Skip to content
IPOK

Methodology

Updated 2026-08-20 · ipok.io

IPOK's risk score (0–100, higher means stronger adverse IP-level evidence observed by this site) blends numeric scores from several sources and applies in-house direct-signal and contextual floors. This page documents the complete IPOK aggregation, floor, and band logic; third-party sources still control their own internal algorithms.

1. Weighted average of sources

Every source that returns a numeric risk score is blended by the weights below. Dormant, failed, or non-numeric sources are excluded from the average. If no usable numeric score is returned, the base defaults to 10. The final score is the maximum of that base and all triggered floors, rounded and clamped to 0–100.

SourceWeightNotes
Scamalytics0.90Pro fraud score; proxy/VPN/datacenter coverage
IPQS0.70Fraud score (API key; currently dormant)
proxycheck0.85Proxy / VPN detection (subject to shared-cache freshness)
AbuseIPDB0.80Community abuse reports + whitelist flag
IPOK-DB0.80Self-built offline DB: Tor exits + X4BNet VPN ranges + Spamhaus DROP + OpenProxyDB verified open proxies (single IPs only, block-level smears dropped), refreshed weekly
ipapi.is0.70Calibrated abuse score + network intel
StopForumSpam0.65Forum / signup spam DB (free, complements AbuseIPDB)
ip-api0.50Boolean inference only; lowest weight

Offline reputation DB (IPOK-DB) snapshot: 2026-09-08, refreshed weekly with each deploy.

2. Hard-signal floors

Once a signal is hit, the final score cannot fall below its floor, no matter how low the weighted average is (final = max of weighted average and all triggered floors). This stops a datacenter IP from being mislabeled "pristine" just because most sources score it low.

SignalFloorNotes
Tor exit node90Strong IP-level anonymity signal; many services commonly restrict Tor, but IPOK does not predict a specific platform outcome
On spam / abuse blocklist70Any hit among DNSBL checks actually completed in this lookup is direct IP-level evidence
Confirmed proxy / VPN65Hosting IPs need ≥2 usable non-ip-api proxy/VPN votes; non-hosting IPs need ≥1; a known anonymizer ASN also qualifies
Recent abuse history55Reports / abuse score above threshold
Flagged /24 ≥25%40Contextual floor only for non-blanket /24 flags; applies from 25% up to, but not including, 50%
Flagged /24 ≥50%50Contextual floor only for non-blanket /24 flags; applies at 50% or above
Datacenter / hosting35Hosting is a use case, not fraud — floor kept low

Three boundary rules apply: any explicit trusted-allowlist signal suppresses only the hosting contextual floor; when the same source marks both allowlisted and abusive, that source's contradictory abuse vote is ignored without overriding independent abuse evidence from other sources; and a /24 filled by one broad-CIDR blanket receives no extra neighborhood floor, avoiding duplicate use of the same block-level evidence. Other direct signals still apply.

3. Spam / abuse blocklists (DNSBL)

IPOK plans five mail / abuse blocklist queries over Cloudflare DoH: SpamCop, UCEPROTECT, Barracuda, S5H, and Anonmails; the result reports how many actually completed. Partial failures are warned, and an all-failed run produces no blocklist verdict—neither is treated as clean. Any hit among completed checks triggers the blocklist floor. IPv4 only.

4. Risk bands

BandRangeMeaning
Pristine< 15Very weak adverse IP-level evidence in this lookup
Clean15 – < 50Weak adverse IP-level evidence in this lookup
Caution50 – < 70Moderate or strong adverse IP-level evidence in this lookup
High risk≥ 70Very strong adverse IP-level evidence in this lookup

5. Native vs. broadcast IP

Only compares the IP's registration country (RDAP / ASN) with its geolocation country: match = native, mismatch = broadcast / forwarded, either side missing = unknown. This is an attribution-consistency label, not a pass or block verdict for any platform.

Disclaimer

The score summarizes only IP-level data available to IPOK. It does not test account state, device fingerprint, payment details, user behavior, or internal platform policy, and cannot promise signup, login, payment, or content-access outcomes. For network diagnostics and research reference only.

AbuseIPDB Contributor BadgeIPOK is a verified AbuseIPDB webmaster; the badge shows this account's own report count — IPOK only queries and never reports visitor IPs.