The IP address is therefore merely an element of the technical context of the session, and not a stand-alone basis for establishing the user's identity.
NAT mechanisms and IP-address sharing
The Starlink architecture uses network address translation (NAT) mechanisms, including solutions similar to Carrier-Grade NAT (CGNAT). In such a model:
- many users may share the same public IP address,
- IP addresses are rotated dynamically between sessions,
- there is no fixed "one subscriber – one IP address" relationship.
For law enforcement, this means that an IP address recorded in the logs of an external service does not, on its own, allow an activity to be unambiguously attributed to a specific person or device.
Interpreting PTR names and DNS data
The canonical (PTR) names assigned to IP addresses in the Starlink network, such as customer.wrswpol1.pop.starlinkisp.net, reflect the operator's internal naming scheme. They contain designations of points of presence (POP) and the operator's networks, but:
- they do not identify the end user,
- they do not contain the terminal number,
- they do not indicate the place where the service is physically used.
The absence of detailed DNS records is a natural feature of infrastructure with dynamic addressing and a high scale of resource sharing.
Dynamic traffic exit points
Starlink satellite access is also characterised by dynamic changes in the points at which traffic exits to the Internet. Depending on:
- network load,
- satellite availability,
- the operator's current configuration,
successive sessions of the same user may be carried out from different IP addresses, belonging to different address pools. The lack of address continuity between sessions is a phenomenon typical of global satellite networks.
The real possibilities for law enforcement
In an evidentiary context, it must be clearly stated that:
- a Starlink IP address does not identify the user, but the operator's infrastructure,
- the only entity holding data that allows a session to be linked to a specific subscriber, terminal and timestamp is the satellite service operator,
- effective identification requires precise time data and a formal request to the operator under international mutual legal assistance.
Without operator data, the IP address remains merely a technical parameter of the session, and not proof of identity.
Practical conclusions
IP addresses originating from the Starlink network, recorded in systems such as Microsoft 365, reflect only the technical point of contact between the operator's infrastructure and the public Internet. They contain no information about the end user, the device or the place where the service is physically used.
Understanding the specifics of satellite access is crucial for a correct assessment of the evidentiary material, the formulation of evidentiary requests and avoiding erroneous assumptions about identifying the perpetrator on the basis of the IP address alone.
In practice, SpaceX (at the time of preparing this opinion), as the operator of the Starlink satellite Internet-access service, does not run a publicly available or self-service online platform for the ongoing handling of law-enforcement requests, in particular one enabling the automatic establishment of subscriber data. Information about users, terminals or network sessions is disclosed solely in the manner provided for by the applicable law, on the basis of a formal request. For technical fulfilment it is necessary to provide at least the public IP address, a precise timestamp of the event (with the time zone specified), the type of protocol or service through which the connection was made, and – where possible – information about the source port or session identifier, without which unambiguously linking the event to a specific subscriber in a satellite-network architecture is technically impossible.