The web verdict and curl verdict share one contract.
EDGE: READY
WHAT THIS REPORTS
Six axes, named jurors, visible dissent, published rules. One named verdict, and every rule and source behind it: what the evidence agrees on, where it disagrees, and what each signal actually measures.
Network role is not abuse. Anonymity is not guilt. Missing data is an abstention—not a clean bill.
EXAMPLEChecked static exampleCache n/aNOT LIVE
IP
8.8.8.8
EXAMPLERUN A LIVE CHECKPublic internet infrastructure · responding evidence is aligned
Last 7 days · HTML requests · ASN-wide, not this IP's human probability.
Chart by Cloudflare Radar · CC BY 4.0 · Native percentages, when shown: Cloudflare Radar HTTP summary data · CC BY-NC 4.0, non-commercial use on this free tool · ASN-wide, not this IP
Blank or blocked? Reload or use Source above. Chart availability does not change the IP verdict.
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessed/100IPJURY SCOREEXPERIMENTAL · NOT A PROBABILITYIPJURY VERDICTEXAMPLE
HOW THE BAND IS DECIDED
Run a live check to obtain an evidence status.
RULE —
The first matching rule in the published precedence table names the band. Each rule reads exactly one axis.
Findings on the axes the rule did not read are listed beside the band, never folded into it, and never averaged.
0254565100
WHY
Run a live check for an evidence verdict and experimental interpretation.
Why this result · full calculation
Run a live check. The example is not scored.
Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.
A source names this exact address in a record against it.
Adverse context was observed; no covered record names this exact IP.
Sources disagree. Review the conflicting location or routing records.
Some evidence is unavailable. LIMITED describes coverage, not an adverse finding.
No source covered here reports anything against this address.
Platforms also weigh account, device, payment and behaviour signals no IP check can see.
is not a public internet address, so no external IP evidence check is made.
This address is in Shared Address Space (100.64.0.0/10), used inside provider networks. It is not a public exit address. This lookup cannot establish how many subscribers share your public connection; no external source was queried.
It is a hosting address, which many platforms treat with more friction than a home connection — that is a role, not a finding.
Sources identify a mobile network role. That alone does not establish whether this exit is shared.
Sources identify a residential network role, not an exclusive household connection.
It answers public infrastructure queries, which is a role rather than a finding.
It is a Tor exit, which is a network role and not an abuse record.
It carries privacy-relay evidence, which is a network role and not an abuse record.
Enter one IPv4 or IPv6 address to convene the jury.
That is not an IPv4 or IPv6 address. Try 8.8.8.8 or 2606:4700:4700::1111.
This connection has made too many lookups and the counter clears shortly.
The lookup counter has cleared. Run the check again.
This deployment has no active source licence profile, so no evidence may be shown. Retrying will not change that.
The request never reached IPJury. Check the connection and run it again.
The sources did not answer in time, so no verdict was reached. Nothing is concluded about this address either way.
Enter an address, or check your own connection · the example below is replaced in place
FULL REPORTIDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
ANONYMITY
No direct anonymity evidence observed
ABUSE EVIDENCE
No abuse evidence in covered sources
COVERAGE
6/7 jurors responded
LIVE DELIBERATION0/0
01
IDENTITY
COORDINATES
not loaded in static example
ROUTING
ROUTE ORIGIN OBSERVED
PREFIX
8.8.8.0/24
TIMEZONE
America/Los_Angeles
REVERSE DNS
not loaded in static example
STACK
IPv4
RANGE
8.8.8.0 – 8.8.8.255
REGISTRY
not loaded in static example
REGISTRATION VERSUS LOCATION
This is the administrative country reported by the approved network source. Compare it with the location estimates above. Agreement does not prove a native IP, a residential connection or a clean history; disagreement can reflect multinational allocations, anycast or outdated data. A missing country stays unreported.
02
SOURCE MATRIX
4 location sources agree at country level · — not covered · W/H withheld
READING THE MATRIX
Sources run across, signals run down. Each cell is what that source actually asserted for this address. A dash means the source does not cover that signal; W/H means the active display profile withholds it; ABSTAIN means the source did not answer. None of them ever means “no”.
Location rows are compared across sources. Agreement and divergence are both shown, and no row is resolved into a single location you have to trust.
SIGNAL
IPBot
IPinfo
GeoLite2
DB-IP
IPtoASN
COUNTRY
US
US
US
US
—
CITY
California, Mountain View
—
—
California, Mountain View
—
ASN
AS15169
AS15169
AS15169
—
AS15169
PROXY
NO
—
—
—
—
VPN
W/H
—
—
—
—
TOR
NO
—
—
—
—
HOSTING
NO
—
—
—
—
ABUSE
NO
—
—
—
—
03
SIX-AXIS VERDICT
SIX AXES
Each axis answers one question from the sources that cover it. Unlike signals are never averaged, and one axis never stands in for another.
Confidence describes how well the axis is covered. It is not a risk level.
