Different IP tools disagree because they answer different questions.

EDGE: READY
More options
What are you checking?
EXAMPLE Checked static example Cache n/a NOT LIVE
IP

8.8.8.8

EXAMPLERUN A LIVE CHECK
ASN
AS15169 · Google LLCgoogle.com
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessedIPJURY SCOREEXPERIMENTAL · NOT A PROBABILITY IPJURY VERDICT EXAMPLE

Run a live check for an evidence verdict and experimental interpretation.

Why this result · full calculation

Run a live check. The example is not scored.

    Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.

    OPEN FULL EVIDENCE REPORT

    JURY READY

    Enter an address, or check your own connection · the example below is replaced in place

    FULL REPORT IDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
    EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
    ANONYMITY
    No direct anonymity evidence observed
    ABUSE EVIDENCE
    No abuse evidence in covered sources
    COVERAGE
    6/7 jurors responded
    01

    IDENTITY

    COORDINATES
    not loaded in static example
    ROUTING
    ROUTE ORIGIN OBSERVED
    PREFIX
    8.8.8.0/24
    TIMEZONE
    America/Los_Angeles
    REVERSE DNS
    not loaded in static example
    STACK
    IPv4
    RANGE
    8.8.8.0 – 8.8.8.255
    REGISTRY
    not loaded in static example
    02

    SOURCE MATRIX

    4 location sources agree at country level · — not covered · W/H withheld

    SIGNALIPBotIPinfoGeoLite2DB-IPIPtoASN
    COUNTRYUSUSUSUS
    CITYCalifornia, Mountain ViewCalifornia, Mountain View
    ASNAS15169AS15169AS15169AS15169
    PROXYNO
    VPNW/H
    TORNO
    HOSTINGNO
    ABUSENO
    03

    SIX-AXIS VERDICT

    NETWORK ROLEHIGH
    Public internet infrastructure

    Service role · anycast context · operator identity

    ANONYMITYMEDIUM
    No direct anonymity evidence observed

    No proxy, VPN, or Tor finding in covered fields

    ABUSE EVIDENCEMEDIUM
    No abuse evidence in covered sources

    This means “not observed,” never “clean”

    GEO CONTEXTLOW
    US · single geolocation estimate

    Country-level context; physical location not proven

    ROUTINGHIGH
    Route origin observed · RPKI state withheld by licence

    Origin ASN · announced prefix · route-origin conflict

    COVERAGEMEDIUM
    6/7 jurors responded

    Named jurors · lineage families · abstentions visible

    04

    EVIDENCE RECORD

    JURORAXISCLAIMCONF.STATUS
    Network identityIPBot networknetwork roleAS15169 · Google LLCHIGHRESPONDED
    Operator and role profileIPBot classificationnetwork rolepublic infrastructureHIGHRESPONDED
    Anonymity signalsIPBot classificationanonymityno direct proxy/VPN/Tor evidenceMEDIUMRESPONDED
    Direct threat evidenceIPBot evidenceabuseno direct record in covered evidenceMEDIUMRESPONDED
    REPORT ipjury.com/check/8.8.8.8 EXPERIMENTAL INDEX
    TERMINAL curl ipjury.com/8.8.8.8 irm ipjury.com/8.8.8.8
    IPJURY.COM · EVIDENCE, NOT AN ENTERTAINMENT SCORE

    IPJury uses the IP2Location LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP Geolocation by DB-IP. Full source credits: source register.

    05

    NINE REASONS SOURCES DISAGREE

    Why do checkers give different answers for one IP?

    Different scopes, collection dates, source coverage and interpretation rules can produce different answers. Compare the actual claims before comparing their numbers; this report explains its own evidence, not the internals of every checker.

    Evidence scope and register licence-review dates — not live lookup dates
    SourceRegister review
    IPJury experimental interpretation policy
    IPtoASN prefix-to-origin table
    DB-IP City Lite

    Source availability depends on the current deployment and each returned record. These review dates do not establish when a particular IP was observed. Method axis-scope-2026-09-15 · Score ipjury-score-v3.

    Check one address on three sites and you will often get three different answers. This is not a sign that two of them are broken. They may describe different objects, scopes or observation times; an error is also possible. This report does not establish the correctness of an outside checker.

