Methodology
Updated 2026-08-20 · ipok.io
IPOK's risk score (0–100, higher means stronger adverse IP-level evidence observed by this site) blends numeric scores from several sources and applies in-house direct-signal and contextual floors. This page documents the complete IPOK aggregation, floor, and band logic; third-party sources still control their own internal algorithms.
1. Weighted average of sources
Every source that returns a numeric risk score is blended by the weights below. Dormant, failed, or non-numeric sources are excluded from the average. If no usable numeric score is returned, the base defaults to 10. The final score is the maximum of that base and all triggered floors, rounded and clamped to 0–100.
| Source | Weight | Notes |
|---|---|---|
| Scamalytics | 0.90 | Pro fraud score; proxy/VPN/datacenter coverage |
| IPQS | 0.70 | Fraud score (API key; currently dormant) |
| proxycheck | 0.85 | Proxy / VPN detection (subject to shared-cache freshness) |
| AbuseIPDB | 0.80 | Community abuse reports + whitelist flag |
| IPOK-DB | 0.80 | Self-built offline DB: Tor exits + X4BNet VPN ranges + Spamhaus DROP + OpenProxyDB verified open proxies (single IPs only, block-level smears dropped), refreshed weekly |
| ipapi.is | 0.70 | Calibrated abuse score + network intel |
| StopForumSpam | 0.65 | Forum / signup spam DB (free, complements AbuseIPDB) |
| ip-api | 0.50 | Boolean inference only; lowest weight |
Offline reputation DB (IPOK-DB) snapshot: 2026-09-08, refreshed weekly with each deploy.
2. Hard-signal floors
Once a signal is hit, the final score cannot fall below its floor, no matter how low the weighted average is (final = max of weighted average and all triggered floors). This stops a datacenter IP from being mislabeled "pristine" just because most sources score it low.
| Signal | Floor | Notes |
|---|---|---|
| Tor exit node | 90 | Strong IP-level anonymity signal; many services commonly restrict Tor, but IPOK does not predict a specific platform outcome |
| On spam / abuse blocklist | 70 | Any hit among DNSBL checks actually completed in this lookup is direct IP-level evidence |
| Confirmed proxy / VPN | 65 | Hosting IPs need ≥2 usable non-ip-api proxy/VPN votes; non-hosting IPs need ≥1; a known anonymizer ASN also qualifies |
| Recent abuse history | 55 | Reports / abuse score above threshold |
| Flagged /24 ≥25% | 40 | Contextual floor only for non-blanket /24 flags; applies from 25% up to, but not including, 50% |
| Flagged /24 ≥50% | 50 | Contextual floor only for non-blanket /24 flags; applies at 50% or above |
| Datacenter / hosting | 35 | Hosting is a use case, not fraud — floor kept low |
Three boundary rules apply: any explicit trusted-allowlist signal suppresses only the hosting contextual floor; when the same source marks both allowlisted and abusive, that source's contradictory abuse vote is ignored without overriding independent abuse evidence from other sources; and a /24 filled by one broad-CIDR blanket receives no extra neighborhood floor, avoiding duplicate use of the same block-level evidence. Other direct signals still apply.
3. Spam / abuse blocklists (DNSBL)
IPOK plans five mail / abuse blocklist queries over Cloudflare DoH: SpamCop, UCEPROTECT, Barracuda, S5H, and Anonmails; the result reports how many actually completed. Partial failures are warned, and an all-failed run produces no blocklist verdict—neither is treated as clean. Any hit among completed checks triggers the blocklist floor. IPv4 only.
4. Risk bands
| Band | Range | Meaning |
|---|---|---|
| Pristine | < 15 | Very weak adverse IP-level evidence in this lookup |
| Clean | 15 – < 50 | Weak adverse IP-level evidence in this lookup |
| Caution | 50 – < 70 | Moderate or strong adverse IP-level evidence in this lookup |
| High risk | ≥ 70 | Very strong adverse IP-level evidence in this lookup |
5. Native vs. broadcast IP
Only compares the IP's registration country (RDAP / ASN) with its geolocation country: match = native, mismatch = broadcast / forwarded, either side missing = unknown. This is an attribution-consistency label, not a pass or block verdict for any platform.
Disclaimer
The score summarizes only IP-level data available to IPOK. It does not test account state, device fingerprint, payment details, user behavior, or internal platform policy, and cannot promise signup, login, payment, or content-access outcomes. For network diagnostics and research reference only.