IP TYPES

IP Types, Badges & Scoring System

An explanation of all badges, IP type classifications, the 6-dimension scoring model, and grading standards shown across CleanIP.

Core Ownership

Checks whether this IP has a current BGP route, and whether its registered country matches its actual location — a match looks like a genuine local user, a mismatch looks like a cross-border cloud egress, and no route at all is flagged separately as unannounced.

Native IP
Positive

This IP's carrier-registered country matches its actual detected location — for example, a China Telecom IP detected within China. Usually local residential broadband or a local datacenter; platforms tend to treat it favorably.

Broadcast IP
Deduction

The carrier-registered country differs from the actual detected country — common with multinational cloud services like Cloudflare and AWS that broadcast the same IP block worldwide. Account, payment, and streaming platforms tend to treat this type of IP with more caution.

Unannounced
Minor Deduction

No Origin ASN or visible route for this IP can be found in the current public BGP table. It may already be allocated to an organization but simply isn't being broadcast right now; this is not the same as a Broadcast IP, and it can't be evaluated as a normal ASN-backed egress.

Unspecified
Neutral

The ASN registration country or IP geolocation data is missing, but it hasn't clearly fallen into the Unannounced or Broadcast state. Not necessarily a bad sign — just insufficient evidence.

Risk Colors

The color bar at the top of the score card falls into one of 6 colors based on the total score, matching the A+/A/B/C/D/F grades in the "Overall Grade" section below. Seeing a color tells you roughly which band the score is in.

A+ 95-100
Excellent — almost no negative signals, verified clean across multiple sources
A 85-94
Good — where most residential ISP IPs land
B 70-84
Fair — the default ceiling for hosting / IDC
C 50-69
Average — hits 1-2 anonymity/abuse signals
D 25-49
Poor — multiple high-risk signals stacked, blocked by many platforms
F 0-24
Very Poor — Tor / multiple blacklists / severe abuse

IP Types

What this IP is used for — residential broadband, mobile cellular data, a corporate line, a datacenter server, or public infrastructure (DNS / CDN). The vast majority of IPs fall into one of the 12 categories below.

Residential IP
Low Risk

An IP assigned by a carrier to a home broadband subscriber — the most common type for genuine users browsing the internet. Platforms favor this kind of egress most for sensitive scenarios like account registration, payments, streaming, and AI subscriptions.

Mobile IP
Low Risk

The egress of a phone's 4G / 5G cellular network. Genuine users, but carriers pack many people behind the same IP (CGNAT), and the IP changes frequently — worth watching for long-lived account assets.

Business IP
Low Risk

The egress of a corporate leased line or office network. Looks more "professional" than residential, but the risk is still low — common for employees browsing or logging into company accounts.

Education IP
Low Risk

Networks of schools, universities, and research institutions. Generally clean, but dorm/campus WiFi has historically been used by students for scraping or abuse, so watch for residual blacklist history.

Government IP
Special

Networks of government agencies, public institutions, defense, or military bodies. Shown as its own category rather than judged as ordinary business/residential — check the ownership carefully before deciding on a business use case.

Public DNS
Informational

Public DNS resolvers such as 1.1.1.1, 8.8.8.8, and 9.9.9.9. This is a domain-resolution service, not a user's actual browsing egress.

Root DNS
Informational

One of only 13 root server groups worldwide (a.root-servers.net, etc.). The internet's most foundational infrastructure, rarely seen as a business egress.

Public CDN
Informational

Edge nodes of CDNs such as Cloudflare, Akamai, Fastly, and AWS CloudFront. Any user visiting a site behind one of these CDNs may resolve to this IP — it does not represent an end user's real IP.

IDC
Medium Risk

IPs of datacenters, VPS, colocation hosting, and cloud servers. Well-suited for running servers, but using them to log into accounts, register new accounts, or make payments is easily flagged by platform risk control as a "non-human user".

Relay IP
Medium Risk

The egress of privacy relays like iCloud Private Relay. Apple devices route through this kind of IP when "Private Relay" is enabled — not technically a proxy, but it does mask the real location.

Tor Exit
High Risk

An exit node of the Tor network (the Tor Project publishes a public list). Platform risk control almost always rejects these outright — using one for business is essentially self-sabotage.

Unknown
Insufficient Data

Signals from multiple data sources conflict or are all missing, making classification impossible. Not necessarily a bad IP — just insufficient evidence to conclude; querying another IP or retrying may clarify it.

Behavioral Signal Badges

Risk markers shown alongside IP type on the IP detail card. A residential IP can, at the same time, carry a behavioral tag such as "Residential Proxy" or "Abuse". Proxy / VPN / Tor Exit / Relay IP are already IP types and are not repeated here.

Residential Proxy

A genuine residential IP sold to a proxy provider as an exit node, common in third-party scraping pools / data-collection networks. The underlying ownership is residential, but the behavior is proxy-like — platform risk control treats it as a proxy egress.

