What a reputation check can and cannot tell you

Enter an address in the form, or leave it empty to re-check the address this connection is using. The result lists every field the queried providers actually returned, marks missing fields as unknown, and names the provider behind each value.

Reputation itself is a record of behaviour. It is not stored in the address, and there is no register of it. What exists is a set of private databases, each built from a different source: spam-trap mailboxes, honeypots that log scanning traffic, complaint feeds from mail administrators, proxy and Tor lists, and registration data from the regional internet registries. Two providers can look at the same address and reach opposite conclusions, and both can be correct about their own evidence.

The sources, and why they disagree

The comparison below is the reason this page exists. A single number hides which of these answered.

Source typeWhat it is built fromHow quickly it changesWhere it is visible
Spam-trap networksMail sent to addresses that never opted inDays to weeks, once traffic stopsOnly through the provider that runs the traps
Honeypot and scan logsConnections to sensors that should receive noneHours to daysVia the security provider publishing the feed
Mail administrator complaintsReports filed through the provider or a shared feedDays, and depends on who filesProvider dashboards, rarely public
Proxy, VPN and Tor listsPublished exit lists and observed relay behaviourHours for Tor, longer for commercial listsTor publishes its consensus; commercial lists do not
Registration and routing dataRegional registry delegation and BGP announcementsWeeks, following allocation documentsPublic through the registries and routing archives

The disagreement follows directly from the update rates and the sources. A provider watching a scanner honeypot will flag an address within hours of it being used for scanning. A provider whose evidence is registry data may take weeks to notice that a range changed owner, and by then the flag belongs to a previous tenant.

Reading a provider risk value

Where a provider publishes its own numerical risk, this page displays the value together with the name of the model that produced it. It is not converted into a percentage chance of anything, and it is not blended with any other number.

Three properties of those values matter when reading them. They are relative to that provider’s own population, so a value of 40 in one model is not a value of 40 in another. They are usually scores, not probabilities, which means a doubling of the number does not mean a doubling of risk. And they are computed on a schedule that is not published in detail, so the same address can change without anything about the address changing.

From evidence to a decision

A flagged hosting address with clean provider fields is ordinary infrastructure: many services run there, and the block is not itself a problem. An address that is flagged as a commercial VPN exit will be treated by many sites as a shared connection, which is a policy decision that no lookup can override.

The scenario worth caring about is a residential or business address carrying recent abuse reports. That combination points at either a compromised device on the network, or a range that was recently reassigned and is still carrying the previous tenant’s history. The second case is worth checking against the blacklist page and, for mail, against the deliverability test which checks the authentication records that receivers weigh alongside reputation.

What the numbers here do not include

Nothing on this page knows your sending volume, your bounce rate or the number of your messages that recipients mark as spam. Those are the signals the large mailbox providers use most heavily, and they live in your own sending infrastructure and in the postmaster tooling the receivers provide. A clean address check is a starting condition, not a result.

Equally, this page cannot tell you which address to use. Substituting a different address changes which history you inherit, and the purity page explains how to read the signals that come with the new one. For network ownership and routing rather than behaviour, see ASN lookup. The guide to IP reputation goes into how the databases are built and maintained.