The jury method: same-axis votes, source lineage, abstention, and dissent.

EDGE: READY
More options
What are you checking?
EXAMPLE Checked static example Cache n/a NOT LIVE
IP

8.8.8.8

EXAMPLERUN A LIVE CHECK
ASN
AS15169 · Google LLCgoogle.com
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessedIPJURY SCOREEXPERIMENTAL · NOT A PROBABILITY IPJURY VERDICT EXAMPLE

Run a live check for an evidence verdict and experimental interpretation.

Why this result · full calculation

Run a live check. The example is not scored.

    Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.

    OPEN FULL EVIDENCE REPORT

    JURY READY

    Enter an address, or check your own connection · the example below is replaced in place

    FULL REPORT IDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
    EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
    ANONYMITY
    No direct anonymity evidence observed
    ABUSE EVIDENCE
    No abuse evidence in covered sources
    COVERAGE
    6/7 jurors responded
    01

    IDENTITY

    COORDINATES
    not loaded in static example
    ROUTING
    ROUTE ORIGIN OBSERVED
    PREFIX
    8.8.8.0/24
    TIMEZONE
    America/Los_Angeles
    REVERSE DNS
    not loaded in static example
    STACK
    IPv4
    RANGE
    8.8.8.0 – 8.8.8.255
    REGISTRY
    not loaded in static example
    02

    SOURCE MATRIX

    4 location sources agree at country level · — not covered · W/H withheld

    SIGNALIPBotIPinfoGeoLite2DB-IPIPtoASN
    COUNTRYUSUSUSUS
    CITYCalifornia, Mountain ViewCalifornia, Mountain View
    ASNAS15169AS15169AS15169AS15169
    PROXYNO
    VPNW/H
    TORNO
    HOSTINGNO
    ABUSENO
    03

    SIX-AXIS VERDICT

    NETWORK ROLEHIGH
    Public internet infrastructure

    Service role · anycast context · operator identity

    ANONYMITYMEDIUM
    No direct anonymity evidence observed

    No proxy, VPN, or Tor finding in covered fields

    ABUSE EVIDENCEMEDIUM
    No abuse evidence in covered sources

    This means “not observed,” never “clean”

    GEO CONTEXTLOW
    US · single geolocation estimate

    Country-level context; physical location not proven

    ROUTINGHIGH
    Route origin observed · RPKI state withheld by licence

    Origin ASN · announced prefix · route-origin conflict

    COVERAGEMEDIUM
    6/7 jurors responded

    Named jurors · lineage families · abstentions visible

    04

    EVIDENCE RECORD

    JURORAXISCLAIMCONF.STATUS
    Network identityIPBot networknetwork roleAS15169 · Google LLCHIGHRESPONDED
    Operator and role profileIPBot classificationnetwork rolepublic infrastructureHIGHRESPONDED
    Anonymity signalsIPBot classificationanonymityno direct proxy/VPN/Tor evidenceMEDIUMRESPONDED
    Direct threat evidenceIPBot evidenceabuseno direct record in covered evidenceMEDIUMRESPONDED
    REPORT ipjury.com/check/8.8.8.8 EXPERIMENTAL INDEX
    TERMINAL curl ipjury.com/8.8.8.8 irm ipjury.com/8.8.8.8
    IPJURY.COM · EVIDENCE, NOT AN ENTERTAINMENT SCORE

    IPJury uses the IP2Location LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP Geolocation by DB-IP. Full source credits: source register.

    05

    THE JURY METHOD

    IPJury separates six evidence axes from an experimental interpretation. The evidence band reports what the sources establish. The optional IPJury Score applies a published policy to those facts; it is not a measured probability, speed test, fraud model or platform guarantee.

