Tested 2026-10-08. Every number on this page was produced by a live request made the same day,
not pulled from a datasheet. You can re-run all of them — links and endpoints included.
Why we did this
People ask "what's the reputation of this IP?" expecting one answer. There isn't one.
We run a free IP check at PureIP, and the single most common misunderstanding
isn't "is the score right" — it's "what is the score even measuring." So we took 8 IPs
and asked 4 free, no-signup IP reputation services the same question on the same morning,
and wrote down what came back.
The 8 test IPs
We picked addresses where the "right" answer is not obvious, plus a few where it is:
| IP | What it is |
|---|---|
8.8.8.8 |
Google Public DNS |
1.1.1.1 |
Cloudflare DNS |
9.9.9.9 |
Quad9 DNS |
185.220.101.1 |
A known Tor exit |
104.131.0.1 |
DigitalOcean host |
23.94.7.1 |
HostPapa host, flagged abuser |
45.83.220.1 |
A host with a VPN flag |
45.155.205.233 |
A host PureIP flags as abuser |
Two reserved-documentation addresses (198.51.100.1, 203.0.113.5) returned
HTTP 400 from PureIP's own endpoint — a real behaviour worth knowing if you test with them.
The four APIs, and what each one returned
1. PureIP /api/ip/health — the "trust score"
GET https://pureip.app/api/ip/health?ip=8.8.8.8 — free, no key, no signup.
| IP | score | status | datacenter | vpn | tor | abuser |
|---|---|---|---|---|---|---|
8.8.8.8 |
63 | moderate | ✓ | |||
1.1.1.1 |
41 | poor | ✓ | |||
9.9.9.9 |
75 | good | ✓ | |||
185.220.101.1 |
40 | poor | ✓ | ✓ | ||
104.131.0.1 |
76 | good | ✓ | |||
23.94.7.1 |
35 | poor | ✓ | ✓ | ||
45.83.220.1 |
54 | moderate | ✓ | ✓ | ||
45.155.205.233 |
69 | moderate | ✓ | ✓ |
Important — this is not our own scoring. The number comes from our upstream data provider
ip.net.coffee as trust_score, and we pass it through unchanged.
Our codebase says so outright:
评分本身来自上游 trust_score(0-100),我们不重新算分——只解释它。
("The score comes from the upstream trust_score; we don't recompute it — we only explain it.")
We add the breakdown (network type, anonymity, reputation, ASN neighbourhood) so the number
is auditable rather than opaque. That distinction matters for the next section.
2. Scamalytics — the "fraud score"
Free per-IP page, no signup: https://scamalytics.com/ip/8.8.8.8
| IP | fraud score | risk |
|---|---|---|
8.8.8.8 |
0 | Low |
1.1.1.1 |
0 | Low |
9.9.9.9 |
0 | Low |
185.220.101.1 |
50 | Medium |
104.131.0.1 |
50 | Medium |
23.94.7.1 |
33 | Medium |
45.83.220.1 |
4 | Low |
45.155.205.233 |
0 | Low |
3. ip-api.com — the boolean flags
Free tier, no key: http://ip-api.com/json/8.8.8.8?fields=status,proxy,hosting
| IP | proxy | hosting |
|---|---|---|
8.8.8.8 |
true | true |
1.1.1.1 |
false | true |
9.9.9.9 |
false | true |
185.220.101.1 |
true | true |
104.131.0.1 |
false | true |
23.94.7.1 |
false | true |
45.83.220.1 |
true | true |
45.155.205.233 |
false | true |
4. ipwho.is — the one with no risk data at all
Free, no key: https://ipwho.is/8.8.8.8
Every one of the 8 IPs returned success: true with geolocation and ISP, and
vpn: null, proxy: null, tor: null for all of them.
That is not a bug in our test. The free tier of ipwho.is returns no risk fields at all.
If you built an "is this a proxy" check on it, you would get "no" for everything,
including the Tor exit.
The three disagreements
Disagreement 1: Is 8.8.8.8 a proxy?
