Tencent Cloud and Alibaba Cloud look identical on paper. Both assign IPs with essentially no reverse DNS — Tencent at 29/30 missing, Alibaba at 30/30. Neither publishes a registrant organisation in RDAP — every single Tencent IP in this sample (30/30) returns no registrant on record, the only provider of the twelve at 100%.
Their blocklist rates are not identical.
| Provider | PTR missing | No registrant | On a blocklist |
|---|---|---|---|
| Tencent Cloud | 29/30 | 30/30 | 6/30 (20%) |
| Alibaba Cloud | 30/30 | 18/30 | 1/30 (3.3%) |
Six times the listing rate, from two providers whose IP metadata is equally broken.
Metadata cannot tell them apart
Everything you can look up without querying a blocklist — PTR record, RDAP registrant, abuse contact — comes back equally empty for both. Tencent publishes an abuse role on 10/30 of its IPs, Alibaba on 12/30. Statistically indistinguishable.
If you were screening a VPS by checking its reverse DNS and WHOIS, you would have no way of telling the Tencent range from the Alibaba range. One carries six times the blocklist risk.
The listings are scattered, not network-wide
All six of Tencent's listed IPs appear on exactly one list — dnsbl.spfbl.net — the same single automated list that dominates the entire dataset (41 of 47 listed IPs across all 12 providers).
But unlike RackNerd, whose 25 listed IPs spread across 25 different /24 blocks look like one operator's policy applied network-wide, Tencent's six listings sit in six separate /24 ranges with no neighbours listed. That pattern reads as individual instances doing something that triggered one automated list, not a network-level decision.
The "Chinese IPs are dirty" assumption doesn't hold either
Pooling the two Chinese providers against the other ten:
| IPs | Listed | Rate | |
|---|---|---|---|
| Tencent + Alibaba | 60 | 7 | 11.7% |
| Other 10 providers | 300 | 40 | 13.3% |
The Chinese providers come in slightly cleaner than the rest of the sample. Whatever explains Tencent's 6/30, it is not the country.
What to actually check
Neither reverse DNS nor RDAP records will tell you whether an IP is clean. The only query that answers the question is the blocklist query itself.
-
Check the blocklists directly — all eight, not one. A single listing from
dnsbl.spfbl.netmeans something different from a listing on SpamCop or UCEProtect. - Check how many lists. In this dataset no IP appears on more than one list — a single listing is the norm, and 87% of all listings trace back to SPFBL alone.
- Ignore PTR and registrant as reputation signals. They describe how the provider provisions IPs, not how the IP has been used.
Method
360 IPs, 30 per provider, across 12 providers: RackNerd, BandwagonHost, Vultr, DigitalOcean, Linode, Hetzner, OVH, Contabo, Oracle Cloud, Alibaba Cloud, Tencent Cloud, and DMIT.
PTR looked up via direct DNS query, classified as named or none. Blocklists checked against 8 public DNSBLs: all.s5h.net, dnsbl-1.uceprotect.net, bl.spamcop.net, dnsbl.dronebl.org, dnsbl.spfbl.net, hostkarma.junkemailfilter.com, psbl.surriel.com, and bl.blocklist.de. RDAP queried against the relevant registry.
Full data: pureip.app/research/vps-audit-2026-09/en/
Blocklist check for any specific IP: pureip.app
Top comments (0)