    The six axes

    Network role
    Residential, mobile, hosting, business, public infrastructure, network provider, special-use, or unknown. A description of the network, never a level of trust.
    Anonymity
    Direct proxy, VPN, Tor, privacy-relay, or residential-proxy evidence — or no such evidence in the fields covered. Anonymity is a transport fact, not a finding of guilt.
    Abuse evidence
    Exact-address direct records, contextual signals, prefix-only context, no observed record, or insufficient coverage. The distinction between "this address" and "its neighbours" is never collapsed.
    Geolocation
    Country-level agreement or disagreement between usage estimates, registry allocation, and current edge context. An estimate about a network, never proof of physical position.
    Routing
    Origin ASN, announced prefix, and route-origin conflicts. RPKI authorization state is withheld, not unknown: the deployed build sources it from RIPEstat, whose terms restrict commercial reuse.
    Coverage
    Responding jurors, abstentions, evidence families, distinct source systems, cache freshness, and known limitations. The denominator, stated openly.

    The verdict band and the rule that chose it

    Every result carries one band: a named state, not a number. The band is chosen by the first matching rule in the table below, and each rule reads exactly one axis. Nothing is weighed against anything else, so no arithmetic can turn a hosting role into an abuse finding or average a contradiction into a middling number.

    BandRuleChosen when
    LISTEDdirect-recordThe exact address appears in a loaded evidence record.
    FLAGGEDadverse-indicatorAn adverse indicator is present without an exact-record match.
    DISPUTEDsource-conflictResponding sources contradict each other, or routing authority conflicts.
    LIMITEDinsufficient-coverageToo many jurors abstained, or a load-bearing axis has no coverage.
    NO ADVERSE RECORDno-adverse-evidenceEvery responding evidence family reported nothing adverse.
    NOT APPLICABLEnon-global-addressA private or reserved address, which is never sent to any source.

    Findings on the axes the deciding rule did not read are printed next to the band as qualifiers rather than folded into it. A Tor exit with no abuse record reads as exactly that: NO ADVERSE RECORD, qualified by Tor exit evidence observed. Neither fact is removed when the separate experimental interpretation is calculated. One exception is typographic, not semantic: a qualifier that repeats the IP TYPE fact word for word is not printed a second time on the card; it stays in the record, the exports and the full report.

    Two of these states are the reason a number cannot replace them. DISPUTED says the sources do not agree — a single value has to pick a side or split the difference, and either choice hides the conflict. LIMITED says there was not enough coverage to answer, which a scale reports as a middling score indistinguishable from a genuine middling finding.

    Rule one — vote only on the same axis

    A juror may only contribute to the axis its evidence actually addresses. A proxy dataset does not get a vote on abuse. An abuse report does not get a vote on network role. A geolocation record does not influence routing. Cross-axis averaging is the single most common way IP tools manufacture false certainty, and it is structurally impossible here because no axis reads another axis's inputs.

    Rule two — direct evidence outranks a prior

    direct observation
              > official registry / operator declaration
              > independent licensed dataset
              > prefix or ASN inference
              > heuristic prior

    A lower-tier signal is never hidden — it is labeled as inferred or contextual and shown with its rank. What it cannot do is outweigh a stronger signal on the same question. An exact-address record and a "this ASN is mostly hosting" inference are both reportable; only one of them is evidence about your address.

    Rule three — deduplicate source lineage

    Several commercial IP-reputation feeds resell or derive from the same upstream data. Counting them as independent confirmations inflates apparent consensus: three interfaces backed by one dataset look like agreement, but they are one observation displayed three times. IPJury assigns every juror a lineage group and reports the count of distinct evidence families separately from the count of source systems. It will never present a set of rows as independent databases when they are not.

    Rule four — let jurors abstain

    A source that timed out, is not configured, has no IPv6 coverage, is licence-withheld, or simply holds no record is reported as an abstention. It is never silently converted into a negative finding. This matters because the alternative — dropping a non-responding source — quietly changes the denominator without telling the reader, so a thin check looks identical to a thorough one.

    The corollary is the phrase this site will not abandon: "no evidence in covered sources" is not "clean." It means the sources that answered held no finding, which depends entirely on what those sources cover and which of them stayed silent.

