Open data
Where seven IP reputation sources agree, and where they don't
Rolling aggregate counts from live IPOK lookups: per-source coverage, flag rate, agreement with the final verdict, and pairwise disagreement. We report datacenter and residential IPs separately, because the consensus rule uses a different threshold for each. Counts only, no IPs, with JSON and CSV downloads.
Generated 2026-09-08T10:27:17.639Z · cached for 30 minutes · we hide a rate when its denominator is below 30.
Coverage, flag rate, agreement
Coverage is the share of queries in which a source returned a verdict. Flag rate is the share of its own verdicts that carried a risk flag. The last rate asks something narrower: how often the source's flag pointed the same way as the score IPOK published (risk ≥ 50). A source can be right and still disagree with us, so read that column as alignment with our score rather than accuracy.
| Source | Coverage | Flag rate | proxy/vpn rate | Agrees with verdict | Verdicts |
|---|---|---|---|---|---|
| ip-api | 98.7% | 33.6% | 33.6% | 75.5% | 844 |
| IPQS | 0.0% | — | — | — | 0 |
| Scamalytics | 5.0% | 2.3% | 2.3% | 74.4% | 43 |
| proxycheck | 100.0% | 71.6% | 71.6% | 60.0% | 855 |
| AbuseIPDB | 100.0% | 7.0% | 0.0% | 68.0% | 855 |
| ipapi.is | 75.0% | 34.9% | 0.0% | 86.9% | 641 |
| StopForumSpam | 100.0% | 5.4% | 0.0% | 66.3% | 855 |
| IPOK-DB | 90.2% | 1.8% | 1.7% | 59.3% | 771 |
| Source | Coverage | Flag rate | proxy/vpn rate | Agrees with verdict | Verdicts |
|---|---|---|---|---|---|
| ip-api | 99.4% | 1.6% | 1.6% | 84.5% | 672 |
| IPQS | 0.0% | — | — | — | 0 |
| Scamalytics | 4.1% | — | — | — | 28 |
| proxycheck | 100.0% | 6.1% | 6.1% | 90.5% | 676 |
| AbuseIPDB | 100.0% | 0.6% | 0.0% | 85.1% | 676 |
| ipapi.is | 15.2% | 2.9% | 0.0% | 88.3% | 103 |
| StopForumSpam | 100.0% | 0.1% | 0.0% | 84.6% | 676 |
| IPOK-DB | 76.5% | 0.2% | 0.2% | 79.9% | 517 |
Pairwise disagreement
For every pair of sources, this counts only the queries where both returned a verdict, then asks how often exactly one of them raised a flag. A high number means the two look at different evidence. It says nothing about which one is right, and it explains why a single-source score reads differently depending on which vendor a site uses.
| Source A | Source B | Datacenter | both ruled | Residential | both ruled |
|---|---|---|---|---|---|
| proxycheck | IPOK-DB | 70.4% | 771 | 8.1% | 517 |
| proxycheck | StopForumSpam | 67.1% | 855 | 5.9% | 676 |
| proxycheck | AbuseIPDB | 65.5% | 855 | 6.1% | 676 |
| Scamalytics | proxycheck | 55.8% | 43 | — | 28 |
| ip-api | proxycheck | 46.6% | 844 | 6.0% | 672 |
| proxycheck | ipapi.is | 44.6% | 641 | 6.8% | 103 |
| ipapi.is | IPOK-DB | 37.9% | 585 | 4.5% | 89 |
| ip-api | IPOK-DB | 35.2% | 761 | 2.3% | 517 |
| ipapi.is | StopForumSpam | 34.0% | 641 | 3.9% | 103 |
| AbuseIPDB | ipapi.is | 32.0% | 641 | 4.9% | 103 |
| ip-api | StopForumSpam | 31.3% | 844 | 1.5% | 672 |
| ip-api | ipapi.is | 28.8% | 638 | 9.8% | 102 |
| ip-api | AbuseIPDB | 28.3% | 844 | 1.6% | 672 |
| Scamalytics | ipapi.is | 23.3% | 43 | — | 28 |
| ip-api | Scamalytics | 20.9% | 43 | — | 28 |
| Scamalytics | StopForumSpam | 9.3% | 43 | — | 28 |
| AbuseIPDB | IPOK-DB | 8.8% | 771 | 1.0% | 517 |
| AbuseIPDB | StopForumSpam | 8.0% | 855 | 0.7% | 676 |
| Scamalytics | AbuseIPDB | 7.0% | 43 | — | 28 |
| StopForumSpam | IPOK-DB | 6.5% | 771 | 0.4% | 517 |
| Scamalytics | IPOK-DB | 2.3% | 43 | — | 24 |
| ip-api | IPQS | — | 0 | — | 0 |
| IPQS | Scamalytics | — | 0 | — | 0 |
| IPQS | proxycheck | — | 0 | — | 0 |
| IPQS | AbuseIPDB | — | 0 | — | 0 |
