Proxy, VPN, and Tor evidence without an abuse shortcut.

EDGE: READY
More options
What are you checking?
EXAMPLE Checked static example Cache n/a NOT LIVE
IP

8.8.8.8

EXAMPLERUN A LIVE CHECK
ASN
AS15169 · Google LLCgoogle.com
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessedIPJURY SCOREEXPERIMENTAL · NOT A PROBABILITY IPJURY VERDICT EXAMPLE

Run a live check for an evidence verdict and experimental interpretation.

Why this result · full calculation

Run a live check. The example is not scored.

    Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.

    OPEN FULL EVIDENCE REPORT

    JURY READY

    Enter an address, or check your own connection · the example below is replaced in place

    FULL REPORT IDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
    EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
    ANONYMITY
    No direct anonymity evidence observed
    ABUSE EVIDENCE
    No abuse evidence in covered sources
    COVERAGE
    6/7 jurors responded
    01

    IDENTITY

    COORDINATES
    not loaded in static example
    ROUTING
    ROUTE ORIGIN OBSERVED
    PREFIX
    8.8.8.0/24
    TIMEZONE
    America/Los_Angeles
    REVERSE DNS
    not loaded in static example
    STACK
    IPv4
    RANGE
    8.8.8.0 – 8.8.8.255
    REGISTRY
    not loaded in static example
    02

    SOURCE MATRIX

    4 location sources agree at country level · — not covered · W/H withheld

    SIGNALIPBotIPinfoGeoLite2DB-IPIPtoASN
    COUNTRYUSUSUSUS
    CITYCalifornia, Mountain ViewCalifornia, Mountain View
    ASNAS15169AS15169AS15169AS15169
    PROXYNO
    VPNW/H
    TORNO
    HOSTINGNO
    ABUSENO
    03

    SIX-AXIS VERDICT

    NETWORK ROLEHIGH
    Public internet infrastructure

    Service role · anycast context · operator identity

    ANONYMITYMEDIUM
    No direct anonymity evidence observed

    No proxy, VPN, or Tor finding in covered fields

    ABUSE EVIDENCEMEDIUM
    No abuse evidence in covered sources

    This means “not observed,” never “clean”

    GEO CONTEXTLOW
    US · single geolocation estimate

    Country-level context; physical location not proven

    ROUTINGHIGH
    Route origin observed · RPKI state withheld by licence

    Origin ASN · announced prefix · route-origin conflict

    COVERAGEMEDIUM
    6/7 jurors responded

    Named jurors · lineage families · abstentions visible

    04

    EVIDENCE RECORD

    JURORAXISCLAIMCONF.STATUS
    Network identityIPBot networknetwork roleAS15169 · Google LLCHIGHRESPONDED
    Operator and role profileIPBot classificationnetwork rolepublic infrastructureHIGHRESPONDED
    Anonymity signalsIPBot classificationanonymityno direct proxy/VPN/Tor evidenceMEDIUMRESPONDED
    Direct threat evidenceIPBot evidenceabuseno direct record in covered evidenceMEDIUMRESPONDED
    REPORT ipjury.com/check/8.8.8.8 EXPERIMENTAL INDEX
    TERMINAL curl ipjury.com/8.8.8.8 irm ipjury.com/8.8.8.8
    IPJURY.COM · EVIDENCE, NOT AN ENTERTAINMENT SCORE

    IPJury uses the IP2Location LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP Geolocation by DB-IP. Full source credits: source register.

    05

    WHAT COUNTS AS ANONYMITY EVIDENCE

    Which proxy or Tor evidence is actually covered for this address?

    Inspect the named anonymity sources and their supported classes. A published Tor exit is distinct from a non-exit relay; a PUB-only proxy dataset miss does not exclude VPN or residential-proxy services.

    Evidence scope and register licence-review dates — not live lookup dates
    SourceRegister review
    IPBot Classification Evidence
    Tor Project bulk exit list
    Tor Project relay directory

    Source availability depends on the current deployment and each returned record. These review dates do not establish when a particular IP was observed. Method axis-scope-2026-09-15 · Score ipjury-score-v3.

    Proxy, VPN, Tor, privacy relay, and residential proxy are transport facts. They describe how traffic reached you, not whether the person sending it did anything wrong.

    Direct evidence versus inference

    The gap between "we can see this" and "this pattern usually means that" is the most important distinction on this axis, when reading this axis. IPJury identifies the named source and the scope of a returned finding.

    Direct evidence
    The operator publishes the fact. The Tor Project maintains a public list of exit addresses, and relay and privacy-relay providers publish the ranges they egress from. When an address appears on such a list, the finding is a lookup, not a guess.
    Dataset evidence
    A licensed dataset asserts that a specific address was observed operating as a proxy or VPN endpoint. A real observation by a party that saw something — but second-hand, with an age, and with a collection method usually not fully disclosed.
    Inference
    Nobody observed this address doing anything. A classifier reasoned from the network it sits in, from what its neighbours do, or from naming conventions. Legitimate context, and a poor basis for a decision on its own.