-
ip-api.com:
proxy: true - PureIP / Scamalytics: no proxy flag, fraud score 0
8.8.8.8 is Google's public DNS resolver. It is not a proxy in any sense a buyer of
fraud-detection cares about. We don't know why ip-api flags it — we only report that it does,
and that the other two don't. If you block on ip-api's proxy field you will block Google DNS.
Disagreement 2: 45.155.205.233 — clean or abuser?
- Scamalytics: fraud score 0, risk Low
-
PureIP: score 69, status moderate, flagged
abuser
One service calls it clean, the other flags it for abuse. We checked the upstream record directly:
GET https://ip.net.coffee/api/ip/lookup/45.155.205.233
The response carries is_abuser: true with an abuser_score label, alongside the trust_score.
So PureIP's flag is upstream data, not something we invented. But we can't tell you which
service is right — we can only show you that they disagree and tell you where each number
came from.
Disagreement 3: the scores aren't correlated at all
PureIP's trust score (higher = better) versus Scamalytics' fraud score (higher = worse),
across the 8 IPs:
| IP | PureIP trust | Scamalytics fraud |
|---|---|---|
8.8.8.8 |
63 | 0 |
1.1.1.1 |
41 | 0 |
9.9.9.9 |
75 | 0 |
185.220.101.1 |
40 | 50 |
45.155.205.233 |
69 | 0 |
104.131.0.1 |
76 | 50 |
23.94.7.1 |
35 | 33 |
45.83.220.1 |
54 | 4 |
Rank correlation (Spearman ρ) between the two: -0.05.
That is not a difference of opinion. That is two instruments measuring different things.
And it is exactly what you should expect: one is a trust score (would a normal person be
behind this IP), the other is a fraud score (has this IP been seen doing something bad).
A public DNS resolver scores poorly on trust-with-a-human-behind-it and perfectly on
never-committed-fraud. Both answers are correct answers to different questions.
We are not going to dress this up as "our score is better." It isn't a contest —
the number alone tells you nothing until you know which question it answers.
With n=8 this correlation is illustrative, not statistical. Re-run it yourself if you need more.
What to actually do about it
Before you block on a score, find out which question it answers.
Trust, fraud risk, proxy-detection, and abuse-history are four different axes.
A vendor that gives you one number without saying which is selling opacity.Ask for the breakdown, not the number. The reason PureIP publishes
network type / anonymity / reputation / ASN neighbourhood alongside the score is that
the number is meaningless without them. Any vendor worth using will show you the components.Test against IPs you already know the answer to. We knew
185.220.101.1was a Tor
exit before we started. That's how you catch a service that returns "clean" for everything.Never build a proxy check on a tier that returns
nullfor risk fields.
ipwho.is gave usvpn: null8 times out of 8. Absent data is not "no."
Re-run it yourself
Every endpoint here needs no account and no key:
# PureIP trust score + flags
curl "https://pureip.app/api/ip/health?ip=8.8.8.8"
# Upstream record PureIP's score comes from (includes ai_verdict)
curl "https://ip.net.coffee/api/ip/lookup/8.8.8.8"
# Scamalytics fraud score (HTML page)
curl "https://scamalytics.com/ip/8.8.8.8"
# ip-api boolean flags
curl "http://ip-api.com/json/8.8.8.8?fields=status,proxy,hosting"
# ipwho.is — check the risk fields before you trust them
curl "https://ipwho.is/8.8.8.8"
Method and limits
- 8 IPs, 4 services, all requests made 2026-10-08 from one machine.
- n=8 is small. The disagreements are real and reproducible; the correlation is illustrative only. Do not quote ρ = -0.05 as a finding about these services generally.
- Scamalytics figures were read from the public HTML page, not an API — a scraping artefact is possible, though the "Fraud Score: N" values are in the rendered page body.
- ip-api's free tier is rate-limited (45/minute); we paced requests and got
successon all 8. - We did not test paid tiers, and we did not test detection accuracy against a ground-truth set. This is a comparison of what each free tier returns, not of which one is more correct.
Built with PureIP — free IP, network and AI-platform checks,
no signup. Every number above is reproducible from the commands in this page.
Top comments (0)