What this page checks, and how

Enter an address below, or leave the field empty to re-check the exit address this connection uses. The result is built from separate observations, and each one names the provider that supplied it. The table further down states, for every signal, what it demonstrates and what it does not.

The rule set is deliberately small, and it is published here rather than applied behind the interface. A signal is reported as flagged, not flagged, or unknown. Nothing is weighted, nothing is summed, and no threshold converts the three values into a grade. If a future version adds an observation, it will appear as another row rather than as a change in a number.

The signals and what each one means

Data centre. The address is registered to a hosting or cloud provider. This usually means the service behind it is a server rather than a home connection, which is exactly what many providers check for. It says nothing about intent.

VPN exit. A provider believes the address is used as the public exit of a commercial privacy network. The address is shared by many users at once, so it carries the behaviour of all of them, which is why VPN exits are frequently rate-limited.

Proxy. The address appears in a list of forwarding services, including open proxies and anonymising pools. The distinction between a legitimate corporate proxy and a compromised host is not visible from the address.

Tor exit. The address is published in the Tor exit-consensus list. This is the one signal with a genuinely public and verifiable source, because the Tor directory authorities publish the list that anyone can fetch and compare.

Reported abuse. A provider has attached abuse reports to the address. The number of reports, the reporting parties and the age of the reports are not in the field, so the flag is weaker evidence than it looks.

Bogon or reserved range. The address falls inside a range that should not appear on the public internet at all, such as a private RFC 1918 block, link-local space or an unallocated reservation. Seeing this value on an address observed from outside usually means the answer, not the connection, is wrong.

Evidence, and what it can prove

The columns in this table are the whole method. Rows are the observations above; the third column is the part that almost every commercial tool omits.

ObservationIt can proveIt cannot prove
Data centreWhere the range is registered and how it is operatedWhether this particular service is trustworthy
VPN exitThat the address is a known commercial exit, when the provider’s list is currentWho is behind it, or what they have done
ProxyThat the address appeared in a forwarding list at some pointThat it is forwarding traffic now
Tor exitThat the address is in the published Tor consensus at query timeAnything about non-Tor traffic on the same host
Reported abuseThat reports exist in one provider’s databaseThe volume, the seriousness or the age of those reports
BogonThat the value is inconsistent with a public addressAny judgement about a service

Reading the result without inventing a conclusion

An address that carries no flags has not been proven safe. It means the providers queried had nothing recorded, which is the expected state for most addresses and also for addresses whose reports have expired or were never reported. The absence of an observation is not the same as a negative observation, and this page keeps the two apart.

Practical use looks like this: a flagged hosting signal plus a known VPN signal on the same address means the address is shared infrastructure, so its behaviour is not attributable to one user. A lone reported-abuse flag on an otherwise ordinary residential range means the range has history worth reading before assuming the worst.

What this check does not do

It does not query any blocklist. Blocklists are separate organisations with separate lookup rules, and they are covered on the IP blacklist check page. It does not measure whether your traffic is being throttled, which depends on the receiving network rather than on the address. It does not resolve the address to a host name, which the reverse DNS lookup does. And it does not tell you which of the signals matters for the site you are trying to reach, because that site’s rule set is not published.

The providers are named in every result with the time of the query. Where a free quota has run out, the fields that provider owns are reported as unavailable rather than replaced. The IP reputation check page compares the providers themselves, and the guide to IP reputation explains how reputation is built and how long it takes to change. Related questions about ownership live in ASN lookup, and a starting order for diagnosing a broken connection is in the network diagnostics guide.