    These do not average. An address on the published Tor exit list is a confirmed Tor exit. An address that merely sits in an ASN where VPN providers rent capacity is exactly that, and calling it a proxy finding is how a self-hosted mail server ends up labelled as anonymity infrastructure.

    What this deployment can and cannot report

    The anonymity axis currently reports proxy, Tor and privacy-relay evidence. A VPN-only classification and a residential-proxy classification are withheld, where the deployed sources do not support their public use. IP2Proxy LITE covers open/public proxies (PUB); a miss cannot exclude a VPN or residential-proxy service. Dataset scope and permission withholding are distinct limitations, neither of which is a negative observation. It is also why a clean result here reads "no direct anonymity evidence" over the signals that were actually assessable, and never as "no VPN".

    Why a VPN finding is not an abuse finding

    Anonymity and abuse are separate axes because they answer separate questions, and evidence on one carries no weight on the other. Commercial VPNs are used by journalists, remote employees under corporate policy, travellers on hotel Wi-Fi, and people who do not want their ISP building a browsing profile. Tor is used for censorship circumvention and for research. A confirmed anonymity finding tells a site operator something they may want to act on — rate limits, extra verification, a policy on relayed sign-ups — but it is not a record that anything happened.

    The reverse also holds. An address with no returned anonymity evidence can still carry a direct abuse record. The result must be read from that separate evidence axis, not inferred from its network type.

    The limits of detection

    Absence of an anonymity flag proves very little, and this is the honest weak point of every tool in this category.

    • Private endpoints cannot be reliably excluded here. A private VPN on a rented machine may have no entry in the covered lists. Missing published evidence does not prove that the machine is not forwarding traffic.
    • Residential role does not rule out proxy use. Traffic may be forwarded through subscriber space. A network-role label cannot certify the particular connection, consent, household or exclusivity.
    • Lists lag. New exit capacity appears before any dataset records it, and decommissioned ranges keep their labels after the service moves on.
    • Address-family coverage varies. Read the source’s returned abstentions and withheld fields. Missing IPv6 data must not be treated as a confident negative finding.

    Coverage and abstention

    "No direct anonymity evidence observed" means the sources that responded held no such evidence. It is not a statement that the address is not a proxy, and IPJury will not restate it as one. When a source times out, is disabled by licence, or cannot answer for this address family, it abstains, and the abstention appears in the coverage axis so the denominator behind the finding stays visible.

    For how anonymity evidence interacts with the network an address sits in, see the network role guide.

    06

    A NUMBER NEEDS ITS EVIDENCE

    IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.

    MYSTERY SCORE MODEL
    83/100

    What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.

    • Cross-axis averaging
    • Hidden source lineage
    • Missing source treated as “false”
    • Disagreement averaged away
    • Platform outcome implied
    EVIDENCE + EXPLAINED INTERPRETATION
    BANDDISPUTED RULEsource-conflict ROLEhosting ANONYMITYno direct evidence ABUSEno record observed GEOcountry disputed ROUTINGorigin observed COVERAGE6/7 responded

    One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.

    07

    THE FIVE RULES OF EVIDENCE

    [ READ FULL METHOD ]
    1. 01

      Vote only on the same axis

      A proxy flag, an abuse report, a hosting role, and a city estimate are not interchangeable votes.

    2. 02

      Direct evidence outranks a prior

      An exact-IP record is different from an inference based on the ASN, prefix, or network category.

    3. 03

      Deduplicate source lineage

      Three websites backed by one upstream database do not become three independent evidence families.

    4. 04

      Let jurors abstain

      Timeout, no IPv6 coverage, disabled license, or missing record is shown—not silently converted to “no.”

    5. 05

      Explain dissent

      CGNAT, anycast, reassignment, data age, and route context can all produce legitimate disagreement.

    09

    QUESTIONS THE SCORE CANNOT ANSWER

    How is a Tor exit identified in the record?

    A confirmed exit is a direct observation and IPJury labels it as one, separately from an ASN-level likely-proxy prior. Which sources supplied that evidence, and whether any abstained, is shown in the coverage axis.

    Does a VPN finding mean the address is dangerous?

    No. VPN use is a transport and privacy trait, not an abuse verdict. IPJury keeps anonymity evidence separate from abuse evidence precisely so one is not read as proof of the other.

    What is a residential proxy, and why is it hard to detect?

    Residential proxy use cannot be excluded by a residential role or a PUB-only dataset miss. Current VPN and residential-proxy fields are withheld where unsupported; inspect the named coverage before drawing a conclusion.

    Why does my home connection show anonymity evidence when I run no VPN?

    Shared egress is one possible explanation, not a confirmed diagnosis. This lookup does not establish subscriber sharing or prove that a source's flag was a false positive.

    IPJURY // RECORD

    Methodology