Fraud scores look deceptively simple — a single number, easy to compare against a threshold — but the same raw score can mean very different things depending on the provider's scale, direction, and how confident that specific reading actually is.

Scale and direction aren't universal

Some providers score 0–100 with higher meaning riskier; others invert it, with higher meaning safer. Some use a 0–1 probability-style scale. Before comparing a number against any threshold, confirm which direction the provider's scale runs — using a score backwards is a real, easy mistake.

What the number leaves out

  • Confidence. A score built from extensive history behind the address is a much stronger signal than the same numeric score built from almost no data.
  • Context. The score reflects the address in isolation — it has no visibility into your specific transaction, account history, or the behavior actually occurring right now.
  • Recency. A score computed hours ago on a residential address that just got reassigned to a new household may already be stale.

The danger of a single-number decision

Making an irreversible decision — blocking an account, denying a transaction — from one fraud score alone risks both false positives (blocking a legitimate customer on a shared or recently-reassigned address) and false negatives (a genuinely risky transaction that happens to come from a currently-clean address). Fraud scores work best as one weighted input into a broader review, combined with account history, device signals, and transaction context.

FAQ

What's a "good" fraud score threshold to use?

There isn't a universal answer — it depends heavily on your specific risk tolerance, the provider's scale, and what else you're combining the score with. Providers that offer fraud scoring typically publish their own guidance for interpreting thresholds in context.

Why did the same address score differently on two different checks?

Provider data updates, new abuse reports, or address reassignment can all shift a score between checks — this is expected behavior, not a bug.