How IP reputation is built
Every request carries an IP address, which makes it the first and cheapest signal a site can check. Reputation services collect facts about addresses from many sources and turn them into categories or scores. Some facts describe what the address is. Others describe what it has done.
The facts about what an address is change slowly and are fairly reliable: registry records say which organization and ASN it belongs to, and whether that network is an internet provider, a mobile carrier or a hosting company. The facts about behavior change quickly: an address sending spam this week may belong to a normal household next month.
- Ownership and type: home broadband, mobile carrier, business, hosting or cloud.
- Anonymizers: known VPN servers, Tor exit relays, open and commercial proxies.
- Abuse history: spam traps, attack reports, blocklists and honeypots.
- Local history: what your own site has seen from that address and its neighbors.
What IP reputation catches, and what it misses
| Traffic source | Caught by IP reputation? | Why |
|---|---|---|
| Bots on cloud servers | Usually | Hosting ranges are well known |
| Tor exit relays | Yes | The exit list is public |
| Commercial VPN servers | Mostly | Server ranges are tracked, though they change |
| Datacenter proxies | Mostly | Owned by hosting networks |
| Residential proxies | Rarely | Exits are real home IPs that rotate constantly |
| Mobile proxies | Rarely | Carrier IPs are shared with real phone users |
| Account takeover from the victim's city | No | The IP looks like any local customer |
Why IP reputation alone is not enough
IP reputation was built for a world where attackers came from servers. That world is gone. Fraud operators now rent clean home and mobile IPs by the gigabyte, rotate them for every request and pick exits in the victim's own city. A reputation list can only flag an address after it has behaved badly somewhere, and a rotating proxy exit may never be used twice for the same target.
The opposite problem matters as much. Mobile carriers and large internet providers put many customers behind a single address. Blocking an address with a bad history can lock out real customers who happen to share it today. And a VPN or datacenter address is normal for remote workers, corporate networks and verified crawlers.
IP reputation vs device reputation
IP reputation
- Available on the very first request
- Shared by everyone behind the address
- Changes when the IP is reassigned
- Easy to escape by switching proxy
Device reputation
- Needs a script or SDK on the device
- Specific to one physical or virtual device
- Follows the device across networks
- Hard to escape without changing hardware
Using IP reputation well
Treat IP reputation as one layer of evidence, keep it fresh, and combine it with what the device and behavior show. Kavra draws on 30+ public reputation feeds and adds its own proxy intelligence, continuously measuring the real exit IPs of commercial residential and mobile proxy networks. That network view is weighed together with device, browser integrity, behavior and account history. See residential and mobile proxy detection and VPN and Tor detection.