Residential, mobile, or hosting? Read the evidence by axis.

EDGE: READY
More options
What are you checking?
EXAMPLE Checked static example Cache n/a NOT LIVE
IP

8.8.8.8

EXAMPLERUN A LIVE CHECK
ASN
AS15169 · Google LLCgoogle.com
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessedIPJURY SCOREEXPERIMENTAL · NOT A PROBABILITY IPJURY VERDICT EXAMPLE

Run a live check for an evidence verdict and experimental interpretation.

Why this result · full calculation

Run a live check. The example is not scored.

    Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.

    OPEN FULL EVIDENCE REPORT

    JURY READY

    Enter an address, or check your own connection · the example below is replaced in place

    FULL REPORT IDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
    EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
    ANONYMITY
    No direct anonymity evidence observed
    ABUSE EVIDENCE
    No abuse evidence in covered sources
    COVERAGE
    6/7 jurors responded
    01

    IDENTITY

    COORDINATES
    not loaded in static example
    ROUTING
    ROUTE ORIGIN OBSERVED
    PREFIX
    8.8.8.0/24
    TIMEZONE
    America/Los_Angeles
    REVERSE DNS
    not loaded in static example
    STACK
    IPv4
    RANGE
    8.8.8.0 – 8.8.8.255
    REGISTRY
    not loaded in static example
    02

    SOURCE MATRIX

    4 location sources agree at country level · — not covered · W/H withheld

    SIGNALIPBotIPinfoGeoLite2DB-IPIPtoASN
    COUNTRYUSUSUSUS
    CITYCalifornia, Mountain ViewCalifornia, Mountain View
    ASNAS15169AS15169AS15169AS15169
    PROXYNO
    VPNW/H
    TORNO
    HOSTINGNO
    ABUSENO
    03

    SIX-AXIS VERDICT

    NETWORK ROLEHIGH
    Public internet infrastructure

    Service role · anycast context · operator identity

    ANONYMITYMEDIUM
    No direct anonymity evidence observed

    No proxy, VPN, or Tor finding in covered fields

    ABUSE EVIDENCEMEDIUM
    No abuse evidence in covered sources

    This means “not observed,” never “clean”

    GEO CONTEXTLOW
    US · single geolocation estimate

    Country-level context; physical location not proven

    ROUTINGHIGH
    Route origin observed · RPKI state withheld by licence

    Origin ASN · announced prefix · route-origin conflict

    COVERAGEMEDIUM
    6/7 jurors responded

    Named jurors · lineage families · abstentions visible

    04

    EVIDENCE RECORD

    JURORAXISCLAIMCONF.STATUS
    Network identityIPBot networknetwork roleAS15169 · Google LLCHIGHRESPONDED
    Operator and role profileIPBot classificationnetwork rolepublic infrastructureHIGHRESPONDED
    Anonymity signalsIPBot classificationanonymityno direct proxy/VPN/Tor evidenceMEDIUMRESPONDED
    Direct threat evidenceIPBot evidenceabuseno direct record in covered evidenceMEDIUMRESPONDED
    REPORT ipjury.com/check/8.8.8.8 EXPERIMENTAL INDEX
    TERMINAL curl ipjury.com/8.8.8.8 irm ipjury.com/8.8.8.8
    IPJURY.COM · EVIDENCE, NOT AN ENTERTAINMENT SCORE

    IPJury uses the IP2Location LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP Geolocation by DB-IP. Full source credits: source register.

    05

    HOW NETWORK ROLE IS ESTABLISHED

    Is this address classified as residential, mobile or hosting?

    The network-role axis reports the classification supported by approved network and service fields. Read that label independently of proxy and abuse evidence; it describes a network, not the person or device using it.

    Evidence scope and register licence-review dates — not live lookup dates
    SourceRegister review
    IPBot Network Identity
    IPBot Classification Evidence

    Source availability depends on the current deployment and each returned record. These review dates do not establish when a particular IP was observed. Method axis-scope-2026-09-15 · Score ipjury-score-v3.

    "Is this address residential, mobile, hosting, or business?" is a network-classification question, answerable only within the returned sources’ coverage. But the answer describes a network — not a person, and not a level of trust.

    How role is actually determined

    Guessing from an autonomous-system name is the cheap method and the wrong one: operator names are marketing strings, and one ASN can carry consumer broadband, colocation, and a transit backbone at once. IPJury draws role from approved network and classification fields. Several fields can share a source; they are not automatically independent observations.

