Core Ownership
Checks whether this IP has a current BGP route, and whether its registered country matches its actual location — a match looks like a genuine local user, a mismatch looks like a cross-border cloud egress, and no route at all is flagged separately as unannounced.
This IP's carrier-registered country matches its actual detected location — for example, a China Telecom IP detected within China. Usually local residential broadband or a local datacenter; platforms tend to treat it favorably.
The carrier-registered country differs from the actual detected country — common with multinational cloud services like Cloudflare and AWS that broadcast the same IP block worldwide. Account, payment, and streaming platforms tend to treat this type of IP with more caution.
No Origin ASN or visible route for this IP can be found in the current public BGP table. It may already be allocated to an organization but simply isn't being broadcast right now; this is not the same as a Broadcast IP, and it can't be evaluated as a normal ASN-backed egress.
The ASN registration country or IP geolocation data is missing, but it hasn't clearly fallen into the Unannounced or Broadcast state. Not necessarily a bad sign — just insufficient evidence.
Risk Colors
The color bar at the top of the score card falls into one of 6 colors based on the total score, matching the A+/A/B/C/D/F grades in the "Overall Grade" section below. Seeing a color tells you roughly which band the score is in.
IP Types
What this IP is used for — residential broadband, mobile cellular data, a corporate line, a datacenter server, or public infrastructure (DNS / CDN). The vast majority of IPs fall into one of the 12 categories below.
An IP assigned by a carrier to a home broadband subscriber — the most common type for genuine users browsing the internet. Platforms favor this kind of egress most for sensitive scenarios like account registration, payments, streaming, and AI subscriptions.
The egress of a phone's 4G / 5G cellular network. Genuine users, but carriers pack many people behind the same IP (CGNAT), and the IP changes frequently — worth watching for long-lived account assets.
The egress of a corporate leased line or office network. Looks more "professional" than residential, but the risk is still low — common for employees browsing or logging into company accounts.
Networks of schools, universities, and research institutions. Generally clean, but dorm/campus WiFi has historically been used by students for scraping or abuse, so watch for residual blacklist history.
Networks of government agencies, public institutions, defense, or military bodies. Shown as its own category rather than judged as ordinary business/residential — check the ownership carefully before deciding on a business use case.
Public DNS resolvers such as 1.1.1.1, 8.8.8.8, and 9.9.9.9. This is a domain-resolution service, not a user's actual browsing egress.
One of only 13 root server groups worldwide (a.root-servers.net, etc.). The internet's most foundational infrastructure, rarely seen as a business egress.
Edge nodes of CDNs such as Cloudflare, Akamai, Fastly, and AWS CloudFront. Any user visiting a site behind one of these CDNs may resolve to this IP — it does not represent an end user's real IP.
IPs of datacenters, VPS, colocation hosting, and cloud servers. Well-suited for running servers, but using them to log into accounts, register new accounts, or make payments is easily flagged by platform risk control as a "non-human user".
The egress of privacy relays like iCloud Private Relay. Apple devices route through this kind of IP when "Private Relay" is enabled — not technically a proxy, but it does mask the real location.
An exit node of the Tor network (the Tor Project publishes a public list). Platform risk control almost always rejects these outright — using one for business is essentially self-sabotage.
Signals from multiple data sources conflict or are all missing, making classification impossible. Not necessarily a bad IP — just insufficient evidence to conclude; querying another IP or retrying may clarify it.
Behavioral Signal Badges
Risk markers shown alongside IP type on the IP detail card. A residential IP can, at the same time, carry a behavioral tag such as "Residential Proxy" or "Abuse". Proxy / VPN / Tor Exit / Relay IP are already IP types and are not repeated here.
A genuine residential IP sold to a proxy provider as an exit node, common in third-party scraping pools / data-collection networks. The underlying ownership is residential, but the behavior is proxy-like — platform risk control treats it as a proxy egress.
Identified as crawler / automated scraping traffic. Common causes include high-frequency requests, missing normal browser fingerprints, and bulk API calls — account registration and login flows will generally be blocked.
Identified for sending spam email, mass spam comments, or similar abusive behavior. Email delivery and community posting services will typically reject this kind of egress.
Reported multiple times in public abuse databases for malicious behavior such as brute-force login attempts, vulnerability scanning, and credential stuffing. Affects this IP's cleanliness grade.
IPs from RFC-reserved blocks, private address ranges, or documentation example ranges that should never appear on the public internet. The system blocks these before they're ever written, so they never enter the database or participate in ranking.
6-Dimension Scoring
Each dimension is scored independently from 0-100, weighted and summed, then multiplied by a business-applicability coefficient (highest for residential IPs, lower for IDC) to produce the final total score.
Whether the IP has a current BGP Origin ASN, whether its registered country matches its actual location, and whether the route is legitimately signed. Reflects how clear this IP's "identity" is.
Whether the IP behaves as an anonymizing egress — proxy / VPN / Tor / residential proxy / privacy relay. This dimension carries the highest weight and directly determines whether it can be used for genuine-user business.
The cumulative intensity of reports in public abuse databases, how recent those reports are, and whether the IP is flagged as high-abuse. Reflects how many victims have historically reported this IP.
The number of hits across public blacklists such as email DNSBLs, HTTP honeypots, and threat intelligence feeds. More hits indicate a historically dirtier IP.
Historical counts of specific attack behaviors such as brute-force login attempts, mass junk registrations, and comment spam. Reflects this IP's record of initiating attacks.
CleanIP's own blacklist/allowlist and threat-event records. IPs that have been reported or blacklisted on-site historically show up in this dimension.
Overall Grade
The weighted sum of the 6 dimensions plus the business-applicability coefficient produces a score from 0-100, displayed as one of the 6 grades below: A+ / A / B / C / D / F. The color bar at the top of the detail card matches this exactly.
The business-applicability coefficient lets normal networks like residential / mobile / education / government reach close to a perfect score, business networks slightly lower, and datacenter / IDC networks are compressed into a lower range; public infrastructure (DNS / CDN) is treated as informational and excluded from normal scoring. A clean residential IP defaults to the mid-to-high score range — reaching the top A+ requires comprehensive positive evidence such as long-term tracking, verified clean across multiple sources, and inclusion on the local allowlist.