IP Reputation
Historical abuse and reputation signals for the address.
Network intelligence
Instantly see your public IP's risk score, network identity — proxy, VPN, Tor, datacenter or residential — plus ASN, ISP and location.
Get an IP's risk score, reputation, proxy, VPN, Tor, datacenter and residential-proxy status — plus ASN, ISP and geolocation. Free on NetRiskScan, or integrate via API, CLI and JS SDK.
Historical abuse and reputation signals for the address.
Detect proxy, VPN and anonymization indicators.
Identify Tor infrastructure and exit-node evidence.
ASN, organization, network type and connection profile.
Scanner, abuse and threat-intelligence evidence.
Identify datacenter, residential and public infrastructure.
Open source
Check IP reputation from the terminal, or integrate NetRiskScan directly into your application.
Check IP reputation, proxy, VPN, Tor and network intelligence directly from your terminal.
npx netriskscan-cli check 8.8.8.8
View CLI on GitHub
Use the NetRiskScan Developer API with a typed, zero-runtime-dependency client.
npm install @netriskscan/sdk
View SDK on GitHub
Building something larger? Explore the Developer API
Higher is cleaner.
The Index combines multiple independent signals across:
What kind of network the IP belongs to — datacenter, residential, mobile or public infrastructure.
Proxy, VPN, Tor and related indicators.
Historical abuse and reputation evidence.
Scanner, malicious activity and security intelligence.
Check an IP before or after deploying a VPS.
Understand proxy type and reputation before use.
Add IP risk signals to signup, login and transaction flows.
Monitor network reputation and unexpected classification changes.
An IP reputation check looks at signals such as proxy, VPN, Tor, datacenter status, abuse reports and threat intelligence to describe how trustworthy an IP address's network activity looks.
The NetRiskScan Index is a 0-100 score where higher means a cleaner network reputation: 90-100 is Excellent, 75-89 Good, 60-74 Fair, 40-59 Poor, and 0-39 High risk.
No. A VPN address does not automatically mean malicious traffic — many people use VPNs for ordinary privacy reasons. NetRiskScan reports VPN status as one signal among several, not a verdict on its own.
No. Datacenter infrastructure does not automatically mean high risk. Many legitimate services, including public DNS resolvers, run on datacenter IPs.
Yes. Residential proxy is one of the network-type signals NetRiskScan reports alongside VPN, datacenter and hosting — based on ASN registration and network-type classification, not just IP location.
Tor exit-node status is one of the signals shown in every IP check result on this page. Enter or auto-detect an address and look for the Tor flag alongside VPN, proxy and datacenter.
Check its public IP on this page the same way you would any address, or run netriskscan-cli or the Developer API directly from the VPS for automated, repeatable checks.
Yes. You can check an IP address on this page without creating an account.
Yes. The NetRiskScan Developer API lets you integrate IP reputation and network intelligence directly into your application.
Yes. netriskscan-cli is an official command-line client you can run with npx, with no signup required for your first checks.
Yes. @netriskscan/sdk is a typed JavaScript/TypeScript client for the Developer API.
Unknown means NetRiskScan does not have enough evidence to confirm or rule out a signal for that address. It is treated differently from a confirmed negative result, not assumed to be false.