An IP fraud score is a real-time risk rating that indicates how likely it is that the person behind an IP address is attempting fraud.
It works by analysing network-level signals including VPN and proxy usage, TOR node connections, open ports, geolocation consistency and blacklist status, combining them into a single score your fraud system can act on.
Try enter an IP to see how it works:
By using this tool, you agree to our Privacy Policy and General Terms of Service. This demo uses predefined example values for illustrative purposes only. No personal data is collected or stored.
at a Glance
What Is an IP Fraud Score?
An IP fraud score helps detect risky or fraudulent users by analyzing how they connect online. Signals like VPN or proxy usage, emulators, and poor IP reputation scores are assigned points. These points combine into a single score that reflects the likelihood of fraud.
For instance, a VPN might add +1, while a suspicious connection from a known TOR node could add more. IPs previously linked to bot activity, abuse, or chargebacks may be automatically blocked based on thresholds set by your fraud prevention system. Businesses often use IP risk scoring at critical moments like signup, login, or checkout—where preventing account takeovers and other threats is vital.
While it’s part of broader fraud detection, an IP fraud score is focused purely on network-level risk—not behavioral data like transactions or spending patterns.
IP Fraud Score vs. IP Reputation: What’s the Difference?
The two terms often get used interchangeably, but they answer different questions. IP reputation reflects an address’s historical trustworthiness, meaning whether it has been linked to abuse before. An IP fraud score reflects current, real-time risk, meaning whether the address shows signs of fraud right now, in this session.
The distinction matters in practice. A clean-history IP can still return a high fraud score if it is suddenly routed through a VPN, and a previously flagged IP can score lower once that activity stops.
| IP Reputation | IP Fraud Score |
|---|---|
| Reflects long-term, historical trustworthiness | Reflects real-time, current risk |
| Built from accumulated abuse history over time | Built from live signals: VPN/proxy detection, blacklist status, geolocation consistency |
| Changes gradually as behavior accumulates | Can change within a single session |
| Useful for a baseline trust assessment | Useful for a point-in-time approve, review or decline decision |
How Is an IP Fraud Score Calculated?
An IP scoring API adds and subtracts points based on detected signals. Once the total score is calculated, the system can flag a user as low, medium, or high risk.
Here’s a simplified example of how an IP risk score is built:
| Signal detected | Points |
|---|---|
| IP from high-risk country | +2 |
| Residential ISP (lower risk) | -1 |
| Suspicious SSH port open | +5 |
| IP on DNSBL spam blacklist | +4 |
| VPN detected | +3 |
| Total score | 13 → high risk |
What happens next depends on the thresholds you set. Most fraud teams auto-approve low scores, send mid-range scores for manual review and auto-decline high scores, with exact cutoffs adjusted per industry and risk appetite.
What Signals Does an IP Fraud Score Analyse?
To calculate an accurate IP fraud score, you need to analyze key IP parameters that reveal how a user connects to the internet—and whether it looks suspicious.
1. Public vs. Private IP Addresses
Think of a public IP as a mailbox at the local post office—it’s how devices connect to the wider Internet. A private IP is like mail routing inside a building. Private doesn’t mean hidden—it just links to a local network.
Public IPs are assigned by ISPs and are essential for online access. Private IPs work within local networks like offices or homes. For fraud detection, public IPs are more valuable because they offer insight into user behavior and risk.
2. IP Geolocation
Geolocation ties IPs to physical locations, often used for targeting ads or restricting content. Accuracy depends on the database: some can pinpoint city-level data, while others only detect the country. Fraud teams use this to see if a user’s location matches expected behavior.
3. Public IP Address Features
- Automatically assigned by ISPs (static or dynamic)
- Globally unique—no two are the same
- Essential for internet access across all connected devices
- Residential IPs are especially valuable to fraudsters and often traded on shady marketplaces
4. Proxy Servers and SOCKS5
Fraudsters often mask their real IPs using:
- HTTP proxies (browser-level rerouting)
- SOCKS proxies (used for apps, gaming, streaming)
- Transparent proxies (set up by organizations to filter traffic)
These tools are cheap and easy to deploy, allowing bad actors to quickly rotate IPs during attacks. SOCKS5 proxies are especially sought after because they mimic legitimate residential users more effectively.
