F*** Fraud.
Check any IP for VPN, proxy, tor, datacenter, and abuse history. Sub-millisecond, free for everyone, no caps, no credit card. And the whole database behind it ships to GitHub, rebuilt every 30 minutes.
Result
185.220.101.34
Brandenburg, Germany · TORSERVERS-NET · Data Center
One API call. Every signal you need.
/01
Send the IP
Curl, fetch, or our SDK. Zero setup. The IP can come from your server, your edge, or your client. Wherever you have it.
/02
Get the verdict
Country, city, ASN, ISP, datacenter detection, VPN/Tor/proxy classification, abuse history, fraud score 0-100. Edge-cached.
/03
Act on it
Block, challenge, allow, or just log. We tell you what we know. What you do with it is your call.
No SDK.
No build step.
Just a curl.
- Public endpoint, no auth, no signup
- Edge-cached for 5 minutes
- No caps. A free key adds batch lookups + usage stats
$ curl https://api.ffraud.com/public/ip/8.8.8.8 { "ip": "8.8.8.8", "fraud_score": 60, "risk": "medium", "vpn": false, "hosting": true, "is_abuser": true, "connection_type": "Data Center", "ASN": 15169, "organization": "Google LLC", "geo": { "country": "US", "city": "Mountain View" } }
One IP call. Six places it pays for itself.
Drop a single fetch into your signup, login, checkout, or API gateway. Every signal you need to decide block / challenge / allow / log.
Block bad signups before they cost you anything.
Score the IP at registration. Disposable + datacenter + Tor signals catch 80% of fake accounts before they touch your DB.
"action": "block"Challenge. Don't reject. VPN users.
Real customers use NordVPN. Real attackers use NordVPN. The fraud_score + abuse history tells them apart so you know when to step up auth instead of locking out.
"action": "challenge"Hold orders from server farms.
No legitimate human shops from a bare datacenter IP. Catch the BIN-test bots before they validate your refund processor at scale.
"action": "hold"Stop spam at the network layer.
Known abusers, recently active scrapers, hijacked subnets. All flagged with confidence levels so you can tune how aggressive your filter wants to be.
"is_abuser": trueThrottle by reputation, not just rate.
A trusted residential ASN gets your full RPS. A flagged subnet gets soft-throttled before it can hammer your gateway. Same endpoint, smarter limits.
"shared_connection": trueFree, accurate, every visitor.
Country, region, city, lat/lon, timezone, ASN, ISP. The same dataset Cloudflare and Stripe pay for. Yours for free, full stop.
"city": "Mountain View"No tiers. No caps. No catch.
Everything ffraud knows is yours: the API is free without limits, the database is MIT-licensed open data on GitHub, and the community keeps both growing. Running something heavy? Tell us and we raise your rate limit. Still free.
The API
∞
lookups · free
Check IPs instantly, no signup needed. A free key adds batch lookups and usage stats. Fair-use rate limiting keeps it fast for everyone.
Read the docsThe data
1.1M+
abusive IPs · MIT
The whole database ships to GitHub, rebuilt every 30 minutes: confirmed-abusive IPs with scores, categories, and types, plus 219k disposable email domains. Fork it, ship it, build on it.
Browse on GitHubThe community
24/7
reports · verified
Anyone can report abusive IPs, attach evidence, and vote on reports. Confirmed reports roll into the next build within the half hour, with credit if you want it.
Report an IPStill want a pricing page? Here it is. It's one number.
Stop guessing.
Start checking.
Every signup, every checkout, every login. One IP call away from knowing whether to trust it. Free forever, no fine print.