A fraud score is the number a website is really reacting to when it challenges a sign-up, holds a payment, or blocks a request before you have done anything. It compresses everything a site can look up about your address into one figure, and a high one means friction no matter how legitimate your intent is. We run FFraud, an IP-intelligence engine that produces exactly this kind of score, so this explains what the number is built from, what counts as a good one, and why a clean proxy can read near zero while a cheap one reads as a threat.
What is an IP fraud score?
An IP fraud score is a single risk rating, usually from 0 to 100, that a fraud-intelligence engine assigns to an address by combining the signals a website cares about: whether the address is a known proxy or VPN exit, whether it belongs to a hosting provider or a consumer ISP, how many unrelated accounts and services it has touched, and its abuse history. Higher means riskier on the common scale, so a low score is the goal.
What the number is built from
A score is not one measurement. It is several, rolled together, and knowing the inputs tells you how to move the number.
- Proxy and VPN classification. The engine checks the address against lists of known proxy, VPN, and Tor exits. Being on one is one of the heaviest upward pushes there is, because it tells a site the visitor is deliberately hiding their real location.
- Network type. A hosting or datacenter ASN scores high by default, since no ordinary person browses from a server. A consumer ISP range starts low. This is the same first gate we describe in how websites detect proxies, expressed as a number.
- Abuse and reputation history. Addresses reported for attacks, spam, or scraping carry that record. One address that many unrelated services have complained about scores higher than a quiet one, even without a formal blocklist entry.
- Recent activity and sharing. An address that has touched many unrelated accounts in a short window looks like shared or automated infrastructure, which reads as risk. This is why a heavily shared free proxy scores badly within days.
What counts as a good score
On the usual 0 to 100 scale where higher is riskier, lower is always better and the ideal is near zero. As a rough reading of that scale:
| Score range | How a site tends to read it |
|---|---|
| 0 to 25 | Low risk, usually passes without friction |
| 25 to 50 | Moderate, may see a soft check on sensitive actions |
| 50 to 75 | Raised, challenges and holds become common |
| 75 to 90 | High risk, frequently blocked or sent to manual review |
| 90 to 100 | Treated as fraud, blocked outright |
The exact thresholds are set by each site, not by the scoring engine, so the same address can pass a lenient sign-up and fail a bank. Read the direction of the scale before you trust a number, too, because a few tools invert it and use a high figure to mean high trust rather than high risk. What stays constant is the goal: an address that reads like an ordinary person, which is a low score on a risk scale.
Why a clean proxy reads near zero and a cheap one does not
This is the part that decides which proxy to buy. A proxy does not carry a fixed score, it inherits the score of the specific exit address it routes you through, so the type and the cleanliness of that exit are everything.
A datacenter proxy exits through a hosting range, so it starts high on network type alone, and if it is a shared or recycled address it also carries whatever the last user did. That is why a bargain proxy so often lands you on a flagged exit: you are sharing a heavily used hosting address that already reads as risk. A clean residential exit inverts every input. It belongs to a real consumer ISP, so the network type is right. It is not on a proxy list if the pool is maintained, so the classification is clean. And if the pool is scored and rotated rather than sold and forgotten, its reputation stays low. Add those up and the exit reads like what it is, a home connection, which is a score near zero. This is the same reason a clean IP passes the first gate while a dirty one fails it, seen through the single number a site actually stores.
How to read your own score before a site does
You can check the exact figure a site will see, which means you never have to find out the hard way.
- Run the exit through FFraud to see the fraud score and the signals behind it. IPQualityScore and Scamalytics offer comparable lookups if you want a second reading.
- Run the same address through our proxy checker to confirm the network and country a site reads, since a hosting classification is the fastest way an address earns a high score.
- Check before you commit real work to an exit, not after. A high score returned in a lookup is a problem you can still avoid. The same score returned by a payment processor is a declined transaction.
What a low score does not buy you
A near-zero fraud score clears the reputation and network question, which is the one most sites weigh first, but it is one signal and not a pass on everything. A site can still read your TLS fingerprint, your headers, and your behavior, so a clean address behind an automation tool that fires requests on a metronome still gets caught by the layers a score does not cover. A good score removes the reason most addresses get flagged. It does not remove the need to behave like a real visitor. Anyone selling a proxy as a guaranteed zero everywhere is selling the number, not the result.
When the job needs an exit that reads clean, our residential proxies route through real consumer ISPs and are scored by FFraud, so they start where you want the number to be, and they cost $0.44/GB pay-as-you-go with a balance that does not expire. Read any exit with the proxy checker and FFraud first, and buy the address that already reads low, because that reading is the only one a site acts on.
Sources
- IPQualityScore, "Fraud Scoring and how it works": the 0 to 100 risk scale and the proxy, VPN, and abuse signals behind it.
- DataDome, "What are data center proxies and how to detect them?": why hosting ASNs score as risk while ISP ranges do not.
- Cloudflare, "Machine learning to detect bot attacks that use residential proxies": how sites weigh residential reputation against known-proxy classification.