What a reputation check can and cannot tell you
Enter an address in the form, or leave it empty to re-check the address this connection is using. The result lists every field the queried providers actually returned, marks missing fields as unknown, and names the provider behind each value.
Reputation itself is a record of behaviour. It is not stored in the address, and there is no register of it. What exists is a set of private databases, each built from a different source: spam-trap mailboxes, honeypots that log scanning traffic, complaint feeds from mail administrators, proxy and Tor lists, and registration data from the regional internet registries. Two providers can look at the same address and reach opposite conclusions, and both can be correct about their own evidence.
The sources, and why they disagree
The comparison below is the reason this page exists. A single number hides which of these answered.
| Source type | What it is built from | How quickly it changes | Where it is visible |
|---|---|---|---|
| Spam-trap networks | Mail sent to addresses that never opted in | Days to weeks, once traffic stops | Only through the provider that runs the traps |
| Honeypot and scan logs | Connections to sensors that should receive none | Hours to days | Via the security provider publishing the feed |
| Mail administrator complaints | Reports filed through the provider or a shared feed | Days, and depends on who files | Provider dashboards, rarely public |
| Proxy, VPN and Tor lists | Published exit lists and observed relay behaviour | Hours for Tor, longer for commercial lists | Tor publishes its consensus; commercial lists do not |
| Registration and routing data | Regional registry delegation and BGP announcements | Weeks, following allocation documents | Public through the registries and routing archives |
The disagreement follows directly from the update rates and the sources. A provider watching a scanner honeypot will flag an address within hours of it being used for scanning. A provider whose evidence is registry data may take weeks to notice that a range changed owner, and by then the flag belongs to a previous tenant.
Reading a provider risk value
Where a provider publishes its own numerical risk, this page displays the value together with the name of the model that produced it. It is not converted into a percentage chance of anything, and it is not blended with any other number.
Three properties of those values matter when reading them. They are relative to that provider’s own population, so a value of 40 in one model is not a value of 40 in another. They are usually scores, not probabilities, which means a doubling of the number does not mean a doubling of risk. And they are computed on a schedule that is not published in detail, so the same address can change without anything about the address changing.
From evidence to a decision
A flagged hosting address with clean provider fields is ordinary infrastructure: many services run there, and the block is not itself a problem. An address that is flagged as a commercial VPN exit will be treated by many sites as a shared connection, which is a policy decision that no lookup can override.
The scenario worth caring about is a residential or business address carrying recent abuse reports. That combination points at either a compromised device on the network, or a range that was recently reassigned and is still carrying the previous tenant’s history. The second case is worth checking against the blacklist page and, for mail, against the deliverability test which checks the authentication records that receivers weigh alongside reputation.
What the numbers here do not include
Nothing on this page knows your sending volume, your bounce rate or the number of your messages that recipients mark as spam. Those are the signals the large mailbox providers use most heavily, and they live in your own sending infrastructure and in the postmaster tooling the receivers provide. A clean address check is a starting condition, not a result.
Equally, this page cannot tell you which address to use. Substituting a different address changes which history you inherit, and the purity page explains how to read the signals that come with the new one. For network ownership and routing rather than behaviour, see ASN lookup. The guide to IP reputation goes into how the databases are built and maintained.