IP Reputation Scores Disagree. We Tested 8 IPs on 4 Free APIs

2026-10-02 · data from public, reproducible sources · by One IP

Tested 2026-10-08. Every number on this page was produced by a live request made the same day, not pulled from a datasheet. You can re-run all of them — links and endpoints included.


Why we did this

People ask "what's the reputation of this IP?" expecting one answer. There isn't one.

We run a free IP check at PureIP, and the single most common misunderstanding isn't "is the score right" — it's "what is the score even measuring." So we took 8 IPs and asked 4 free, no-signup IP reputation services the same question on the same morning, and wrote down what came back.


The 8 test IPs

We picked addresses where the "right" answer is not obvious, plus a few where it is:

IPWhat it is
8.8.8.8Google Public DNS
1.1.1.1Cloudflare DNS
9.9.9.9Quad9 DNS
185.220.101.1A known Tor exit
104.131.0.1DigitalOcean host
23.94.7.1HostPapa host, flagged abuser
45.83.220.1A host with a VPN flag
45.155.205.233A host PureIP flags as abuser

Two reserved-documentation addresses (198.51.100.1, 203.0.113.5) returned HTTP 400 from PureIP's own endpoint — a real behaviour worth knowing if you test with them.


The four APIs, and what each one returned

1. PureIP /api/ip/health — the "trust score"

GET https://pureip.app/api/ip/health?ip=8.8.8.8 — free, no key, no signup.

IPscorestatusdatacentervpntorabuser
8.8.8.863moderate✓
1.1.1.141poor✓
9.9.9.975good✓
185.220.101.140poor✓✓
104.131.0.176good✓
23.94.7.135poor✓✓
45.83.220.154moderate✓✓
45.155.205.23369moderate✓✓

Important — this is not our own scoring. The number comes from our upstream data provider ip.net.coffee as trust_score, and we pass it through unchanged. Our codebase says so outright:

> 评分本身来自上游 trust_score(0-100),我们不重新算分——只解释它。 > ("The score comes from the upstream trust_score; we don't recompute it — we only explain it.")

We add the breakdown (network type, anonymity, reputation, ASN neighbourhood) so the number is auditable rather than opaque. That distinction matters for the next section.

2. Scamalytics — the "fraud score"

Free per-IP page, no signup: https://scamalytics.com/ip/8.8.8.8

IPfraud scorerisk
8.8.8.80Low
1.1.1.10Low
9.9.9.90Low
185.220.101.150Medium
104.131.0.150Medium
23.94.7.133Medium
45.83.220.14Low
45.155.205.2330Low

3. ip-api.com — the boolean flags

Free tier, no key: http://ip-api.com/json/8.8.8.8?fields=status,proxy,hosting

IPproxyhosting
8.8.8.8truetrue
1.1.1.1falsetrue
9.9.9.9falsetrue
185.220.101.1truetrue
104.131.0.1falsetrue
23.94.7.1falsetrue
45.83.220.1truetrue
45.155.205.233falsetrue

4. ipwho.is — the one with no risk data at all

Free, no key: https://ipwho.is/8.8.8.8

Every one of the 8 IPs returned success: true with geolocation and ISP, and vpn: null, proxy: null, tor: null for all of them.

That is not a bug in our test. The free tier of ipwho.is returns no risk fields at all. If you built an "is this a proxy" check on it, you would get "no" for everything, including the Tor exit.


The three disagreements

Disagreement 1: Is 8.8.8.8 a proxy?

8.8.8.8 is Google's public DNS resolver. It is not a proxy in any sense a buyer of fraud-detection cares about. We don't know why ip-api flags it — we only report that it does, and that the other two don't. If you block on ip-api's proxy field you will block Google DNS.

Disagreement 2: 45.155.205.233 — clean or abuser?

One service calls it clean, the other flags it for abuse. We checked the upstream record directly:

GET https://ip.net.coffee/api/ip/lookup/45.155.205.233

The response carries is_abuser: true with an abuser_score label, alongside the trust_score. So PureIP's flag is upstream data, not something we invented. But we can't tell you which service is right — we can only show you that they disagree and tell you where each number came from.

Disagreement 3: the scores aren't correlated at all

PureIP's trust score (higher = better) versus Scamalytics' fraud score (higher = worse), across the 8 IPs:

IPPureIP trustScamalytics fraud
8.8.8.8630
1.1.1.1410
9.9.9.9750
185.220.101.14050
45.155.205.233690
104.131.0.17650
23.94.7.13533
45.83.220.1544

Rank correlation (Spearman ρ) between the two: -0.05.

That is not a difference of opinion. That is two instruments measuring different things. And it is exactly what you should expect: one is a *trust* score (would a normal person be behind this IP), the other is a *fraud* score (has this IP been seen doing something bad). A public DNS resolver scores poorly on trust-with-a-human-behind-it and perfectly on never-committed-fraud. Both answers are correct answers to different questions.

We are not going to dress this up as "our score is better." It isn't a contest — the number alone tells you nothing until you know which question it answers. With n=8 this correlation is illustrative, not statistical. Re-run it yourself if you need more.


What to actually do about it

1. Before you block on a score, find out which question it answers. Trust, fraud risk, proxy-detection, and abuse-history are four different axes. A vendor that gives you one number without saying which is selling opacity.

2. Ask for the breakdown, not the number. The reason PureIP publishes network type / anonymity / reputation / ASN neighbourhood alongside the score is that the number is meaningless without them. Any vendor worth using will show you the components.

3. Test against IPs you already know the answer to. We knew 185.220.101.1 was a Tor exit before we started. That's how you catch a service that returns "clean" for everything.

4. Never build a proxy check on a tier that returns null for risk fields. ipwho.is gave us vpn: null 8 times out of 8. Absent data is not "no."


Re-run it yourself

Every endpoint here needs no account and no key:

# PureIP trust score + flags
curl "https://pureip.app/api/ip/health?ip=8.8.8.8"

# Upstream record PureIP's score comes from (includes ai_verdict)
curl "https://ip.net.coffee/api/ip/lookup/8.8.8.8"

# Scamalytics fraud score (HTML page)
curl "https://scamalytics.com/ip/8.8.8.8"

# ip-api boolean flags
curl "http://ip-api.com/json/8.8.8.8?fields=status,proxy,hosting"

# ipwho.is — check the risk fields before you trust them
curl "https://ipwho.is/8.8.8.8"

Method and limits

illustrative only. Do not quote ρ = -0.05 as a finding about these services generally.

is possible, though the "Fraud Score: N" values are in the rendered page body.

set. This is a comparison of what each free tier returns, not of which one is more correct.


*Built with PureIP — free IP, network and AI-platform checks, no signup. Every number above is reproducible from the commands in this page.*

One IP is a free online toolbox for VPS and network people: IP reputation, risk scoring, AI-service reachability, global ping, DNS/CDN and WHOIS. Runs on Cloudflare Workers, no signup.

Raw data and the sampler: vps-audit-2026-09.json (360 records, CC BY 4.0). Want another provider covered? Email agent@pureip.app.

测完发现 IP 不干净?我们整理的 VPS 线路入口:RackNerd · 搬瓦工 · DMIT