IP Health
中文

Scoring and evidence guide

How IP Health Works

IP Health combines reputation, network identity, infrastructure, connectivity, and provider evidence into a practical IP risk assessment. It is designed to help you understand an IP before using it for login, registration, payments, remote work, or business operations.

1. Overall Score

The IP Health Score is a practical risk summary on a 0–100 scale, not a guarantee. Higher scores generally mean fewer observed concerns; lower scores mean stronger reputation, privacy-network, infrastructure, or connectivity concerns were found.

The current score combines three dimension scores: Reputation (50%), Network Quality (30%), and Compatibility (20%). Each dimension is calculated from the evidence available for that check. Missing or incomplete evidence can limit a dimension's maximum score, so the result should always be read together with Evidence Quality and Network Identity.

2. Main Assessment Dimensions

Reputation

Reviews reported abuse confidence, provider fraud or reputation scores, recent-abuse and bot signals, and reported VPN, proxy, Tor, or abuse indicators. Provider availability also affects how confidently a clean reputation result can be stated.

Network Quality

Reviews ownership visibility, ASN and organization data, consumer access signals, hosting or datacenter indicators, VPN, proxy, relay, and Tor signals. A residential or mobile classification can keep a secondary infrastructure flag in review context instead of letting that flag redefine the network by itself.

Compatibility

Uses browser connectivity probes and the result's regional or policy restriction signals to estimate whether the tested services appear reachable. “Not verified” means the browser could not fully confirm a probe; it is not the same as “unreachable.” Compatibility does not test or predict whether an account registration, payment, or login will be accepted.

3. Evidence Quality

Evidence Quality describes the coverage and completeness of the data used for the report. It is not a second risk score and it is not a direct measurement of agreement between every provider.

  • High: the required ownership, reputation, secondary intelligence, and connectivity evidence was available without a recorded coverage gap.
  • Medium: some evidence was unavailable or partial, but enough fallback reputation and network context remained for a useful assessment.
  • Low: important sources were unavailable or incomplete, increasing uncertainty in the result.

A provider failure does not automatically make an IP risky. It can cap a dimension score, reduce Evidence Quality, and produce more cautious wording. Low Evidence Quality means “less certain,” not “bad IP.”

4. Network Identity

Network Identity describes the most likely kind of network, based on privacy flags, provider usage data, ownership text, ASN patterns, and selected known public-service endpoints. The supported categories are Residential ISP, Mobile Network, Enterprise Network, Public Infrastructure, Cloud Provider, Datacenter, VPN / Proxy, Tor Exit, and Unknown.

Identity is descriptive, not a finding of maliciousness. A public DNS or CDN endpoint can be legitimate infrastructure but unsuitable as a personal access IP. An enterprise network can be clean but shared. A residential IP can still carry reputation concerns, while a datacenter IP can have clean abuse history and still face stricter platform review.

5. Sharing Risk

Sharing Risk separately estimates whether traffic may come through shared, relayed, hosted, corporate, public-service, proxy, or multi-user infrastructure. It uses privacy signals, network identity, hosting and datacenter evidence, ownership coverage, and secondary provider signals.

Tor or a strong VPN/proxy signal produces high sharing concern. Hosted, enterprise, and public infrastructure are interpreted in their identity context and can produce medium concern without being treated as malicious. Normal residential or mobile access without a strong privacy or infrastructure signal is generally assessed as low sharing risk. Limited ownership and provider data can leave the level unknown.

6. Strong Signals and Review Signals

Strong signals include Tor, VPN/proxy or relay indicators recognized by the direct identity checks, severe abuse history, recent abuse, and high provider reputation risk. These can directly drive a risk assessment or recommendation.

Review signals include secondary privacy or infrastructure flags, hosting or managed-network observations, enterprise or public routing context, and partially verified connectivity. Their meaning depends on Network Identity. Known public-service endpoints are handled before generic privacy labels, while some infrastructure observations remain review context when the network is otherwise classified as consumer, enterprise, or public infrastructure.

7. Data Sources

A report may use the following sources. No source is guaranteed to be available for every analysis.

  • IPinfo: IP ownership, ASN, organization, location, and privacy-network fields.
  • AbuseIPDB: reported abuse confidence, usage type, and ISP context.
  • IPQualityScore (IPQS): fraud, recent-abuse, bot, VPN, proxy, and Tor reputation signals when the provider responds.
  • Scamalytics: secondary reputation score and proxy, VPN, Tor, and server indicators.
  • ipapi.is: secondary privacy, hosting, datacenter, abuse, ownership, and location context.
  • Connectivity probes: browser-observed reachable, unreachable, or not-verified states for selected services.

8. How Conflicting Signals Are Handled

Provider results are evaluated together, but they do not all have the same role. Strong privacy and reputation evidence can directly affect a score or classification; some secondary fields instead act as corroborating review evidence. Network Identity is evaluated in a defined order so that, for example, a known public-service endpoint is not presented as a personal VPN solely because of a provider label.

Classification-aware wording keeps legitimate infrastructure from being described as malicious. Missing providers reduce confidence instead of failing the whole analysis. Recommendations then combine score context with identity: clean hosted infrastructure, shared enterprise traffic, and normal residential access can receive different guidance even when their reputation evidence is similar.

9. Limitations

  • The score does not guarantee that an account will be accepted.
  • Platforms use private risk systems that IP Health cannot see.
  • IP reputation and provider data can differ and change over time.
  • Browser and network conditions can affect connectivity probes.
  • “Not verified” does not mean “unreachable.”
  • A clean score does not guarantee account or transaction safety.
  • A low score does not prove malicious activity.
  • The result should be interpreted for the intended use, especially for registration, verification, payments, banking, or sensitive account changes.

10. Privacy and Data Handling

IP Health sends the IP being analyzed to server-side provider APIs. Recent-check history is stored only in your browser's localStorage, and IP Health has no account system. Anonymous product analytics use category-level fields and do not store raw IP addresses, request headers, API keys, tokens, account identifiers, or device identifiers. IP Health does not sell personal data or use tracking cookies.

Read the full Privacy page for the current data-handling statement.