The jury method: same-axis votes, source lineage, abstention, and dissent.
EDGE: READY
WHAT THIS REPORTS
Six axes, named jurors, visible dissent, published rules. One named verdict, and every rule and source behind it: what the evidence agrees on, where it disagrees, and what each signal actually measures.
Network role is not abuse. Anonymity is not guilt. Missing data is an abstention—not a clean bill.
EXAMPLEChecked static exampleCache n/aNOT LIVE
IP
8.8.8.8
EXAMPLERUN A LIVE CHECKPublic internet infrastructure · responding evidence is aligned
Last 7 days · HTML requests · ASN-wide, not this IP's human probability.
Chart by Cloudflare Radar · CC BY 4.0 · Native percentages, when shown: Cloudflare Radar HTTP summary data · CC BY-NC 4.0, non-commercial use on this free tool · ASN-wide, not this IP
Blank or blocked? Reload or use Source above. Chart availability does not change the IP verdict.
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessed/100IPJURY SCOREEXPERIMENTAL · NOT A PROBABILITYIPJURY VERDICTEXAMPLE
HOW THE BAND IS DECIDED
Run a live check to obtain an evidence status.
RULE —
The first matching rule in the published precedence table names the band. Each rule reads exactly one axis.
Findings on the axes the rule did not read are listed beside the band, never folded into it, and never averaged.
0254565100
WHY
Run a live check for an evidence verdict and experimental interpretation.
Why this result · full calculation
Run a live check. The example is not scored.
Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.
A source names this exact address in a record against it.
Adverse context was observed; no covered record names this exact IP.
Sources disagree. Review the conflicting location or routing records.
Some evidence is unavailable. LIMITED describes coverage, not an adverse finding.
No source covered here reports anything against this address.
Platforms also weigh account, device, payment and behaviour signals no IP check can see.
is not a public internet address, so no external IP evidence check is made.
This address is in Shared Address Space (100.64.0.0/10), used inside provider networks. It is not a public exit address. This lookup cannot establish how many subscribers share your public connection; no external source was queried.
It is a hosting address, which many platforms treat with more friction than a home connection — that is a role, not a finding.
Sources identify a mobile network role. That alone does not establish whether this exit is shared.
Sources identify a residential network role, not an exclusive household connection.
It answers public infrastructure queries, which is a role rather than a finding.
It is a Tor exit, which is a network role and not an abuse record.
It carries privacy-relay evidence, which is a network role and not an abuse record.
Enter one IPv4 or IPv6 address to convene the jury.
That is not an IPv4 or IPv6 address. Try 8.8.8.8 or 2606:4700:4700::1111.
This connection has made too many lookups and the counter clears shortly.
The lookup counter has cleared. Run the check again.
This deployment has no active source licence profile, so no evidence may be shown. Retrying will not change that.
The request never reached IPJury. Check the connection and run it again.
The sources did not answer in time, so no verdict was reached. Nothing is concluded about this address either way.
Enter an address, or check your own connection · the example below is replaced in place
FULL REPORTIDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
ANONYMITY
No direct anonymity evidence observed
ABUSE EVIDENCE
No abuse evidence in covered sources
COVERAGE
6/7 jurors responded
LIVE DELIBERATION0/0
01
IDENTITY
COORDINATES
not loaded in static example
ROUTING
ROUTE ORIGIN OBSERVED
PREFIX
8.8.8.0/24
TIMEZONE
America/Los_Angeles
REVERSE DNS
not loaded in static example
STACK
IPv4
RANGE
8.8.8.0 – 8.8.8.255
REGISTRY
not loaded in static example
REGISTRATION VERSUS LOCATION
This is the administrative country reported by the approved network source. Compare it with the location estimates above. Agreement does not prove a native IP, a residential connection or a clean history; disagreement can reflect multinational allocations, anycast or outdated data. A missing country stays unreported.
02
SOURCE MATRIX
4 location sources agree at country level · — not covered · W/H withheld
READING THE MATRIX
Sources run across, signals run down. Each cell is what that source actually asserted for this address. A dash means the source does not cover that signal; W/H means the active display profile withholds it; ABSTAIN means the source did not answer. None of them ever means “no”.
Location rows are compared across sources. Agreement and divergence are both shown, and no row is resolved into a single location you have to trust.
SIGNAL
IPBot
IPinfo
GeoLite2
DB-IP
IPtoASN
COUNTRY
US
US
US
US
—
CITY
California, Mountain View
—
—
California, Mountain View
—
ASN
AS15169
AS15169
AS15169
—
AS15169
PROXY
NO
—
—
—
—
VPN
W/H
—
—
—
—
TOR
NO
—
—
—
—
HOSTING
NO
—
—
—
—
ABUSE
NO
—
—
—
—
03
SIX-AXIS VERDICT
SIX AXES
Each axis answers one question from the sources that cover it. Unlike signals are never averaged, and one axis never stands in for another.