    Nine mechanisms of disagreement

    IP-level record versus ASN or prefix prior
    One tool reports only what is recorded against the exact address. Another starts from what its network or surrounding prefix is generally like and applies that to everything inside. On a quiet address in a busy range these produce opposite results, because an exact record and a network prior answer different questions. That difference alone does not certify either tool’s accuracy.
    CGNAT and shared egress
    When an ISP places many subscribers behind one public address, that address accumulates the combined behaviour of all of them. Tools weighting observed activity see a busy multi-user pattern resembling proxy infrastructure; tools weighting operator identity see an ordinary consumer or mobile ISP. Those are possible explanations to investigate; a public lookup does not establish subscriber sharing or validate either classification.
    Mobile reassignment
    Carrier pools rotate. The subscriber on an address this morning may not be the one on it this afternoon, so observations at different times may concern different assignments. The address history does not identify individual users or prove that reassignment caused a discrepancy.
    Anycast and CDN edges
    One anycast address is announced from many locations at once, so "where is it" has no single answer. Geolocation databases resolve this differently — registered country, nearest observed edge, last place measured — so compare the actual source definitions rather than assuming a single physical location.
    Dataset vintage
    Every dataset has a collection date and a refresh cycle, and they do not align. A recently updated record can differ from an older one. A newer timestamp does not itself prove greater accuracy, and collection method may differ as well.
    Registry country versus observed usage
    A registry records the country of the organisation that received a block; geolocation estimates where the addresses are used. A European provider can legitimately deploy an allocation in Brazil, so registry and measurement name different countries, both correct about what they record.
    Hosting treated as proxy
    Some classifiers conflate "this address is in a datacenter" with "this address relays traffic," because commercial VPN exits do live in datacenters. The conflation catches the exits and also every self-hosted service, CI runner, and corporate gateway sharing that space. A tool keeping the two axes separate disagrees with one that does not, every time.
    IPv6 coverage gaps
    Several evidence families that cover IPv4 thoroughly return little or nothing for IPv6. One tool presents thin coverage as a confident negative while another declines to answer. The addresses are the same; the data behind the two answers is not.
    Source abstention changing the denominator
    When a source times out, is unavailable under its licence, or cannot handle the address family, an honest system records an abstention and a careless one drops it from the average. The same evidence then yields a different summary purely because of who answered — which is why IPJury publishes responding jurors, abstentions, and evidence-family counts alongside every verdict.

    What to do with a conflict

    Read the conflict as information rather than noise. Ask each tool what it measured, at what scope, and when; where that answer is unavailable, the absence is itself worth weighting. IPJury keeps material conflicts as structured dissent — what each source says, the scope of its claim, and the limits of the comparison — instead of averaging them into a figure that carries neither.

    For what the number itself is made of, see what an IP purity score actually measures.

    06

    A NUMBER NEEDS ITS EVIDENCE

    IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.

    MYSTERY SCORE MODEL
    83/100

    What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.

    • Cross-axis averaging
    • Hidden source lineage
    • Missing source treated as “false”
    • Disagreement averaged away
    • Platform outcome implied
    EVIDENCE + EXPLAINED INTERPRETATION
    BANDDISPUTED RULEsource-conflict ROLEhosting ANONYMITYno direct evidence ABUSEno record observed GEOcountry disputed ROUTINGorigin observed COVERAGE6/7 responded

    One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.

    07

    THE FIVE RULES OF EVIDENCE

    [ READ FULL METHOD ]
    1. 01

      Vote only on the same axis

      A proxy flag, an abuse report, a hosting role, and a city estimate are not interchangeable votes.

    2. 02

      Direct evidence outranks a prior

      An exact-IP record is different from an inference based on the ASN, prefix, or network category.

    3. 03

      Deduplicate source lineage

      Three websites backed by one upstream database do not become three independent evidence families.

    4. 04

      Let jurors abstain

      Timeout, no IPv6 coverage, disabled license, or missing record is shown—not silently converted to “no.”

    5. 05

      Explain dissent

      CGNAT, anycast, reassignment, data age, and route context can all produce legitimate disagreement.

    09

    QUESTIONS THE SCORE CANNOT ANSWER

    Why do two IP reputation tools return completely different results for one address?

    Because they measure different objects, at different data ages, against different thresholds. Two tools can both be internally consistent and still disagree, since one may be answering about hosting likelihood while the other answers about observed reports.

    If sources conflict, which one should I trust?

    Use the source whose scope and evidence match your question; read dates, exclusions and conflicting claims. An exact-address abuse record cannot settle a separate location or network-role question.

    Do different IP data providers share the same underlying data?

    Often yes. Several commercial feeds resell or derive from common upstreams, so three sites can be one dataset wearing three names. IPJury reports the number of distinct source systems and evidence families, not just the number of rows.

    What is source lineage, and why does it change the count of agreeing sources?

    Known lineage groups avoid treating duplicate provenance as extra corroboration where the rules require independence. The record does not establish every provider's undisclosed upstream relationships.

    IPJURY // RECORD

    Methodology