Glossary

Detection & reputation

Fraud score

A single number that fraud-detection services assign to an IP address to summarise how risky traffic from it looks.

A fraud score compresses everything a risk service knows about an address into one figure, is it a proxy or VPN, what is its network, does it carry a history of abuse, how does its behaviour read, so that a site can act on a single threshold instead of weighing signals itself. It is IP reputation packaged for an instant yes-or-no.

Checkout and signup flows lean on it heavily. A high score can silently add friction, an extra verification, a declined payment, a shadow-ban, without ever telling the visitor a score was the reason, which makes it one of the least visible ways an address shapes what you can do.

Because the score keys largely on network type and history, it rewards the same things every other detection layer does: a genuine residential or mobile address, a clean record, behaviour that does not stand out. It is less a separate obstacle than the same reputation, read through a different lens.

What makes it distinctly frustrating is that there is no single authoritative number. Every risk vendor computes its own from its own data with its own weighting, and every site chooses its own threshold and its own vendor. So one service can rate an address low-risk while another rates the same address high, and both are internally consistent. The score you can look up is not necessarily the score that refused you.

The consequences are also deliberately quiet, which is the part worth preparing for. A high score rarely produces an error message. It produces an extra verification step, a payment declined with a generic reason, a signup that appears to succeed and never activates, or a limit applied without explanation. From the outside it looks like something went wrong rather than like a judgement was made.

One structural unfairness deserves naming: simply BEING identified as a proxy or VPN raises the score on most systems, regardless of behaviour. That is a classification, not evidence of wrongdoing, and it is applied to everyone using a commercial exit including people with entirely ordinary privacy reasons. It is also why residential and mobile addresses score better, since they are harder to classify as commercial infrastructure in the first place.

Frequently asked questions

How do I check my IP's fraud score?

Several risk vendors expose a public lookup that returns their score plus the factors behind it. Treat the result as one opinion rather than the answer: each vendor computes its own from its own data, thresholds vary by site, and many sites use a vendor you cannot query. It is useful for spotting an obviously bad address, not for predicting a specific site's decision.

Why was my payment declined through a proxy?

Payment flows lean heavily on risk scoring, and being identified as a proxy or VPN raises the score on most systems by itself. A mismatch between the IP's country and the card's issuing country compounds it. Declines are deliberately vague about the reason, so you will rarely be told this was the cause, and using a proxy for payments is generally a bad idea for exactly this reason.

Can I lower my fraud score?

Not directly, since you do not control the vendors or their data. What you can control is which address you present: a genuine residential or mobile IP with no abuse history starts much lower than a datacenter address on a range known for hosting. Beyond that, scores weight recent behaviour, so an address used cleanly over time improves on its own.

Do all sites use fraud scores?

No. They are concentrated where money and identity are at stake: checkout, signup, account recovery, anything involving payment. A content site collecting no personal data has little reason to buy risk scoring. That is why the same address can browse freely on one site and be blocked at another's checkout.

Back to the full glossary.

HProxy.

Ready when you are.Your dashboard is ten seconds away.

Get Startedor talk to us at support@hproxy.com
HProxy