NETWORK ROLEHIGH
Public internet infrastructure
Service role · anycast context · operator identity
ANONYMITYMEDIUM
No direct anonymity evidence observed
No proxy, VPN, or Tor finding in covered fields
ABUSE EVIDENCEMEDIUM
No abuse evidence in covered sources
This means “not observed,” never “clean”
GEO CONTEXTLOW
US · single geolocation estimate
Country-level context; physical location not proven
ROUTINGHIGH
Route origin observed · RPKI state withheld by licence
Origin ASN · announced prefix · route-origin conflict
COVERAGEMEDIUM
6/7 jurors responded
Named jurors · lineage families · abstentions visible
04
EVIDENCE RECORD
JUROR
AXIS
CLAIM
CONF.
STATUS
Network identityIPBot network
network role
AS15169 · Google LLC
HIGH
RESPONDED
Operator and role profileIPBot classification
network role
public infrastructure
HIGH
RESPONDED
Anonymity signalsIPBot classification
anonymity
no direct proxy/VPN/Tor evidence
MEDIUM
RESPONDED
Direct threat evidenceIPBot evidence
abuse
no direct record in covered evidence
MEDIUM
RESPONDED
No example dissent loaded.
A live result explains CGNAT, hosting-vs-abuse, location mismatch, prefix-only context, routing conflicts, and source abstention when applicable.
NETWORK ROLE CONTEXT
internet_infrastructure · public_resolver
RPKI
withheld · the deployed build sources validity from RIPEstat, whose terms restrict commercial reuse
INFORMATIONAL RECORDS
records that assert nothing adverse are listed here, never counted against the abuse axis
EDGE OBSERVATION
not applicable to arbitrary IP lookup
IMPORTANT LIMIT
IP evidence cannot observe account, device, behavior, payment, or platform-private history.
application/json
{
"example": true,
"message": "Run a live check to load the evidence contract."
}
WHAT IPJURY HAS WATCHED
AN OBSERVATION WINDOW, NOT A HISTORY OF THE ADDRESS
First seen is the date this deployment first observed the claim in a published source edition. It is not the date the address started doing anything, and a short record means IPJury started watching recently.
A claim that stops appearing is recorded as withdrawn rather than deleted, and claims from different sources are kept side by side rather than resolved into one fact.
A recorded change means the source's published claim differed from the previous edition on that date; IPJury shows the date, not the earlier value.
It is a change in what that source published. It is not a change in IPJury's coverage of the source, and not a change in how the experimental score reads the evidence; those are separate and are not recorded here.
05
ONE CONTRACT, FIVE OUTPUT FORMATS
One address, one command, one evidence record. The browser verdict, the terminal verdict, and the JSON payload are three views of the same evidence record and separately versioned experimental interpretation — no API key, no signup, no dashboard.
curl ipjury.com/8.8.8.8
What comes back
Plain curl gets the terminal rendering. The same request with Accept: application/json, or against /api/v1/ip/8.8.8.8, returns the structured record. Shape, abbreviated:
Field values above are illustrative of the shape. Run the command to see the live record for any address.
Every endpoint
Current connection
curl ipjury.com or /api/v1/self. Returned private, no-store and never shared cross-origin.
Any address
/8.8.8.8 or /api/v1/ip/8.8.8.8. IPv4 and IPv6 both accepted.
Streaming deliberation
curl -N ipjury.com/api/v1/stream/8.8.8.8 emits NDJSON source progress and cache state, followed by the completed evidence record. A progress event is not an individual juror's substantive finding.
Compare two addresses
/api/v1/compare?left=8.8.8.8&right=1.1.1.1 returns both records plus the axes that differ. It never ranks a winner.
Source disclosure
/api/v1/sources lists every juror, its lineage group, license review date, cache policy, and privacy behavior — including sources currently withheld.
Health
/api/v1/health reports readiness and the active public-display profile identity. Its operations surface declares isolate-local, closed-window operational summaries, not user history or a whole-site traffic measurement.
Experimental interpretation
The browser renders the same interpretation without recalculating it: label accompanies the evidence band, range or provisional bounds determines the shaded scale interval, and value places a tick only for a point. Visible WHY rows preserve explanation order and zero contributions; full lines remain in the calculation disclosure and exports. The confidence token reads interpretation.confidence; the separate answered-juror token reads verdicts.coverage.detail. Address range and registration country remain in the full report's identity section. These presentation choices add no API field or scoring rule.
The ipjury-result-v2 envelope includes independently versioned interpretation.schema = ipjury-score-v3. An available result has a point value and matching bounds. A provisional result has value: null, numeric bounds and possibleValues; use display for its policy range, never a midpoint. withheld and not-applicable have no numeric bounds and should not display /100. The original evidence band is unchanged: LIMITED may coexist with a point when all core axes answered but optional sources did not.
assessedAxes, missing, observed, summary and nextAction explain the coverage. explanation contains point arithmetic or the known facts and range basis, without hypothetical evidence claims. principles.globalScoreCalculated signals a point; scoreRangeCalculated signals a provisional range. Both are false for an unassessed record. A null value is neither zero nor necessarily an empty result. Compare only matching policy versions and scopes.