Crawler

Identified as crawler / automated scraping traffic. Common causes include high-frequency requests, missing normal browser fingerprints, and bulk API calls — account registration and login flows will generally be blocked.

Spam

Identified for sending spam email, mass spam comments, or similar abusive behavior. Email delivery and community posting services will typically reject this kind of egress.

Abuse

Reported multiple times in public abuse databases for malicious behavior such as brute-force login attempts, vulnerability scanning, and credential stuffing. Affects this IP's cleanliness grade.

Bogon

IPs from RFC-reserved blocks, private address ranges, or documentation example ranges that should never appear on the public internet. The system blocks these before they're ever written, so they never enter the database or participate in ranking.

6-Dimension Scoring

Each dimension is scored independently from 0-100, weighted and summed, then multiplied by a business-applicability coefficient (highest for residential IPs, lower for IDC) to produce the final total score.

20%
Network Ownership Trust
identity

Whether the IP has a current BGP Origin ASN, whether its registered country matches its actual location, and whether the route is legitimately signed. Reflects how clear this IP's "identity" is.

Starting pointNeutral when ordinary geolocation data is missing; flagged as Unannounced when there is no current BGP Origin ASN / route.
Bonus to 100Matching registration country + legitimate route → full score.
DeductionUnannounced → minor deduction; registered country mismatched with actual location → deduction depending on network type; invalid RPKI / suspected route hijack → significant deduction.
25%
Anonymity Evasion Score
anonymity

Whether the IP behaves as an anonymizing egress — proxy / VPN / Tor / residential proxy / privacy relay. This dimension carries the highest weight and directly determines whether it can be used for genuine-user business.

Starting pointStarts close to a perfect score.
Bonus to 100Multiple independent signals consistently confirming a non-anonymizing egress → full score.
DeductionTor drops straight to zero; residential proxy / commercial VPN / public proxy incur heavy deductions; privacy relay / crawler / high-risk ratings also incur deductions.
20%
Abuse History
abuse

The cumulative intensity of reports in public abuse databases, how recent those reports are, and whether the IP is flagged as high-abuse. Reflects how many victims have historically reported this IP.

Starting pointStarts close to a perfect score, then deducted based on historical abuse intensity.
Bonus to 100Long-term tracking with no new reports recently → boosted to the top.
DeductionNew reports within the last 7 days, a high cumulative report count, or a "high-abuse" flag → significant deduction.
15%
Blacklist / Honeypot
blacklist

The number of hits across public blacklists such as email DNSBLs, HTTP honeypots, and threat intelligence feeds. More hits indicate a historically dirtier IP.

Starting pointStarts close to a perfect score.
Bonus to 100Verified clean across multiple blacklist sources → full score.
DeductionDNSBL hits / honeypot hits / flagged as a compromised device → heavy deductions, with more hits meaning steeper deductions.
10%
Attack Activity
attack

Historical counts of specific attack behaviors such as brute-force login attempts, mass junk registrations, and comment spam. Reflects this IP's record of initiating attacks.

Starting pointStarts close to a perfect score.
Bonus to 100Long-term tracking with zero attack activity → full score.
DeductionExisting attack history is deducted in tiers based on scale, with large-scale attacks dropping straight to zero.
10%
Local Reputation
local

CleanIP's own blacklist/allowlist and threat-event records. IPs that have been reported or blacklisted on-site historically show up in this dimension.

Starting pointStarts close to a perfect score.
Bonus to 100Being on the allowlist grants a full score outright; long-term tracking with no on-site threat events and positive reputation → boosted.
DeductionBeing on the local blacklist drops it straight to zero; threat events within the last 30 days, a high cumulative event count, or negative reputation → significant deduction.

Overall Grade

The weighted sum of the 6 dimensions plus the business-applicability coefficient produces a score from 0-100, displayed as one of the 6 grades below: A+ / A / B / C / D / F. The color bar at the top of the detail card matches this exactly.

A+
95-100
Excellent — almost no negative signals, verified clean across multiple sources
A
85-94
Good — where most residential ISP IPs land
B
70-84
Fair — the default ceiling for hosting / IDC
C
50-69
Average — hits 1-2 anonymity/abuse signals
D
25-49
Poor — multiple high-risk signals stacked, blocked by many platforms
F
0-24
Very Poor — Tor / multiple blacklists / severe abuse

The business-applicability coefficient lets normal networks like residential / mobile / education / government reach close to a perfect score, business networks slightly lower, and datacenter / IDC networks are compressed into a lower range; public infrastructure (DNS / CDN) is treated as informational and excluded from normal scoring. A clean residential IP defaults to the mid-to-high score range — reaching the top A+ requires comprehensive positive evidence such as long-term tracking, verified clean across multiple sources, and inclusion on the local allowlist.

mimetic
mimetic
mimetic