When a reputation provider hands back a single number, that number is standing in for several separate judgments bundled together. Knowing what's actually inside the blend makes the number far more useful than treating it as one opaque verdict.

The usual ingredients

  • Network type. Whether the address is residential, mobile, datacenter, or known VPN/proxy infrastructure — a structural fact, not behavioral.
  • Abuse history. Reports and observed incidents tied to the address, weighted by how recent and how verified they are.
  • Current behavior signals. Traffic patterns the provider observes directly, where available — request velocity, automation indicators, and similar.
  • Confidence weighting. How much data the provider actually has for this specific address; a score built on thin data should carry less weight than one built on extensive history.

Why providers weight these differently

Two reputation services can look at identical raw signals and produce different scores because they weight the ingredients differently — one might treat network type as a heavy factor, another might lean more on recent abuse reports. Neither approach is objectively "correct"; they reflect different design priorities, which is exactly why cross-checking a single high-stakes decision against more than one source is worth doing.

What this means for reading a score

A low score doesn't mean "definitely malicious" any more than a high score means "definitely safe" — both are probabilistic judgments built from imperfect, time-limited data. Treat the score as a starting point for further review on anything consequential, not a final answer. See Methodology for how NetRiskScan's own risk score is built specifically.

FAQ

Can I see exactly which factors produced a specific score?

Usually not in full detail — most commercial reputation providers treat their exact weighting as proprietary, though many will describe the general categories of signal they use.

Does a score update in real time?

It depends on the provider — some recompute frequently, others on a fixed schedule. A score you see right now may not reflect an event that happened minutes ago.