Guides ·
What is an IP purity score? How to read it, and why checkers disagree
“IP purity”, “fraud score”, “IP reputation” — every checker has its own formula that adds several kinds of signals into one number or grade. So one site giving an IP 90 and another giving it 60 is not unusual. Here is what these scores are usually made of, and what to look at instead of the total.
What a score is usually made of
- Risk flags: whether the IP is flagged as a proxy, VPN, Tor exit or crawler. These come from IP-intelligence databases built from port scans, traffic behaviour and reports.
- Abuse history: reports of spam, brute-force logins or scanning, often from public abuse lists.
- DNS blocklists (DNSBLs): lists used by mail servers; being listed usually means the IP or its range sent spam.
- IP type: residential, mobile or datacenter. Most checkers deduct points for datacenter IPs, which are more often used for proxies and automation.
- Consistency: native vs broadcast (registration country vs location), and whether time zone and language match.
Why the same IP scores differently
- Different data sources. One database flags a proxy, another has no record.
- Different weights. A datacenter IP may cost 10 points on one site and 40 on another.
- Different freshness. Reputation changes: a shared exit that was clean last week can be listed after someone abuses it, and listings also expire. Sites that cache for long lag behind.
- Different definitions of “residential”. Some only check which ISP owns the range; others also read registry data and reverse DNS. That decides whether the datacenter deduction applies.
A single total tells you little. What helps is seeing which items the points came from — a good checker lists every item with its source.
What actually matters
- AI services such as ChatGPT, Claude and Gemini: first, is the region on that platform’s official list; second, is the IP flagged as proxy / VPN; third, is it a datacenter IP. Blocklists rarely matter. The three lists differ — Hong Kong and Macau, for example, are only supported by Gemini.
- Sending e-mail: DNS blocklists matter most; a listing on a major one sends mail to spam.
- E-commerce and social accounts: IP type and consistency matter more; hopping between exits and mismatched time zones raise risk checks.
Check it yourself
- DNS blocklists: reverse the IP and prepend it to the list’s zone. For 1.2.3.4:
dig +short 4.3.2.1.bl.spamcop.net. A 127.0.0.x answer means listed; no answer means not listed. - IP type: read reverse DNS and whois data — see Residential vs datacenter vs ISP IPs.
Common misconceptions
- “100 means no risk checks” — no. Platforms also weigh your account, device, payment method and behaviour.
- “A low score means unusable” — not necessarily. A datacenter IP with no risk flags may only see more verification prompts.
- “Checking once is enough” — shared exits change reputation; check again from time to time.
IP Judge publishes its full deduction table on the Method page, and every result lists each risk check and piece of evidence.
Which kind of IP do you have?
Check my IP for free