| IPQS | ipapi.is | — | 0 | — | 0 |
| IPQS | StopForumSpam | — | 0 | — | 0 |
| IPQS | IPOK-DB | — | 0 | — | 0 |
How many dedicated sources called it proxy or VPN
The consensus rule counts votes from dedicated sources only (everything except ip-api, whose booleans are derived rather than measured). A datacenter IP needs 2 such votes before IPOK treats it as a proxy; a residential IP needs 1. The bars below show the observed distribution of that vote count, so you can see how much of the traffic sits at the threshold instead of taking our word for it.
Download
Both files carry the same numbers as this page. The CSV holds the raw daily signature counts rather than the computed rates, so you can recompute every percentage above without trusting our arithmetic.
Licensed CC BY 4.0. If you cite these numbers, please credit IPOK and link back to this page.
How it is counted
- ·We compress each counted lookup into one 16-bit signature: eight sources, two bits each, for absent, no flag, reported proxy/vpn, or reported Tor and abuse history without proxy/vpn. The row holds a UTC date, the datacenter or residential bucket, the final verdict as 0 or 1, that signature, and a count.
- ·We split datacenter from residential on "at least one source flagged hosting", the same expression the consensus rule uses when it picks the 2-vote or 1-vote threshold. That differs from the IP-type label shown on a result page, which goes through extra reconciliation.
- ·The final verdict is 1 when the published risk score reaches 50, the boundary between the clean and caution bands we use elsewhere on the site.
- ·We keep rows for 60 days, then delete them lazily. There is no per-query record to delete, because we never write one.
- ·Below 30 observations we print a dash instead of a rate. A percentage drawn from a handful of queries is noise.
The scoring rules these numbers describe are documented on the methodology page. For a hand-checked snapshot of specific, reproducible IPs rather than traffic aggregates, see the source-vote study.
What these numbers cannot tell you
- ·This is not site traffic. We reject requests that claim to be a browser while carrying header combinations a browser never sends, first at the edge and again in the API route, both upstream of the counter. Whatever that filter gets wrong, in either direction, lands in the sample.
- ·We drop lookups served while the third-party upstream pool was full. In that state four commercial sources read cache only by design, so counting them would report our own quota policy as a coverage failure of theirs.
- ·A source answering from a stale cache entry still counts as having returned a verdict. Coverage measures whether an answer came back, not how fresh it was.
- ·We call two of the sources on a subset of queries only: Scamalytics when a person looks up a specific address, ipapi.is when a cheap signal already suggests something worth checking. Their coverage figures describe that routing, not the vendor.
- ·IPQS has no API key configured and stays dormant. Its row is here for continuity and reads zero.
- ·Agreement with the final verdict does not measure who is correct. IPOK has no ground truth for whether an address was running a proxy at query time, so do not read either table as a vendor accuracy ranking.
- ·Traffic decides which addresses get measured. The mix is whatever people looked up, which skews toward addresses someone already suspected.
Source names, in signature bit order: ip-api, IPQS, Scamalytics, proxycheck, AbuseIPDB, ipapi.is, StopForumSpam, IPOK-DB.