    Operator identity
    The operator named in the approved network fields, with its source provenance. This is not a separate live registry-ownership audit.
    Service role
    What the operator sells on this range: subscriber access, virtual machines, transit, enterprise connectivity, or public infrastructure such as a resolver.
    Usage classification
    How a range is used in practice, which routinely differs from how it was allocated.
    Anycast and edge traits
    Whether one address is announced from many locations at once — characteristic of CDN space, and incompatible with any single-subscriber reading.
    Routing context
    The origin ASN and announced prefix, showing which network carries the address today rather than which owns it on paper.
    RIR allocation
    The regional registry's record of who received the block, and under what allocation type. Strong for ownership, weak for present-day use.

    When those inputs disagree, IPJury reports the conflict rather than picking a winner.

    What each role does and does not imply

    • Residential. Consumer subscriber access. It does not mean a human is at the keyboard, or that the address is untouched: residential proxy networks resell exactly this egress.
    • Mobile. A carrier's cellular data network. The label alone does not establish how many subscribers share an exit or when this address was reassigned.
    • Hosting or datacenter. Servers, virtual machines, rented compute. Enormous volumes of ordinary traffic originate here: CI jobs, monitoring, corporate VPN concentrators, self-hosted mail and web services.
    • Business or enterprise. An allocation held by an organisation. One block can carry office egress, a public web server, and a VPN gateway at once.
    • Public infrastructure. Recursive resolvers, authoritative DNS, anycast services — a service answering queries, not a client.

    Role is context, not a verdict

    The axis has no ordering: no ladder runs from hosting up to residential, because it measures network type, not conduct. Treating a hosting role as an abuse finding conflates two separate questions. A hosting classification is not evidence that this address caused an incident.

    The shared-egress caveat

    Mobile carriers and many consumer ISPs place many subscribers behind one public address using carrier-grade NAT, drawing on the range 100.64.0.0/10 that RFC 6598 reserves for it. Where that applies, the address's history is collective: anything observed there belongs to the exit, not to any subscriber behind it.

    Reading role alongside anonymity and abuse

    Read the three axes in sequence, separately. Role establishes the kind of network. Anonymity states whether there is direct evidence of proxy, VPN, Tor, or relay transport. Abuse states whether a covered source holds a record against the exact address, only against its prefix neighbours, or nothing. A hosting role with no finding from covered sources differs from a returned exact-IP threat record. It does not prove that nobody reported the address elsewhere; the separate axes preserve that distinction.

    "No evidence in covered sources" is also not the same as "clean." It means the sources that answered held no finding, which depends on what they cover and which abstained. The coverage axis shows that denominator instead of leaving you to assume it.

    If you are trying to work out why two tools describe the same address differently, see why IP scores disagree.

    06

    A NUMBER NEEDS ITS EVIDENCE

    IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.

    MYSTERY SCORE MODEL
    83/100

    What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.

    • Cross-axis averaging
    • Hidden source lineage
    • Missing source treated as “false”
    • Disagreement averaged away
    • Platform outcome implied
    EVIDENCE + EXPLAINED INTERPRETATION
    BANDDISPUTED RULEsource-conflict ROLEhosting ANONYMITYno direct evidence ABUSEno record observed GEOcountry disputed ROUTINGorigin observed COVERAGE6/7 responded

    One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.

    07

    THE FIVE RULES OF EVIDENCE

    [ READ FULL METHOD ]
    1. 01

      Vote only on the same axis

      A proxy flag, an abuse report, a hosting role, and a city estimate are not interchangeable votes.

    2. 02

      Direct evidence outranks a prior

      An exact-IP record is different from an inference based on the ASN, prefix, or network category.

    3. 03

      Deduplicate source lineage

      Three websites backed by one upstream database do not become three independent evidence families.

    4. 04

      Let jurors abstain

      Timeout, no IPv6 coverage, disabled license, or missing record is shown—not silently converted to “no.”

    5. 05

      Explain dissent

      CGNAT, anycast, reassignment, data age, and route context can all produce legitimate disagreement.

    09

    QUESTIONS THE SCORE CANNOT ANSWER

    How does IPJury decide whether an address is residential or hosting?

    It combines network operator identity, service role, usage classification, anycast and edge traits, and routing context. Strong public-infrastructure markers outrank generic guesses based on the ASN name.

    Can an address be residential and still carry proxy evidence?

    Yes. Residential proxy networks and shared gateways sit inside genuine consumer space, which is why IPJury reports network role and anonymity as separate axes rather than one label.

    What does a business network role actually mean?

    It means the address sits in space allocated to an organization rather than to a consumer subscriber pool. Business allocations routinely host VPN gateways and cloud workloads, so the role is context and not a conclusion.

    Does a hosting role mean the address is being used for abuse?

    No. A hosting role describes where the address lives, not what has been done from it. Abuse evidence is a separate axis, and plenty of hosting addresses carry no record in the covered sources.

    IPJURY // RECORD

    Methodology