    Rule five — explain dissent

    When jurors disagree, the disagreement is a finding, not an error to be smoothed away. The dissent engine names the likely mechanism and separates what is confirmed from what is not. Recognised patterns include: mobile carrier-grade NAT read as proxy infrastructure; a hosting role with no abuse record; anonymity evidence conflated with abuse; an exact-address record versus prefix neighbours; geolocation estimate versus registry allocation country; PTR naming that contradicts operator data; RPKI origin conflicts; and coverage gaps caused by abstention.

    Dated source observations

    A recorded change means that the source's published claim differed from its previous edition on that date. IPJury shows the date and recorded kind, not the earlier value. A source-content change is separate from a change in IPJury's coverage of the source or in how the experimental score reads its evidence. A claim returning after withdrawal is still recorded as value_changed and labelled “changed”, without an inferred return narrative. Each source has its own observation window; missing history is not evidence that nothing changed. Copied text names the source and preserves withdrawal, unretrieved history and truncation warnings.

    What this method cannot do

    No IP evidence record can observe account history, device integrity, behavioural patterns, payment history, cookies, or any platform's private reputation data. A record here explains what is knowable about an address. It cannot predict, promise, or influence what any platform decides — and any tool that claims otherwise is selling certainty it does not have.

    Experimental IPJury Score — version ipjury-score-v3

    The first card keeps the interpretation label beside the independently named evidence band. Its single 0–100 track shades the band's permitted interval and marks a point with a tick; for a provisional result it shades the bounds without a tick. It is not a probability fill. The WHY list shows the server's explanation in its original order, including zero contributions. A reason already represented by the band is marked “in band”; the full reason and calculation remain in the details. Evidence confidence and the number of jurors answering are separate labelled facts, not two names for the same quantity.

    This is an operator-defined policy index, not an outcome-calibrated model. The weights are design choices published for inspection, not estimates learned from signup, payment, email or other platform success data. Higher values represent a more favorable interpretation under this particular general-use policy. Compare scores only with the same policy version and evidence scope.

    Evidence bandBaseDisplayed range
    No adverse record8570–100
    Disputed6050–65
    Flagged4030–45
    Listed150–25
    Limited coverageFrom answered evidencePoint or provisional policy range
    Not applicable / unusable evidenceNoneNot assessed, no /100

    Numbers use five-point steps. LIMITED is a coverage state, not a risk interval: when all five core questions have answers, an optional-source failure no longer vetoes their policy score. The original LIMITED evidence band stays visible. The scoring interval follows the strongest recorded finding, independently of the source-response count.

    When a core question is unassessed, the display gives the minimum and maximum possible policy scores while holding observed facts fixed. It varies only the unanswered policy inputs, never inserts hypothetical claims into the evidence, and does not select a midpoint. This is a provisional policy range, not a statistical confidence interval. Missing abuse includes both adverse and non-adverse possibilities; it is not scored as clean. A known exact-address listing still caps the entire range at 25 even when location or role is unavailable.

    The range uses the existing finite policy choices: network roles (−5, 0, +5), anonymity (−10, −5, 0), abuse (covered negative, surrounding prefix, indicator, exact record), location (aligned or conflicting), and routing (ordinary, independently corroborated or conflicting). Some values inside the displayed envelope may be unreachable under the five-point policy; the API lists possibleValues. The range narrows when a missing core answer arrives with all other evidence held unchanged. Completely unusable, unsupported, stale or non-global inputs still receive a named non-numeric state, not a decorative 0–100 range.

    Each result shows how many of the five core questions have answers, which questions remain unassessed, the known findings and the next useful action. Missing coverage never becomes a risk penalty or a probability. A low-confidence observed answer is still distinct from a missing answer; field-level exclusions remain visible.

