Fraud and risk scores
IP Fraud Score: What the Numbers Actually Mean
A plain-language guide to reading IP fraud scores — what the 0–100 scale means, what triggers a high score, and how to use it without over-blocking.
- Author
- Mojahid Ul Haque
- Updated
- Reading time
- 3 min read
Reading the score bands
Crafzo shows the Scamalytics band next to the score, and the bands are the provider's documented ones: 0-19 low, 20-59 medium, 60-89 high, 90-100 very high. The score comes from Scamalytics, which describes it as the approximate share of users seen from that address who were linked to fraudulent activity: a score of 70 means roughly 7 in 10. Crafzo shows the provider's band with the score (0-19 low, 20-59 medium, 60-89 high, 90-100 very high). The band is a triage signal, not a verified probability for your traffic, and the provider recommends adjusting thresholds to your own fraud data.
Other providers cut their 0-100 scales differently, so a 30 from one service and a 30 from another are not the same statement. Always read a score together with the provider that produced it.
A low score does not prove a user is safe, and a high score does not prove a user is malicious. It is a triage signal that should change how much verification or review you apply.
Signals that raise risk
Proxy and VPN usage, data center ownership, recent abuse history, blacklist appearances, unusual country changes, and high request velocity can all push a score upward. Some systems also weigh bot behavior, disposable infrastructure, and known credential attack patterns.
Legitimate users can inherit risk from shared networks, mobile gateways, public Wi-Fi, or a reused IP that previously belonged to someone else. That is why fraud scores work best with account history and behavior logs.
How to act on scores
Use low scores for normal flow, medium scores for logging or light friction, and high scores for step-up verification, rate limits, or manual review. Hard blocks should be reserved for strong score plus strong behavior evidence.
Crafzo helps make scores readable by showing the IP context next to location and network signals. That broader view reduces the risk of over-blocking good users.
Frequently asked questions
Keep reading
Related guides
- Fraud and risk scores6 min read
IP Risk Score Explained: How Fraud Teams Use It to Stop Bad Actors
What goes into an IP risk score, how fraud teams combine it with geolocation, proxy and blocklist signals, and why the score is evidence rather than a verdict.
Updated
- Fraud and risk scores6 min read
IP Risk Score for Ecommerce
How an IP risk score fits a checkout review: pairing the score with address mismatch, proxy and hosting signals so fake orders are caught without blocking real buyers.
Updated
- IP lookup essentials4 min read
Web Scraping Without Getting Blocked: Understanding IP Trust Scores
Why sites score the IPs that hit them, which signals (datacenter ranges, blocklists, bot scores) trigger blocks, and how to keep a legitimate crawler's addresses clean.
Updated
- Fraud and risk scores9 min read
What Does It Mean When Your IP Is Blacklisted?
What an IP blocklist listing means for your email and web traffic, why addresses get listed, how to check your reputation, and how delisting works.
Updated