An IP fraud score is a number, usually from 0 to 100, that estimates how risky a request is, judged only by the IP address it came from.
It summarises facts about the address: whether it is a VPN, proxy or Tor exit, whether it belongs to a hosting provider, and whether threat blocklists have recently reported it. A higher score means more, or stronger, evidence against the address.
How is an IP fraud score calculated?
Every vendor chooses its own signals and weights, so a 60 from one API is not a 60 from another. Most combine two kinds of evidence: classification (what the address is, such as a VPN or a datacenter server) and accusation (what it has done, such as appearing on attack blocklists). Related signals are usually capped, so one fact reported by several lists is not counted several times.
How should you use a fraud score?
Use it to sort and compare requests, and set thresholds by how costly a mistake is on each route. Many people can share one address (see CGNAT), so a score describes a network, not a person. Pair it with checks on the email, the phone number or the browser before you refuse anyone.
How Hextner uses it
VerifIP's /v1/check returns fraud_score from 0 (no evidence) to 100, a verdict of allow, challenge or block, and a signal_breakdown that lists each signal and its weight. A Tor exit alone scores 25 and a datacenter address alone 10; both stay allow, because classification is not accusation. A challenge needs accusing evidence, such as attack-feed listings. The score bands and every weight are in the VerifIP reference.
Related reading
Browse every definition in the glossary.