A high IP score is a claim. Ask what evidence produced it.

EDGE: READY
More options
What are you checking?
EXAMPLE Checked static example Cache n/a NOT LIVE
IP

8.8.8.8

EXAMPLERUN A LIVE CHECK
ASN
AS15169 · Google LLCgoogle.com
LOCATION
US · California, Mountain View
IPBot
🇺🇸 US · California, Mountain View
IPinfo
🇺🇸 US · AS15169
GeoLite2
🇺🇸 US
DB-IP
🇺🇸 US · California, Mountain View
Bright Data
🇺🇸 US · California, Mountain View
ROUTE
ANNOUNCED 8.8.8.0/24
IP TYPE
PUBLIC INTERNET INFRASTRUCTURE
Not assessedIPJURY SCOREEXPERIMENTAL · NOT A PROBABILITY IPJURY VERDICT EXAMPLE

Run a live check for an evidence verdict and experimental interpretation.

Why this result · full calculation

Run a live check. The example is not scored.

    Evidence confidence is not prediction accuracy. A provisional range spans policy outcomes for unanswered questions; it is not a probability interval.

    OPEN FULL EVIDENCE REPORT

    JURY READY

    Enter an address, or check your own connection · the example below is replaced in place

    FULL REPORT IDENTITY · SOURCE MATRIX · SIX-AXIS VERDICT · EVIDENCE RECORD
    EVIDENCE SNAPSHOTSEPARATE AXES · NOT A SCORE
    ANONYMITY
    No direct anonymity evidence observed
    ABUSE EVIDENCE
    No abuse evidence in covered sources
    COVERAGE
    6/7 jurors responded
    01

    IDENTITY

    COORDINATES
    not loaded in static example
    ROUTING
    ROUTE ORIGIN OBSERVED
    PREFIX
    8.8.8.0/24
    TIMEZONE
    America/Los_Angeles
    REVERSE DNS
    not loaded in static example
    STACK
    IPv4
    RANGE
    8.8.8.0 – 8.8.8.255
    REGISTRY
    not loaded in static example
    02

    SOURCE MATRIX

    4 location sources agree at country level · — not covered · W/H withheld

    SIGNALIPBotIPinfoGeoLite2DB-IPIPtoASN
    COUNTRYUSUSUSUS
    CITYCalifornia, Mountain ViewCalifornia, Mountain View
    ASNAS15169AS15169AS15169AS15169
    PROXYNO
    VPNW/H
    TORNO
    HOSTINGNO
    ABUSENO
    03

    SIX-AXIS VERDICT

    NETWORK ROLEHIGH
    Public internet infrastructure

    Service role · anycast context · operator identity

    ANONYMITYMEDIUM
    No direct anonymity evidence observed

    No proxy, VPN, or Tor finding in covered fields

    ABUSE EVIDENCEMEDIUM
    No abuse evidence in covered sources

    This means “not observed,” never “clean”

    GEO CONTEXTLOW
    US · single geolocation estimate

    Country-level context; physical location not proven

    ROUTINGHIGH
    Route origin observed · RPKI state withheld by licence

    Origin ASN · announced prefix · route-origin conflict

    COVERAGEMEDIUM
    6/7 jurors responded

    Named jurors · lineage families · abstentions visible

    04

    EVIDENCE RECORD

    JURORAXISCLAIMCONF.STATUS
    Network identityIPBot networknetwork roleAS15169 · Google LLCHIGHRESPONDED
    Operator and role profileIPBot classificationnetwork rolepublic infrastructureHIGHRESPONDED
    Anonymity signalsIPBot classificationanonymityno direct proxy/VPN/Tor evidenceMEDIUMRESPONDED
    Direct threat evidenceIPBot evidenceabuseno direct record in covered evidenceMEDIUMRESPONDED
    REPORT ipjury.com/check/8.8.8.8 EXPERIMENTAL INDEX
    TERMINAL curl ipjury.com/8.8.8.8 irm ipjury.com/8.8.8.8
    IPJURY.COM · EVIDENCE, NOT AN ENTERTAINMENT SCORE

    IPJury uses the IP2Location LITE database for IP geolocation. This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP Geolocation by DB-IP. Full source credits: source register.

    05

    TRANSLATE A SCORE INTO EVIDENCE QUESTIONS

    Which findings explain the score I was shown?

    IPJury explains its own versioned policy index through the visible evidence axes and exclusions. Use those facts to question an outside score, without assuming that another vendor uses the same inputs or rules.

    Evidence scope and register licence-review dates — not live lookup dates
    SourceRegister review
    IPJury experimental interpretation policy
    IPBot Direct Evidence

    Source availability depends on the current deployment and each returned record. These review dates do not establish when a particular IP was observed. Method axis-scope-2026-09-15 · Score ipjury-score-v3.

    Some site told you an address is "high risk" and gave you a number instead of a reason. Before acting on it, work out which claim produced it — "risk" is not one measurement but several compressed into a word.

