Hextner
VerifIPDetectBTPricingDocsSupport
Sign inStart free →
  1. Hextner
  2. Glossary
  3. IP fraud score

What is an IP fraud score? 

An IP fraud score is a number, usually from 0 to 100, that estimates how risky a request is, judged only by the IP address it came from.

It summarises facts about the address: whether it is a VPN, proxy or Tor exit, whether it belongs to a hosting provider, and whether threat blocklists have recently reported it. A higher score means more, or stronger, evidence against the address.

How is an IP fraud score calculated?

Every vendor chooses its own signals and weights, so a 60 from one API is not a 60 from another. Most combine two kinds of evidence: classification (what the address is, such as a VPN or a datacenter server) and accusation (what it has done, such as appearing on attack blocklists). Related signals are usually capped, so one fact reported by several lists is not counted several times.

How should you use a fraud score?

Use it to sort and compare requests, and set thresholds by how costly a mistake is on each route. Many people can share one address (see CGNAT), so a score describes a network, not a person. Pair it with checks on the email, the phone number or the browser before you refuse anyone.

How Hextner uses it

VerifIP's /v1/check returns fraud_score from 0 (no evidence) to 100, a verdict of allow, challenge or block, and a signal_breakdown that lists each signal and its weight. A Tor exit alone scores 25 and a datacenter address alone 10; both stay allow, because classification is not accusation. A challenge needs accusing evidence, such as attack-feed listings. The score bands and every weight are in the VerifIP reference.

Related reading

  • Tor exit node
  • Datacenter IP
  • CGNAT (carrier-grade NAT)
  • ASN (autonomous system number)

Browse every definition in the glossary.

Hextner

Adversarial traffic detection for teams that ship to the open internet.

Product

  • VerifIP
  • DetectBT
  • Pricing
  • Documentation

Company

  • Support
  • Release notes
  • Talk to sales
  • Get an API key
  • Console

Resources

  • Glossary
  • Use cases
  • India

Stay in the loop

Release notes (also as an RSS feed), new signals, and the occasional write-up on how detection actually gets evaded.

Create an account →

This product includes GeoLite Data created by MaxMind, available from https://www.maxmind.com. IP blocklist data: The Spamhaus Project (DROP). Phishing data: PhishTank, CC BY-SA 2.5. Malware data: abuse.ch. Hextner uses the IP2Proxy LITE database for IP geolocation. Full notices: Data sources.

© 2026 Hextner. All rights reserved.
Privacy PolicyTerms of ServiceData sources