Classification with sources, not a score

What network is this IP, and how will destinations classify it?

Enter any IPv4 or IPv6 address. Every answer names its source and its date: IANA registries, ranges the cloud operators themselves publish, the Tor exit list, routed-ASN data, and Databay's own live free-proxy pool. No invented reputation number, because you could not verify one.

Pure data lookup: nothing connects to the address you enter, and it is never logged or sent to analytics.

Signal semantics

What each signal does and does not tell you

SignalAnswersSourceUncertainty
Special-purpose classificationIs this even a public address? Private, CGNAT, loopback, documentation, multicast, and reserved blocks.IANA special-purpose address registries (RFC-defined, deterministic).None: these assignments are definitional.
Origin network (ASN + organization)Which autonomous system announces the address, and under what organization name.iptoasn.com ip2asn snapshot, committed and versioned in this repository.Routing changes between snapshot refreshes; IPv4 only in this version.
Location estimateCountry and city estimate for the address.GeoLite2 database, committed copy. This product includes GeoLite2 data created by MaxMind, available from maxmind.com.An IP-to-location estimate, never a statement about a person or their whereabouts.
Published cloud rangeDoes the operator of a major cloud itself publish this address as part of its network?Each provider’s own published range list (AWS, Google Cloud, Cloudflare, DigitalOcean, Oracle, Akamai/Linode, Fastly), snapshot dates below.Coverage is only the providers listed; absence proves nothing.
Tor exitWas the address on the Tor Project’s official exit list at snapshot time.check.torproject.org bulk exit list, committed snapshot.Exit sets churn; the snapshot date is shown with every match.
Databay free-proxy pool exposureIs the address in Databay’s live verified free-proxy pool right now: ports, protocols, first-seen, check counts.Databay’s own verification pipeline, the same one behind the free proxy list.Current pool only. Absence today says nothing about yesterday.
Snapshot provenance

The range snapshots behind cloud and Tor matches

Cloud matches come from lists the operators publish about their own networks, committed to this site's repository so every answer is reproducible against a named file version. Current snapshot: 2026-07-28. Regenerated with a committed refresh script, never edited by hand.

OperatorPublished listIPv4 rangesIPv6 ranges
Amazon Web Servicesip-ranges.amazonaws.com/ip-ranges.json78072953
Google Cloudwww.gstatic.com/ipranges/cloud.json99948
Cloudflarewww.cloudflare.com/ips/157
DigitalOceanwww.digitalocean.com/geo/google.csv1080148
Oracle Clouddocs.oracle.com/en-us/iaas/tools/public_ip_ranges.json11020
Akamai/Linodegeoip.linode.com/534798
Fastlyapi.fastly.com/public-ip-list192
Tor Projectcheck.torproject.org/torbulkexitlist1385 exit addresses (2026-07-28)
The score question

Why there is no fraud score here

Commercial IP reputation scores aggregate inputs you cannot see: honeypot hits, login-abuse telemetry, email spam traps, customer block feedback, device and session correlation. That data lives inside each vendor, which is why two vendors routinely score the same address differently and why neither number is checkable from the outside. We do not hold such a dataset, so this tool does not pretend to compute one. Everything it shows, you can verify at the named source.

How to read any commercial score

  • Treat it as a probability claim about past observations, not a verdict about your traffic today.
  • Ask what window it covers: shared addresses change hands, and CGNAT puts thousands of users behind one address.
  • Compare vendors before acting on a single number, and prefer the vendor that documents its inputs.
  • For a specific destination, the destination's own behavior (via a controlled test) outranks any third-party score. That is what the proxy checker measures for proxy endpoints.
Keep going

Where this fits in a proxy workflow

Classification tells you how a destination is likely to categorize an address before any request is sent. What the address does is a separate question: our anonymity-levels guide covers what proxies actually change, the proxy checker measures live endpoint behavior, the free proxy list is the verified pool behind the exposure signal, and Databay's networks are where you choose an address class deliberately instead of discovering it afterwards.

Why does this tool not show a fraud score?

Because we do not have the private behavioral datasets a defensible score requires, and inventing a number would be worse than useless. Every signal here is checkable against a named source with a date. If you need a commercial score, this page explains how to read one critically.

Does a datacenter or cloud match mean the address is bad?

No. It means the operator publishes the address as part of its network, which destinations often treat as hosting rather than consumer space. Monitoring agents, corporate egress, and legitimate automation all live in such ranges.

Does a clean result mean the address is safe?

No. It means the address matched none of the lists this tool checks, which cover published cloud ranges, Tor exits, and Databay’s current free-proxy pool. Plenty of problematic addresses match none of them, and plenty of matched addresses are harmless.

What happens to the addresses I look up?

They are classified in memory and returned. They are not logged, not stored, not sent to analytics, and responses carry no-store cache headers. The lookup never connects to the address you enter.

Choose the address class before the workload runs

Residential, datacenter, and mobile networks classify differently by design. Pick the one that matches the job from one account.

This lookup never connects to, probes, or stores the addresses you enter.