    Network-context group: residential role contributes +5, hosting −5, an observed proxy/VPN/privacy relay −5, and a Tor exit −10. A non-exit Tor relay, mobile, business or public-infrastructure role contributes zero. Apply only the strongest negative in this group, or its strongest positive if no negative exists. Thus related hosting/proxy/ASN observations cannot stack three penalties, and a residential proxy does not gain a bonus that cancels its proxy context. These are interpretation choices, never abuse findings.

    Other modifiers: country disagreement is −5 unless already represented by the Disputed band; routing conflict is −5 unless already represented there. Current origin agreement across independent IPtoASN and GeoLite2 ASN tables is +5, not a claim of historical stability. Surrounding-prefix-only threat context is −5, not an exact-address listing. City disagreement or administrative registration differences receive no automatic extra deduction. Abuse findings that chose the band are not charged again. The subtotal is rounded to a five-point step and constrained to that band's range. “Why this score” lists the applied, suppressed and range-limit adjustments.

    Confidence and exclusions: evidence confidence is the weakest critical-axis confidence, capped at Medium for a disputed result. It describes evidence, not prediction accuracy; 12 of 13 responses do not by themselves establish High confidence. Withheld VPN, unreported relay fields and unestablished RPKI remain explicitly excluded.

    ASN traffic: native Cloudflare Radar values require an approved public-display profile. A future eligible modifier is bounded to this same network-context group (+5 for at least 85% Human, −5 below 40%, zero otherwise), and requires separate derivative-use approval, matching ASN/HTML/seven-day scope and a fresh snapshot. The current score calculation excludes separately loaded Radar data: opening a chart or receiving a later traffic response cannot silently change an exported score. An ASN ratio is never this address's human probability.

    Every juror, its lineage group, licence review date, and limitations are listed in the source register. If a verdict looks wrong, submit a correction with evidence.

    06

    A NUMBER NEEDS ITS EVIDENCE

    IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.

    MYSTERY SCORE MODEL
    83/100

    What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.

    • Cross-axis averaging
    • Hidden source lineage
    • Missing source treated as “false”
    • Disagreement averaged away
    • Platform outcome implied
    EVIDENCE + EXPLAINED INTERPRETATION
    BANDDISPUTED RULEsource-conflict ROLEhosting ANONYMITYno direct evidence ABUSEno record observed GEOcountry disputed ROUTINGorigin observed COVERAGE6/7 responded

    One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.

    07

    THE FIVE RULES OF EVIDENCE

    [ READ FULL METHOD ]
    1. 01

      Vote only on the same axis

      A proxy flag, an abuse report, a hosting role, and a city estimate are not interchangeable votes.

    2. 02

      Direct evidence outranks a prior

      An exact-IP record is different from an inference based on the ASN, prefix, or network category.

    3. 03

      Deduplicate source lineage

      Three websites backed by one upstream database do not become three independent evidence families.

    4. 04

      Let jurors abstain

      Timeout, no IPv6 coverage, disabled license, or missing record is shown—not silently converted to “no.”

    5. 05

      Explain dissent

      CGNAT, anycast, reassignment, data age, and route context can all produce legitimate disagreement.

    09

    QUESTIONS THE SCORE CANNOT ANSWER

    What are the six axes in an IPJury verdict?

    Network role, anonymity, abuse evidence, geolocation context, routing, and coverage. Each carries its own label, confidence, basis and detail, and none is allowed to overwrite another.

    How does IPJury decide which evidence outranks which?

    In this order: direct observation, then official registry or operator declaration, then an independent licensed dataset, then prefix or ASN inference, then heuristic prior. Lower-tier signals are still shown, labeled as inferred or contextual.

    What happens when a source does not respond?

    The abstention is reported rather than dropped. Silently excluding a non-responding source would change the denominator without telling you, so coverage names who answered and who did not.

    How are conflicts between sources on the same axis presented?

    As structured dissent. The record explains the common conflict shapes, such as mobile CGNAT against proxy heuristics or registry country against a geolocation estimate, instead of averaging them into a single label.

    IPJURY // RECORD

    Methodology