IP reputation

What is this IP's reputation?

A single 0 to 100 score for any address, and every signal that produced it. Not a black box: the page shows you the evidence, so you can decide whether you agree with the number.

Live IP intelligence
<1ms

Result

185.220.101.34

Brandenburg, Germany · TORSERVERS-NET · Data Center

Fraud score100critical
VPN · yesProxy · yesTor · yesDatacenter · yes
Tagsc2_serverbotnet_nodessh_brute_force+12 more
high confidenceopen full report →

Pre-filled with a known Tor exit node. Type any address to score your own.

Behind every check

19.8 million

IP addresses profiled

2.4 million

malicious domains tracked

208,000

disposable email domains

1.9 million

networks scored

Counts read live from the engine, not written into the page. The full dataset is published on GitHub under the MIT license and rebuilt every 30 minutes.

How the score is built

The score is not a vote count and it is not one provider's opinion resold. An address is only listed as abusive once it has been independently confirmed at least twice, which keeps single-source noise out of the number.

Direct observation

Our own honeypot sensors record what actually hit them. This is first-party evidence, not a feed we bought.

Community reports

Reports from operators running real infrastructure, weighted by a trust tier that a reporter earns over time rather than gets on signup.

Independent threat feeds

Multiple established intelligence sources, cross-checked against each other. Agreement across genuinely independent sources counts; the same data republished under several names does not.

Network context

Reputation of the surrounding subnet and of the autonomous system, so an address in a block that is overwhelmingly abusive does not get graded as if it stood alone.

Infrastructure classification

VPN, proxy, Tor, residential proxy, datacenter, or consumer. Anonymization is a risk signal in context, not proof of wrongdoing on its own.

Confidence and completeness

Every result carries a confidence level and a data-completeness figure alongside the score. A low score on thin data is not the same statement as a low score on rich data, and pretending otherwise is how scoring systems mislead people. When we have not seen enough to be sure, the result says so instead of projecting false precision.

Checking your own address

Most people arriving here are checking themselves, usually because something blocked them and they want to know what it saw. Your own reputation is shaped by things you may not control: your provider's history, whether your address is shared through carrier-grade NAT, whether a VPN you use has been abused by other customers, and what the previous holder of the address did. The result page separates what is true of you from what is true of your neighborhood.

Reading the result

None to low

No abuse signal of substance. This is what an ordinary connection looks like.

Medium

Something is there: older abuse, a dirty neighborhood, or anonymizing infrastructure. Worth a challenge, not a ban.

High to critical

Confirmed, usually recent, abusive activity. Treat traffic from here as hostile until proven otherwise.

Questions people ask

What is a good IP reputation score?

On our 0 to 100 scale, lower is better and 0 to 29 is the normal range for an ordinary residential or business connection. From 30 to 69 something is present but not decisive: aging abuse, a bad neighborhood, or anonymizing infrastructure. From 70 up the address has confirmed abusive activity behind it. Note that scoring directions differ between vendors, so a score from another service is not comparable to this one without checking which way their scale runs.

Why is my IP score high when I have done nothing wrong?

IP reputation is a property of the address, not of you. If your provider hands the same address to thousands of subscribers through carrier-grade NAT, you inherit their behavior. If you rented a cloud or hosting address, you inherit whatever the previous tenant did with it. If you use a VPN, you inherit the conduct of everyone else on that endpoint. The result page shows first seen, last seen, and the neighborhood ratio so you can see which of these applies.

How often is IP reputation data updated?

Continuously. Threat feeds and honeypot observations flow in around the clock, community reports are applied as they are confirmed, and the published open dataset on GitHub is rebuilt every 30 minutes from the live engine.

Can I check IP reputation in bulk or from code?

Yes. The same verdict is available from a free public API endpoint that needs no key. A free account adds batch checking of up to 100 addresses per call. If you would rather not call an API at all, the entire confirmed-abusive list is published on GitHub under the MIT license.

Does a high score mean I should block the address?

Not automatically. Score it, then decide based on what is at stake. Blocking outright is defensible at the top of the range and on high-value actions such as payment or account creation. For ordinary browsing, a challenge costs an attacker far more than it costs a legitimate user who happens to sit behind a shared address.

Do it in code.

The same answer from a free API endpoint, or download the whole database and never call an API at all. No card, no quota, no expiry.