Confidence describes how well the axis is covered. It is not a risk level.
NETWORK ROLEHIGH
Public internet infrastructure
Service role · anycast context · operator identity
ANONYMITYMEDIUM
No direct anonymity evidence observed
No proxy, VPN, or Tor finding in covered fields
ABUSE EVIDENCEMEDIUM
No abuse evidence in covered sources
This means “not observed,” never “clean”
GEO CONTEXTLOW
US · single geolocation estimate
Country-level context; physical location not proven
ROUTINGHIGH
Route origin observed · RPKI state withheld by licence
Origin ASN · announced prefix · route-origin conflict
COVERAGEMEDIUM
6/7 jurors responded
Named jurors · lineage families · abstentions visible
04
EVIDENCE RECORD
JUROR
AXIS
CLAIM
CONF.
STATUS
Network identityIPBot network
network role
AS15169 · Google LLC
HIGH
RESPONDED
Operator and role profileIPBot classification
network role
public infrastructure
HIGH
RESPONDED
Anonymity signalsIPBot classification
anonymity
no direct proxy/VPN/Tor evidence
MEDIUM
RESPONDED
Direct threat evidenceIPBot evidence
abuse
no direct record in covered evidence
MEDIUM
RESPONDED
No example dissent loaded.
A live result explains CGNAT, hosting-vs-abuse, location mismatch, prefix-only context, routing conflicts, and source abstention when applicable.
NETWORK ROLE CONTEXT
internet_infrastructure · public_resolver
RPKI
withheld · the deployed build sources validity from RIPEstat, whose terms restrict commercial reuse
INFORMATIONAL RECORDS
records that assert nothing adverse are listed here, never counted against the abuse axis
EDGE OBSERVATION
not applicable to arbitrary IP lookup
IMPORTANT LIMIT
IP evidence cannot observe account, device, behavior, payment, or platform-private history.
application/json
{
"example": true,
"message": "Run a live check to load the evidence contract."
}
WHAT IPJURY HAS WATCHED
AN OBSERVATION WINDOW, NOT A HISTORY OF THE ADDRESS
First seen is the date this deployment first observed the claim in a published source edition. It is not the date the address started doing anything, and a short record means IPJury started watching recently.
A claim that stops appearing is recorded as withdrawn rather than deleted, and claims from different sources are kept side by side rather than resolved into one fact.
A recorded change means the source's published claim differed from the previous edition on that date; IPJury shows the date, not the earlier value.
It is a change in what that source published. It is not a change in IPJury's coverage of the source, and not a change in how the experimental score reads the evidence; those are separate and are not recorded here.
05
THE JURY METHOD
IPJury separates six evidence axes from an experimental interpretation. The evidence band reports what the sources establish. The optional IPJury Score applies a published policy to those facts; it is not a measured probability, speed test, fraud model or platform guarantee.
The six axes
Network role
Residential, mobile, hosting, business, public infrastructure, network provider, special-use, or unknown. A description of the network, never a level of trust.
Anonymity
Direct proxy, VPN, Tor, privacy-relay, or residential-proxy evidence — or no such evidence in the fields covered. Anonymity is a transport fact, not a finding of guilt.
Abuse evidence
Exact-address direct records, contextual signals, prefix-only context, no observed record, or insufficient coverage. The distinction between "this address" and "its neighbours" is never collapsed.
Geolocation
Country-level agreement or disagreement between usage estimates, registry allocation, and current edge context. An estimate about a network, never proof of physical position.
Routing
Origin ASN, announced prefix, and route-origin conflicts. RPKI authorization state is withheld, not unknown: the deployed build sources it from RIPEstat, whose terms restrict commercial reuse.
Coverage
Responding jurors, abstentions, evidence families, distinct source systems, cache freshness, and known limitations. The denominator, stated openly.
The verdict band and the rule that chose it
Every result carries one band: a named state, not a number. The band is chosen by the first matching rule in the table below, and each rule reads exactly one axis. Nothing is weighed against anything else, so no arithmetic can turn a hosting role into an abuse finding or average a contradiction into a middling number.
Band
Rule
Chosen when
LISTED
direct-record
The exact address appears in a loaded evidence record.
FLAGGED
adverse-indicator
An adverse indicator is present without an exact-record match.
DISPUTED
source-conflict
Responding sources contradict each other, or routing authority conflicts.