    Five questions, in order

    1. Check the network role first. A network-role prior can explain part of a score; check the displayed method before assuming it is the cause. If the address belongs to a hosting provider, many classifiers raise their output on that basis alone, before looking at anything the address has done. That is a defensible choice for a platform blocking bulk automation, and a poor diagnosis for someone running a personal server. Establish the role, then ask whether the figure survives once you set it aside. Do not assume that no other issue remains: an outside system may use evidence this record does not contain.
    2. Look for a record against the exact address. There is a large difference between a source holding a report about 203.0.113.45 and one holding reports about other addresses in 203.0.113.0/24. The first is evidence about your address; the second about your neighbours, inherited because you share a prefix that may hold thousands of unrelated customers. A tool that cannot tell you which you have is not showing you evidence.
    3. Separate anonymity from abuse. A proxy, VPN, or Tor finding describes how traffic is transported. An abuse record states that something was observed and reported. Many scoring systems fold both into one figure, so an address whose entire "risk" is "this is a VPN endpoint" reads identically to one with a spam history. Those call for different responses, and the number hides which you have.
    4. Check freshness and dataset vintage. Every finding has an age, and addresses change hands constantly. A block reassigned last quarter carries the previous tenant's labels until each dataset refreshes on its own schedule, and mobile addresses may serve a different subscriber within hours. A record with no timestamp, or older than the address's likely tenancy, is a historical note rather than a description of it now.
    5. Account for causes that are not the address. If the symptom is a CAPTCHA loop, a declined sign-up, or a verification prompt, platforms weigh signals no IP tool can see: account age, payment history, device fingerprint, browser configuration, behaviour. An address-level explanation covers address-level friction; assuming it covers everything sends people chasing a problem they do not have.

    What to do with the answer

    Once decomposed, the useful outcomes are narrow but real.

    • If the finding is a role prior only. The observed role is not itself an abuse event. Ask the service about its network policy without asserting that all other causes have been excluded.
    • If the finding is prefix-inherited. The record belongs to the range. Ask the operator who controls the range and follow the named source’s process; quote the exact scope rather than substituting a score.
    • If there is a direct exact-IP record. Now you have something specific: a named source, a date, a claim. Go to that source's own dispute or delisting process — using the procedure that operator actually publishes.
    • If a record looks wrong. Bring the disputed claim and a public source that contradicts it. Evidence changes an evidence record; screenshots of unexplained numbers do not.

    One caution: no IP evidence record, including this one, can promise a platform will change its decision. Platforms do not publish their inputs. The evidence documents possible IP-side contributors. It cannot establish or exclude the address as the cause of that platform’s decision.

    If two tools gave you different answers about the same address, see why IP scores disagree.

    06

    A NUMBER NEEDS ITS EVIDENCE

    IPJury keeps network type, anonymity, abuse, location, routing and coverage separate. Its optional experimental index explains a published policy over those facts; it never replaces the named evidence verdict or conceals missing information.

    MYSTERY SCORE MODEL
    83/100

    What does 83 measure? Who supplied it? Is hosting being treated as abuse? Did one heuristic outweigh a direct record? A number cannot tell you that two of its sources flatly contradicted each other.

    • Cross-axis averaging
    • Hidden source lineage
    • Missing source treated as “false”
    • Disagreement averaged away
    • Platform outcome implied
    EVIDENCE + EXPLAINED INTERPRETATION
    BANDDISPUTED RULEsource-conflict ROLEhosting ANONYMITYno direct evidence ABUSEno record observed GEOcountry disputed ROUTINGorigin observed COVERAGE6/7 responded

    One rule read one axis and named the state. The axes it did not read stay beside it. “Disputed” and “too little coverage to say” are answers a single number cannot express.

    07

    THE FIVE RULES OF EVIDENCE

    [ READ FULL METHOD ]
    1. 01

      Vote only on the same axis

      A proxy flag, an abuse report, a hosting role, and a city estimate are not interchangeable votes.

    2. 02

      Direct evidence outranks a prior

      An exact-IP record is different from an inference based on the ASN, prefix, or network category.

    3. 03

      Deduplicate source lineage

      Three websites backed by one upstream database do not become three independent evidence families.

    4. 04

      Let jurors abstain

      Timeout, no IPv6 coverage, disabled license, or missing record is shown—not silently converted to “no.”

    5. 05

      Explain dissent

      CGNAT, anycast, reassignment, data age, and route context can all produce legitimate disagreement.

    09

    QUESTIONS THE SCORE CANNOT ANSWER

    My address is flagged high risk. Does that mean I did something wrong?

    No. A score is a method's interpretation of evidence about an address, not evidence that its current user did something wrong.

    Which IP-side findings can this record explain?

    It separates source-reported role, covered anonymity evidence, exact-address records, surrounding-prefix context and location/routing differences. It cannot identify a platform's private reason or reconstruct all previous labels.

    Can I lower my IP risk score?

    You cannot edit a third-party dataset. If you control the address you can remove the cause and pursue corrections or delisting with the relevant operator; on an ISP-assigned or shared address the reputation is not yours to change.

    How long does a poor address reputation last?

    It varies by source. Direct records age out on each operator's own schedule, while inferred labels persist until that dataset is refreshed. IPJury reports the checked time and cache state rather than predicting an expiry.

    IPJURY // RECORD

    Methodology