That’s why IP lookup tools are crucial—they help detect when an IP has been spoofed or manipulated.
How Users Hide Their IP Addresses
There are many reasons why someone would want to avoid spoofing detection. Circling back to our examples above, it could simply be to watch a video from a foreign country. It could be to improve their security via added encryption. And of course, it could be for malicious purposes.
Regardless of the why, let’s see how IP addresses are hidden:
- VPNs: Short for Virtual Private Networks. Increasingly popular tools, which tunnel all traffic from a device towards a server in another location. Different VPNs offer different kinds of IP addresses, such as static, dynamic, or shared.
- TOR: a system designed to maintain a user’s anonymity by masking IP addresses. Users download and run a free browser, which passes and encrypts traffic multiple times to hide the original IP address. However, an ISP or fraud detection tool will know if the user connected to TOR’s entry and exit nodes.
- Proxy servers: act as a middle man between a device and a visited website. TOR and VPNs are also considered proxies, even if they redirect all traffic coming from all software and device systems.
Proxies help fraudsters hide their IP addresses and stay anonymous. See how bad agents use them, and how our API flags them.
Learn more
Velocity Rules for IP Usage
So what should you do if you find a suspicious user’s IP address connecting to your system? You could simply block it straight away, but adding that address to an IP blacklist doesn’t make sense. This is because IP addresses are mostly dynamic, and multiple users could eventually end up sharing them, so you’d end up blocking valid customers.
This is why you can’t just look at the IP address itself, but also their usage via velocity rules. These algorithms look at the patterns and changes of IP address usage over time, which helps anti-fraud intelligence.
The Benefits of IP Analysis Against Fraud
As we’ve seen, IP addresses contain a multitude of valuable parameters that help us calculate risk. It’s not the only reason to rely on IP analysis against fraud. Here is why you should deploy that type of tool today:
- Lightweight checks: IP analysis is invisible to the end user. All the checks happen behind the scenes, without slowing down the user journey.
- Real-time results: checking most IP parameters is nearly instantaneous, which also helps create a frictionless experience without sacrificing safety.
As for the types of fraud you can detect with IP analysis, they include bot traffic, bonus abuse, multi-accounting, payment fraud, and more.
Where IP Fraud Scoring Matters Most
IP fraud scoring earns its place differently in each industry, because the fraud patterns and the moments of risk are not the same. Where one sector worries about coordinated signup rings, another is focused on cross-border payment risk or account takeover at login. The five verticals below show how the same network-level signals map to very different problems.
- Fintech sees the risk concentrate at signup. Coordinated fraud rings and bot registrations often arrive before identity verification, so IP scoring filters automated attempts during onboarding without adding friction for genuine users.
- For Payments, the pressure point is authorization. Cross-border traffic routed through a VPN to disguise its origin is a common indicator, and scoring the connection before a transaction is authorized catches it before funds move.
- iGaming operators lean on IP signals for two things: confirming a player is not connecting from a restricted or self-excluded jurisdiction, and surfacing bonus-abuse rings, which tend to share the same IP infrastructure across many accounts.
- In Banking, the reference point is consistency. A login from a VPN or proxy on an account that has never used one is a recognized signal of account takeover, which IP scoring makes visible at the moment of login.
- Retail fraud tends to be automated: bot-driven checkout attacks, promo and coupon fraud, and card testing. These are usually routed through proxy networks, so the connection type itself becomes a useful filter.
Discover how VPN provider Buffered used SEON’s IP fraud scoring to block high-risk traffic and cut chargebacks almost instantly.
Find out moreFAQ
What is an IP score?
There are two types of IP scores. One of them is called an IP reputation score. Service providers use it to determine if your emails should pass spam filters. In fraud prevention, your IP risk score can determine if a system labels you as fraudulent or not,
What is IP abuse?
Any improper use of the IP address of a server is considered IP abuse. This includes spamming, phishing attempts, DDoS or malware attacks.
What is the IP score rating?
An IP score rating helps businesses determine whether an IP address is risky or not. While there is no standard for how the scores are calculated, a higher score tends to point towards a risky IP.
How to do IP analysis?
IP analysis can be performed manually by taking certain parameters, such as an IP address, and checking it against public databases. However, most businesses automate the process using IP lookup and IP risk-scoring tools