LIMITED
insufficient-coverage
Too many jurors abstained, or a load-bearing axis has no coverage.
NO ADVERSE RECORD
no-adverse-evidence
Every responding evidence family reported nothing adverse.
NOT APPLICABLE
non-global-address
A private or reserved address, which is never sent to any source.
Findings on the axes the deciding rule did not read are printed next to the band as qualifiers rather than folded into it. A Tor exit with no abuse record reads as exactly that: NO ADVERSE RECORD, qualified by Tor exit evidence observed. Neither fact is removed when the separate experimental interpretation is calculated. One exception is typographic, not semantic: a qualifier that repeats the IP TYPE fact word for word is not printed a second time on the card; it stays in the record, the exports and the full report.
Two of these states are the reason a number cannot replace them. DISPUTED says the sources do not agree — a single value has to pick a side or split the difference, and either choice hides the conflict. LIMITED says there was not enough coverage to answer, which a scale reports as a middling score indistinguishable from a genuine middling finding.
Rule one — vote only on the same axis
A juror may only contribute to the axis its evidence actually addresses. A proxy dataset does not get a vote on abuse. An abuse report does not get a vote on network role. A geolocation record does not influence routing. Cross-axis averaging is the single most common way IP tools manufacture false certainty, and it is structurally impossible here because no axis reads another axis's inputs.
Rule two — direct evidence outranks a prior
direct observation
> official registry / operator declaration
> independent licensed dataset
> prefix or ASN inference
> heuristic prior
A lower-tier signal is never hidden — it is labeled as inferred or contextual and shown with its rank. What it cannot do is outweigh a stronger signal on the same question. An exact-address record and a "this ASN is mostly hosting" inference are both reportable; only one of them is evidence about your address.
Rule three — deduplicate source lineage
Several commercial IP-reputation feeds resell or derive from the same upstream data. Counting them as independent confirmations inflates apparent consensus: three interfaces backed by one dataset look like agreement, but they are one observation displayed three times. IPJury assigns every juror a lineage group and reports the count of distinct evidence families separately from the count of source systems. It will never present a set of rows as independent databases when they are not.
Rule four — let jurors abstain
A source that timed out, is not configured, has no IPv6 coverage, is licence-withheld, or simply holds no record is reported as an abstention. It is never silently converted into a negative finding. This matters because the alternative — dropping a non-responding source — quietly changes the denominator without telling the reader, so a thin check looks identical to a thorough one.
The corollary is the phrase this site will not abandon: "no evidence in covered sources" is not "clean." It means the sources that answered held no finding, which depends entirely on what those sources cover and which of them stayed silent.
Rule five — explain dissent
When jurors disagree, the disagreement is a finding, not an error to be smoothed away. The dissent engine names the likely mechanism and separates what is confirmed from what is not. Recognised patterns include: mobile carrier-grade NAT read as proxy infrastructure; a hosting role with no abuse record; anonymity evidence conflated with abuse; an exact-address record versus prefix neighbours; geolocation estimate versus registry allocation country; PTR naming that contradicts operator data; RPKI origin conflicts; and coverage gaps caused by abstention.
Dated source observations
A recorded change means that the source's published claim differed from its previous edition on that date. IPJury shows the date and recorded kind, not the earlier value. A source-content change is separate from a change in IPJury's coverage of the source or in how the experimental score reads its evidence. A claim returning after withdrawal is still recorded as value_changed and labelled “changed”, without an inferred return narrative. Each source has its own observation window; missing history is not evidence that nothing changed. Copied text names the source and preserves withdrawal, unretrieved history and truncation warnings.
What this method cannot do
No IP evidence record can observe account history, device integrity, behavioural patterns, payment history, cookies, or any platform's private reputation data. A record here explains what is knowable about an address. It cannot predict, promise, or influence what any platform decides — and any tool that claims otherwise is selling certainty it does not have.
Experimental IPJury Score — version ipjury-score-v3
The first card keeps the interpretation label beside the independently named evidence band. Its single 0–100 track shades the band's permitted interval and marks a point with a tick; for a provisional result it shades the bounds without a tick. It is not a probability fill. The WHY list shows the server's explanation in its original order, including zero contributions. A reason already represented by the band is marked “in band”; the full reason and calculation remain in the details. Evidence confidence and the number of jurors answering are separate labelled facts, not two names for the same quantity.
This is an operator-defined policy index, not an outcome-calibrated model. The weights are design choices published for inspection, not estimates learned from signup, payment, email or other platform success data. Higher values represent a more favorable interpretation under this particular general-use policy. Compare scores only with the same policy version and evidence scope.
