What is this IP's reputation?
A single 0 to 100 score for any address, and every signal that produced it. Not a black box: the page shows you the evidence, so you can decide whether you agree with the number.
Result
185.220.101.34
Brandenburg, Germany · TORSERVERS-NET · Data Center
Pre-filled with a known Tor exit node. Type any address to score your own.
Behind every check
19.8 million
IP addresses profiled
2.4 million
malicious domains tracked
208,000
disposable email domains
1.9 million
networks scored
Counts read live from the engine, not written into the page. The full dataset is published on GitHub under the MIT license and rebuilt every 30 minutes.
How the score is built
The score is not a vote count and it is not one provider's opinion resold. An address is only listed as abusive once it has been independently confirmed at least twice, which keeps single-source noise out of the number.
Direct observation
Our own honeypot sensors record what actually hit them. This is first-party evidence, not a feed we bought.
Community reports
Reports from operators running real infrastructure, weighted by a trust tier that a reporter earns over time rather than gets on signup.
Independent threat feeds
Multiple established intelligence sources, cross-checked against each other. Agreement across genuinely independent sources counts; the same data republished under several names does not.
Network context
Reputation of the surrounding subnet and of the autonomous system, so an address in a block that is overwhelmingly abusive does not get graded as if it stood alone.
Infrastructure classification
VPN, proxy, Tor, residential proxy, datacenter, or consumer. Anonymization is a risk signal in context, not proof of wrongdoing on its own.
Confidence and completeness
Every result carries a confidence level and a data-completeness figure alongside the score. A low score on thin data is not the same statement as a low score on rich data, and pretending otherwise is how scoring systems mislead people. When we have not seen enough to be sure, the result says so instead of projecting false precision.
Checking your own address
Most people arriving here are checking themselves, usually because something blocked them and they want to know what it saw. Your own reputation is shaped by things you may not control: your provider's history, whether your address is shared through carrier-grade NAT, whether a VPN you use has been abused by other customers, and what the previous holder of the address did. The result page separates what is true of you from what is true of your neighborhood.
What the score looks like in practice.
Live results, fetched as this page loaded. The useful ones are the addresses whose flags and score disagree.
185.220.101.34
100/100 · critical
tor-exit-34.for-privacy.net · Tor, VPN, proxy, datacenter
Top of the scale. Confirmed abuse, anonymising infrastructure, and a reverse DNS name that confirms what it is.
1.1.1.1
5/100 · none
one.one.one.one · VPN, datacenter
The most instructive result here. It carries VPN and datacenter flags and still scores near zero, because flags are context and not a verdict.
8.8.8.8
5/100 · none
dns.google · datacenter
Datacenter, and clean. If a hosting flag alone drove the score, this would rank as risky, which is exactly the mistake to avoid.
45.148.10.121
100/100 · critical
no PTR record · Tor, datacenter
Confirmed abusive with no hostname to go on, scored on behaviour rather than on naming.
52.95.110.1
10/100 · none
no PTR record · datacenter
No signal at all. We say so rather than inventing a middling score to look decisive.
Every verdict above was fetched from the engine when this page loaded. Nothing here is a screenshot or a stored example, so if a number looks surprising, that is what our data actually says right now.
Reading the result
None to low
No abuse signal of substance. This is what an ordinary connection looks like.
Medium
Something is there: older abuse, a dirty neighborhood, or anonymizing infrastructure. Worth a challenge, not a ban.
High to critical
Confirmed, usually recent, abusive activity. Treat traffic from here as hostile until proven otherwise.
Questions people ask
What is a good IP reputation score?
On our 0 to 100 scale, lower is better and 0 to 29 is the normal range for an ordinary residential or business connection. From 30 to 69 something is present but not decisive: aging abuse, a bad neighborhood, or anonymizing infrastructure. From 70 up the address has confirmed abusive activity behind it. Note that scoring directions differ between vendors, so a score from another service is not comparable to this one without checking which way their scale runs.
Why is my IP score high when I have done nothing wrong?
IP reputation is a property of the address, not of you. If your provider hands the same address to thousands of subscribers through carrier-grade NAT, you inherit their behavior. If you rented a cloud or hosting address, you inherit whatever the previous tenant did with it. If you use a VPN, you inherit the conduct of everyone else on that endpoint. The result page shows first seen, last seen, and the neighborhood ratio so you can see which of these applies.
How often is IP reputation data updated?
Continuously. Threat feeds and honeypot observations flow in around the clock, community reports are applied as they are confirmed, and the published open dataset on GitHub is rebuilt every 30 minutes from the live engine.
Can I check IP reputation in bulk or from code?
Yes. The same verdict is available from a free public API endpoint that needs no key. A free account adds batch checking of up to 100 addresses per call. If you would rather not call an API at all, the entire confirmed-abusive list is published on GitHub under the MIT license.
Does a high score mean I should block the address?
Not automatically. Score it, then decide based on what is at stake. Blocking outright is defensible at the top of the range and on high-value actions such as payment or account creation. For ordinary browsing, a challenge costs an attacker far more than it costs a legitimate user who happens to sit behind a shared address.
Other free tools
IP blacklist check
Check any IPv4 or IPv6 address against our abuse database. See if it is listed, why, and how recently.
What is my IP
Your public address, plus the risk score, VPN classification, and network reputation that sites see with it.
Proxy and VPN detection
Test whether an address is seen as a VPN, proxy, Tor node, or datacenter host, and what to do about it.
Do it in code.
The same answer from a free API endpoint, or download the whole database and never call an API at all. No card, no quota, no expiry.