/api/v1/asn/54600/traffic is the separate native traffic resource. Its fixed scope is seven days, HTML requests, ASN-wide. It returns ready, stale, no-data, unavailable or withheld. Percentages are null unless an approved public-display profile and source data are available; a token alone does not activate publication. Current interpretation snapshots do not change after a later traffic response. This endpoint shares the lookup limiter, accepts GET/HEAD and no custom filters, and never exposes a Cloudflare token.
Dated source observations
context.observationRecord[] carries per-source observations, not a history of the address or a historical score. Each entry names sourceId, subject, claim and status (observed or withdrawn), alongside firstObservedAt, lastObservedAt, lastChangedAt, changeCount and editionStale. Its optional window has the source's first and latest committed edition dates; one source's window is not the site's coverage.
historyStatus distinguishes recorded (dated events returned), none (the ledger returned an empty event list for this entry), and not_retrieved (old payload, unavailable or invalid history). Never interpret not_retrieved as a quiet history. Each event contains only kind and observedAt; kinds are first_observation, value_changed and withdrawn. Events are newest first, at most 10 per entry and 50 per record; eventsTruncated flags a cut. The displayed count is the number shown, not an invented total: changeCount excludes first observations.
Text, Markdown and BBCode include source-named WATCHED rows, date-and-kind CHANGE rows, and explicit missing-history or truncation notes. Copy retains the source's own observation window and the stale-edition warning. The PNG remains a current evidence summary without per-source history; use text or JSON for the dated observations. A recorded withdrawal means that the source stopped publishing that claim in a later edition, not that an address became safe. Digests and historical values are not exported; the six axes and experimental interpretation do not read these events.
Output formats
Append ?format= or send an Accept header: json, text, markdown, bbcode, handover on the address route, and NDJSON on the stream routes. Markdown exists so a verdict can be pasted into an issue, a ticket, or a message without reformatting.
On the existing address route, ?format=handover returns plain text beginning with the unchanged standard text export, including all WATCHED / CHANGE / CHANGES lines. The supplement names all six axes with confidence, every returned juror with source, claim, status and retrieval date, and the method and score versions. Retrieval dates are not independent observation times; a source’s history keeps its own dated window.
The optional scenario is exactly proxy, friction or mail, and adds the same Cannot confirm sentence shown by that selected report task. An unsupported scenario returns 400 rather than silently using a different task. Omit it for a general record. Open an example handover for 8.8.8.8.
The response is private, no-store. It uses the normal checked record, cache and permission gates; requesting it may perform a new lookup and cannot freeze an earlier browser result. To hand over the exact currently displayed record without a new request, use the existing Copy text action. Neither format certifies identity, platform acceptance or the truth of an outside source.
Access and limits
No API key, no signup. Single-address checks are free and anonymous.
Shared fair-use limit. Roughly 90 lookups per minute per client across every surface — web, curl, stream, and compare together. A comparison counts as two. Limit state is returned in X-RateLimit-* headers.
No bulk or monitoring tier at launch. Do not build a scanner on this endpoint.
Attribution. Keep the named sources and checked time when sharing a record. A link to the address runs a current lookup; it is not a permanent copy of the earlier result.
Contract guarantees
No upstream risk_score, ip_score or purity_score is imported. The separately named experimental interpretation is IPJury policy, not source evidence or a platform-success probability.
Every axis carries a label, confidence, basis, status, and detail — so a claim can be traced to what produced it.
Every juror names its source lineage and its limitations, and abstentions appear as abstentions rather than negative findings.
Partial source failure narrows the verdict or returns an explicitly labeled stale record. It never silently fills the gap.
Private, shared, reserved, and other special-use addresses are classified locally and never sent to an external source.
The rules behind these outputs are documented in the methodology, and every juror is listed in the source register.
06
A NUMBER NEEDS ITS EVIDENCE
IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.
MYSTERY SCORE MODEL
83/100
What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.
Cross-axis averaging
Hidden source lineage
Missing source treated as “false”
Disagreement averaged away
Platform outcome implied
≠
EVIDENCE + EXPLAINED INTERPRETATION
BANDDISPUTEDRULEsource-conflictROLEhostingANONYMITYno direct evidenceABUSEno record observedGEOcountry disputedROUTINGorigin observedCOVERAGE6/7 responded
One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.
No. Single-IP lookups are keyless and free, subject to reasonable rate limits. A one-line curl against the address is the whole integration.
What output formats can the API return?
JSON, plain text, Markdown and BBCode share the same evidence and versioned interpretation. An available result has a point; a provisional result has null value with explicit policy bounds. Unusable evidence has neither a point nor numeric bounds. PNG is available from the web interface.
Can I watch the sources respond instead of waiting for the final verdict?
The stream reports source progress and cache state before the final result. Most substantive claims arrive in that completed result; a responded event alone does not establish what a source found.
Am I allowed to run bulk lookups or mirror the output?
No. Single-IP use is what the keyless endpoint authorizes; automated bulk extraction, resale, mirroring and building a substitute intelligence feed are not permitted.