Evidence band
Base
Displayed range
No adverse record
85
70–100
Disputed
60
50–65
Flagged
40
30–45
Listed
15
0–25
Limited coverage
From answered evidence
Point or provisional policy range
Not applicable / unusable evidence
None
Not assessed, no /100
Numbers use five-point steps. LIMITED is a coverage state, not a risk interval: when all five core questions have answers, an optional-source failure no longer vetoes their policy score. The original LIMITED evidence band stays visible. The scoring interval follows the strongest recorded finding, independently of the source-response count.
When a core question is unassessed, the display gives the minimum and maximum possible policy scores while holding observed facts fixed. It varies only the unanswered policy inputs, never inserts hypothetical claims into the evidence, and does not select a midpoint. This is a provisional policy range, not a statistical confidence interval. Missing abuse includes both adverse and non-adverse possibilities; it is not scored as clean. A known exact-address listing still caps the entire range at 25 even when location or role is unavailable.
The range uses the existing finite policy choices: network roles (−5, 0, +5), anonymity (−10, −5, 0), abuse (covered negative, surrounding prefix, indicator, exact record), location (aligned or conflicting), and routing (ordinary, independently corroborated or conflicting). Some values inside the displayed envelope may be unreachable under the five-point policy; the API lists possibleValues. The range narrows when a missing core answer arrives with all other evidence held unchanged. Completely unusable, unsupported, stale or non-global inputs still receive a named non-numeric state, not a decorative 0–100 range.
Each result shows how many of the five core questions have answers, which questions remain unassessed, the known findings and the next useful action. Missing coverage never becomes a risk penalty or a probability. A low-confidence observed answer is still distinct from a missing answer; field-level exclusions remain visible.
Network-context group: residential role contributes +5, hosting −5, an observed proxy/VPN/privacy relay −5, and a Tor exit −10. A non-exit Tor relay, mobile, business or public-infrastructure role contributes zero. Apply only the strongest negative in this group, or its strongest positive if no negative exists. Thus related hosting/proxy/ASN observations cannot stack three penalties, and a residential proxy does not gain a bonus that cancels its proxy context. These are interpretation choices, never abuse findings.
Other modifiers: country disagreement is −5 unless already represented by the Disputed band; routing conflict is −5 unless already represented there. Current origin agreement across independent IPtoASN and GeoLite2 ASN tables is +5, not a claim of historical stability. Surrounding-prefix-only threat context is −5, not an exact-address listing. City disagreement or administrative registration differences receive no automatic extra deduction. Abuse findings that chose the band are not charged again. The subtotal is rounded to a five-point step and constrained to that band's range. “Why this score” lists the applied, suppressed and range-limit adjustments.
Confidence and exclusions: evidence confidence is the weakest critical-axis confidence, capped at Medium for a disputed result. It describes evidence, not prediction accuracy; 12 of 13 responses do not by themselves establish High confidence. Withheld VPN, unreported relay fields and unestablished RPKI remain explicitly excluded.
ASN traffic: native Cloudflare Radar values require an approved public-display profile. A future eligible modifier is bounded to this same network-context group (+5 for at least 85% Human, −5 below 40%, zero otherwise), and requires separate derivative-use approval, matching ASN/HTML/seven-day scope and a fresh snapshot. The current score calculation excludes separately loaded Radar data: opening a chart or receiving a later traffic response cannot silently change an exported score. An ASN ratio is never this address's human probability.
IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.
MYSTERY SCORE MODEL
83/100
What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.
Cross-axis averaging
Hidden source lineage
Missing source treated as “false”
Disagreement averaged away
Platform outcome implied
≠
EVIDENCE + EXPLAINED INTERPRETATION
BANDDISPUTEDRULEsource-conflictROLEhostingANONYMITYno direct evidenceABUSEno record observedGEOcountry disputedROUTINGorigin observedCOVERAGE6/7 responded
One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.
Network role, anonymity, abuse evidence, geolocation context, routing, and coverage. Each carries its own label, confidence, basis and detail, and none is allowed to overwrite another.
How does IPJury decide which evidence outranks which?
In this order: direct observation, then official registry or operator declaration, then an independent licensed dataset, then prefix or ASN inference, then heuristic prior. Lower-tier signals are still shown, labeled as inferred or contextual.
What happens when a source does not respond?
The abstention is reported rather than dropped. Silently excluding a non-responding source would change the denominator without telling you, so coverage names who answered and who did not.
How are conflicts between sources on the same axis presented?
As structured dissent. The record explains the common conflict shapes, such as mobile CGNAT against proxy heuristics or registry country against a geolocation estimate, instead of averaging them into a single label.