IP reputation analysis with an explainable score
Check whether an IP is listed on blacklists, is a Tor node, its country and ASN. The 0-100 score shows which signals weigh and why.
What you get
Multiple DNSBLs
We query several recognized public blacklists and aggregate the result in two signals (single/multi) with different weights.
Tor exit nodes
Tor exit node detection updated from official datasets.
Reverse DNS + FCrDNS
PTR and forward-confirmed validation: "no_fcrdns" signal if the loop does not close (typical of abuse infrastructure).
ASN and organization
Autonomous system number + network operator name. Useful to distinguish cheap hosting from residential ISP.
Country and geo
Country resolved from local dataset, with declared source for auditing.
CGNAT
We identify the shared 100.64.0.0/10 space used by many mobile carriers — many users behind the same IP.
Explainable score
Each signal shows its points; score is not a black box that blindly blocks.
IPv4 and IPv6
Both versions supported, with correct IPv6 normalization.
How it works
Normalization and classification
We validate IPv4/IPv6 format and classify scope. If private, reserved or non-routable, we stop before querying anything external and do not charge.
Reputation lookup
We run parallel lookups against public DNSBLs (with 15-minute cache to avoid abuse) and against the Tor exit nodes dataset.
Network and DNS
We resolve reverse DNS, validate FCrDNS and obtain ASN + organization from local datasets. Country with declared source.
Score and signals
We aggregate weights per signal and return a 0-100 score, a bucket (low/medium/high/critical) and the list of signals with their individual weights.
In code
cURLcurl -X POST https://api.byebouncer.com/api/v1/verify-ip \ -H "Authorization: Bearer $BYEBOUNCER_API_KEY" \ -H "Content-Type: application/json" \ -d '{"ip":"8.8.8.8"}'
Node / TypeScriptimport { ByeBouncer } from '@bye_bouncer/sdk'; const bb = new ByeBouncer({ apiKey: process.env.BYEBOUNCER_API_KEY! }); const result = await bb.verifyIP('8.8.8.8'); if (result.risk === 'high' || result.risk === 'critical') blockSignup();
Frequently asked questions
Which blacklists do you query?
A set of recognized public DNSBLs. If an IP appears in several lists (signal "dnsbl_multi") risk is much higher than appearing in one only (signal "dnsbl_single", which may be a false positive).
How does the 0-100 score work?
We start at 0 (clean) and add weights per detected signal. 0-19 = low, 20-49 medium, 50-79 high, 80-100 critical. Each signal shows how many points it contributes so the score is not a black box.
Do you detect anonymous traffic (Tor, VPN)?
We detect Tor exit nodes with signal "tor_exit". Commercial VPNs are hard to identify generically; use ASN and organization as a hint.
Do you charge for private IPs?
No. Private IPs (RFC 1918), reserved, loopback, link-local, CGNAT and broadcast are marked as "invalid_scope" and do not consume credits.
What information do you return?
Score 0-100, risk (low/medium/high/critical), network (ASN, organization, country, reverse DNS, FCrDNS valid or not), reputation (listed on DNSBLs, Tor node), and signals explaining the score.
How long is reputation data cached?
DNSBL results are cached up to 15 minutes to avoid overloading public lists. If an IP just left a blacklist it may take a few minutes to update. ASN and country data are local and updated periodically.
Can I block by IP alone?
We recommend using IP as one signal, not as the sole reason. A shared VPN may have 10,000 legitimate users and some abusive ones: cross with email, phone and behavior for better signal.
Is there IP bulk?
Not publicly today. If you have a use case contact hello@byebouncer.com and we will evaluate.
Try it with 500 free credits
No credit card. Start using the API as soon as you sign up.
Create account