Free tool

IP checker

Paste any IPv4 address to see its geolocation, the network behind it, and whether it is a proxy, VPN, Tor exit or datacenter address. Your own address is filled in to start with. Free, no signup, nothing stored.

Rate limited, no key required. Results appear inline.

What the check looks at

Datacenter and hosting, matched against 44,000 cloud and hosting CIDR ranges. Proxy and VPN flags from live IP intelligence. Tor exit nodes, against the public exit list, refreshed regularly.

Plus the descriptive half: geolocation (country, region, city, timezone and coordinates), the ISP, ASN and organisation behind the address, and the reverse hostname, which is often the giveaway on a hosting range nobody has catalogued yet.

The four flags are not equally interesting

Datacenter or hosting is the strongest of the four. Nobody lives in an AWS range. A signup from one was started by a machine somebody rented, and while there are honest reasons for that (a corporate proxy, or a VPN endpoint the customer runs themselves), it has the best ratio of signal to noise of anything here.

Commercial VPN is the one people over-weight badly. Millions of ordinary people run one, and remote workers sit behind corporate tunnels all day. Blocking it costs you real users at a rate that is easy to underestimate, because the ones you turn away do not complain. They leave, and they never appear in your numbers.

Tor means someone deliberately anonymised themselves. Worth a review, not a rejection. Journalists and the merely cautious use it too.

Residential proxyis the one built specifically to defeat all of the above: real consumer traffic, routed through somebody’s home connection, often without their knowledge. It is the hardest to catch and the most likely to be genuinely malicious, because almost nobody ends up on one by accident.

Why the ASN beats the country

Country tells you where an address is registered. The ASN tells you what kind of network it is, and that is the more useful fact almost every time.

A residential address in a market you do not sell to is usually a customer on holiday. A hosting-provider address is someone running accounts at scale, and that stays true whichever country it happens to be registered in. Geo-blocking a country turns away real people to catch a pattern that simply moves next door. ASN classification catches the pattern itself.

The stronger version is first-party: track which ASNs have produced abuse in your own historyand weigh accordingly. A network that is 80% fraud for you is worth more than any vendor’s global reputation score, because it is measured on your traffic and your definition of abuse.

What an IP cannot tell you

It cannot tell you how many people are behind it. Carrier-grade NAT puts thousands of mobile users on one address; an office or a university puts hundreds on another. Any rule of the form “more than N accounts from one IP is fraud” will eventually ban a school.

It cannot tell you who someone is. Addresses rotate, and a residential one can change between two visits by the same person on the same evening. That is the gap device identity exists to close: the IP describes the route, the device describes the visitor.

And geolocation is looser than the city field suggests. It is accurate to the country almost always and to the city often enough to be useful, but it is inferred from registry and routing data rather than measured, so treating a city mismatch as proof of anything will cost you.

Checking it at signup

The check above is one endpoint of the Kaidn API:

POST /v1/check/ip
curl -X POST https://api.kaidn.io/v1/check/ip \
  -H "x-api-key: $KAIDN_API_KEY" \
  -H "content-type: application/json" \
  -d '{"ip":"203.0.113.42"}'

# {
#   "ip": {
#     "fraud_score": 90,
#     "is_datacenter": true,
#     "is_proxy": true,
#     "is_vpn": true,
#     "vpn_provider": "NordVPN",
#     "is_tor": false,
#     "asn": "9009",
#     "isp": "M247 Europe SRL",
#     "country_code": "US"
#   },
#   "summary": "203.0.113.42 is a NordVPN exit, a datacenter/hosting address (M247 Europe SRL) — not a typical residential user (Ashburn, United States) — fraud score 90/100."
# }

Or send it through POST /v1/score alongside the email and the device, and get one verdict with the reasons behind it. That is the version worth building, because no single one of these flags should decide anything on its own.

Frequently asked questions

Frequently asked questions

Is this IP checker free?

Free, no signup. Paste an IPv4 address and read the result. Nothing about the lookup is stored against you or the address.

What is the difference between a proxy, a VPN and a datacenter IP?

A datacenter IP belongs to a hosting provider, so nobody lives there and traffic from it was started by a machine someone rented. A commercial VPN is a consumer product that millions of ordinary people run for privacy. A residential proxy is traffic routed through someone else's home connection, often without their knowledge, and it is the one built specifically to look legitimate.

Should I block VPN traffic?

Almost never outright. A commercial VPN is used by privacy-conscious customers, remote workers on a corporate tunnel and anyone on hotel wifi. Blocking it costs you real users at a rate that is easy to underestimate, because the ones you turn away never complain, they just leave.

Why does the ASN matter more than the country?

Because the country tells you where an address is registered and the ASN tells you what kind of network it is. A residential address in a market you do not sell to is a customer travelling. A hosting-provider address is someone running accounts at scale, and that is true whichever country it is registered in.

Does a Tor exit node mean fraud?

It means the person deliberately anonymised themselves, which is enough to review but not to convict alone. Journalists, activists and the merely cautious use Tor. What makes it damning is Tor plus a disposable inbox plus a device already tied to other accounts, not Tor by itself.

Can I tell how many people are behind one IP address?

Not from the address alone, and this is where IP-only rules go wrong. Carrier-grade NAT puts thousands of mobile users behind one address, and an office or a university puts hundreds behind another. An IP is a rough location and a network type, not a person, which is why device identity does the work an IP cannot.

Is IPv6 supported?

This tool takes IPv4. The scoring API accepts both, but the free lookup is IPv4 only for now.

How do I check IPs at signup automatically?

Call POST /v1/check/ip from your server for the single lookup, or POST /v1/score to weigh the address alongside the email and the device and get one verdict back with the reasons behind it.

Related

Run this on every signup

The check above is one endpoint. The same engine scores a whole event, the address, the connection and the device together, and returns one verdict with the reasons behind it.