Check an IP for risks

Enter an IP to check its network, proxy or hosting indicators and known risks.

Higher score, higher risk

0–29 is low, 30–59 medium, 60–79 high and 80–100 critical. The composite score represents signals under the current rules, not a probability of malicious activity.

How the composite risk score is calculated

Multiply the AbuseIPDB abuse score by 0.72 and take the greater of that value and the network baseline: Tor 72, VPN/proxy 58, or datacenter 42. If several types match, use only the first in that order. Then add 1 point per report, capped at 18 points. Round and limit the result to 0–100. Browser observations and latency do not contribute.

What results cannot guarantee

The score indicates risk. It does not guarantee access to any platform or replace a professional security audit.

Understanding the results

Keep IP scores separate from browser checks

The IP risk score comes from the backend query. WebRTC, DNS and fingerprint checks do not add to it. Read the score alongside network ownership, IP type, data sources and confidence.

Check sources and missing information

The page shows only the sources and risk factors returned by this request. An unspecified source, failed request or missing score is not a reason to infer vendors, weights or zero risk.

How the composite risk score is calculated

Multiply the AbuseIPDB abuse score by 0.72 and take the greater of that value and the network baseline: Tor 72, VPN/proxy 58, or datacenter 42. If several types match, use only the first in that order. Then add 1 point per report, capped at 18 points. Round and limit the result to 0–100. Browser observations and latency do not contribute.

Frequently asked questions

Does high risk prove that an IP is malicious?

No. A risk score is an investigative signal, not proof that a person or a particular visit is malicious. Consider observed behavior, data sources and the context of use.

How do scores map to risk levels?

0–29 is low, 30–59 medium, 60–79 high and 80–100 critical. The composite score represents signals under the current rules, not a probability of malicious activity.

Why is a result unavailable?

A failed request or a backend response without a valid score cannot support a risk conclusion. You can try again later. Unavailable means neither safe nor high risk.