Fraud and risk scores
IP Risk Score Explained: How Fraud Teams Use It to Stop Bad Actors
What goes into an IP risk score, how fraud teams combine it with geolocation, proxy and blocklist signals, and why the score is evidence rather than a verdict.
- Author
- Mojahid Ul Haque
- Updated
- Reading time
- 6 min read
Quick Answer
An IP risk score is a numeric rating that predicts how likely an IP address is to be involved in fraudulent activity. It combines geolocation consistency, proxy/VPN status, blacklist listings, and abuse history into a single value (often 0-100). Fraud teams use this score in real time to block, challenge, or allow traffic, improving detection while reducing manual review workload.
Key Takeaways
An IP risk score combines multiple signals-geolocation, proxy/VPN status, blacklist reputation, and behavior-to produce a single risk rating.
Fraud teams apply the score in real time to block high-risk traffic, step-up authentication, or trigger manual review.
Common mistakes include relying on a single data source, ignoring score thresholds, and failing to update models as threats evolve.
Crafzo IP Lookup provides a ready-to-use risk score API that can be dropped into existing fraud-prevention stacks.
How It Works
IP risk scoring starts with raw data points collected from various sources. Geolocation services compare the IP’s registered location with the user’s declared location or typical behavior patterns. Proxy and VPN detectors examine network traits, such as known data center ranges, Tor exit nodes, or commercial VPN IP lists. Blacklist feeds provide historical abuse reports, spam trap hits, and records of IPs seen in credential stuffing or carding attacks. Additional signals may include the IP’s autonomous system number (ASN) type, connection speed, and whether the address appears in recent honeypot logs.
Each signal is normalized to a common scale and weighted according to its predictive power. For example, an IP on a recent spam blacklist might receive a high weight, while a residential ISP with clean history gets a low weight. The weighted values are summed and scaled to produce the final score. Many providers update these weights continuously using machine learning models that learn from confirmed fraud and legitimate traffic.
When to Use It
Fraud teams insert IP risk scoring at the earliest possible point in the traffic flow-often at the edge or API gateway-so decisions happen before any application logic runs. Typical use cases include:
Login protection: Block or challenge logins from IPs scoring above a threat threshold, reducing account takeover attempts.
Transaction screening: Flag payments originating from high-risk IPs for additional verification or manual review.
Content abuse prevention: Stop comment spam, fake account creation, or coupon abuse by rejecting submissions from risky addresses.
API security: Rate-limit or block requests from IPs with a history of scraping or credential stuffing.
Because the score is a single number, it integrates easily with existing rules engines, SIEMs, or fraud platforms that already consume IP lookup, geolocation, and blacklist data.
Mistakes to Avoid
Over-reliance on one signal - Using only blacklist status or only VPN detection can miss sophisticated attackers who use clean residential IPs or newly compromised hosts.
Static thresholds - Setting a fixed cutoff (e.g., score > 80) without periodic review can cause drift as fraud tactics evolve; regularly recalibrate based on observed false positive and false negative rates.
Ignoring network sharing - Legitimate users behind CGNAT, corporate proxies, or public Wi-Fi may inherit a high score from a few bad actors; consider combining IP risk with device or session-level signals.
Failing to feed back outcomes - Not logging whether a blocked IP was truly malicious prevents model improvement; maintain a feedback loop to retrain scoring models.
Neglecting latency - Some scoring services add hundreds of milliseconds; choose a low-latency provider or cache results for short periods to keep user experience smooth.
How to Use Crafzo IP Lookup
Crafzo is a manual lookup tool, not an API: there is no key to obtain and no endpoint to call. It fits the parts of a fraud workflow where a person is looking at one address, which is most of them once an automated rule has fired.
Paste the address from the alert, the login event or the chargeback record into the lookup field. IPv4 and IPv6 both work.
Read the risk overview first. The 0-100 score is shown with the provider's own band (low, medium, high, very high) and the time it was checked, so the number in your case notes carries its own context.
Check the signals that explain the score. VPN, proxy, Tor, hosting and blacklist each name the provider that reported them and say "Not reported" when a provider did not return the field, so you can tell a real negative from a gap.
Compare the network with the account. The ISP, organization and ASN tell you whether the address belongs to a consumer carrier, a corporate network or a hosting provider; a residential ISP on a new account and a cloud provider on a checkout deserve different questions.
Copy the report into the case. The Copy report button produces a plain-text record with every field, its source and the lookup time, which is what a reviewer needs later.
For automated, per-request scoring you need a provider's API in your own stack. The score Crafzo displays comes from Scamalytics, which offers an API with a free tier; other options include IPQualityScore, MaxMind minFraud and ipinfo. Whichever you pick, the checklist above still applies: log the score with its band and provider, review the boundary cases by hand, and feed the outcomes back into your thresholds.
Sources
Frequently asked questions
Keep reading
Related guides
- Fraud and risk scores3 min read
IP Fraud Score: What the Numbers Actually Mean
A plain-language guide to reading IP fraud scores — what the 0–100 scale means, what triggers a high score, and how to use it without over-blocking.
Updated
- Fraud and risk scores6 min read
IP Risk Score for Ecommerce
How an IP risk score fits a checkout review: pairing the score with address mismatch, proxy and hosting signals so fake orders are caught without blocking real buyers.
Updated
- Fraud and risk scores7 min read
Reduce Fake Signups With IP Risk Signals
Use IP reputation, velocity, proxy detection, and location context to reduce fake accounts without hurting good users.
Updated
- IP lookup essentials8 min read
Residential Proxy Detection for Login Risk: How to Spot and Block Suspicious IPs
Residential proxies make attack traffic look like home users. The signals that still give them away, and how to use them in login risk decisions without false positives.
Updated