ByeBouncer
IP · 1 credit per request

IP reputation analysis with an explainable score

Check whether an IP is listed on blacklists, is a Tor node, its country and ASN. The 0-100 score shows which signals weigh and why.

Start free1 credit per public IP · free on private, reserved and CGNAT

What you get

Multiple DNSBLs

We query several recognized public blacklists and aggregate the result in two signals (single/multi) with different weights.

Tor exit nodes

Tor exit node detection updated from official datasets.

Reverse DNS + FCrDNS

PTR and forward-confirmed validation: "no_fcrdns" signal if the loop does not close (typical of abuse infrastructure).

ASN and organization

Autonomous system number + network operator name. Useful to distinguish cheap hosting from residential ISP.

Country and geo

Country resolved from local dataset, with declared source for auditing.

CGNAT

We identify the shared 100.64.0.0/10 space used by many mobile carriers — many users behind the same IP.

Explainable score

Each signal shows its points; score is not a black box that blindly blocks.

IPv4 and IPv6

Both versions supported, with correct IPv6 normalization.

How it works

1

Normalization and classification

We validate IPv4/IPv6 format and classify scope. If private, reserved or non-routable, we stop before querying anything external and do not charge.

2

Reputation lookup

We run parallel lookups against public DNSBLs (with 15-minute cache to avoid abuse) and against the Tor exit nodes dataset.

3

Network and DNS

We resolve reverse DNS, validate FCrDNS and obtain ASN + organization from local datasets. Country with declared source.

4

Score and signals

We aggregate weights per signal and return a 0-100 score, a bucket (low/medium/high/critical) and the list of signals with their individual weights.

In code

cURL
curl -X POST https://api.byebouncer.com/api/v1/verify-ip \ -H "Authorization: Bearer $BYEBOUNCER_API_KEY" \ -H "Content-Type: application/json" \ -d '{"ip":"8.8.8.8"}'
Node / TypeScript
import { ByeBouncer } from '@bye_bouncer/sdk'; const bb = new ByeBouncer({ apiKey: process.env.BYEBOUNCER_API_KEY! }); const result = await bb.verifyIP('8.8.8.8'); if (result.risk === 'high' || result.risk === 'critical') blockSignup();

Frequently asked questions

Which blacklists do you query?

A set of recognized public DNSBLs. If an IP appears in several lists (signal "dnsbl_multi") risk is much higher than appearing in one only (signal "dnsbl_single", which may be a false positive).

How does the 0-100 score work?

We start at 0 (clean) and add weights per detected signal. 0-19 = low, 20-49 medium, 50-79 high, 80-100 critical. Each signal shows how many points it contributes so the score is not a black box.

Do you detect anonymous traffic (Tor, VPN)?

We detect Tor exit nodes with signal "tor_exit". Commercial VPNs are hard to identify generically; use ASN and organization as a hint.

Do you charge for private IPs?

No. Private IPs (RFC 1918), reserved, loopback, link-local, CGNAT and broadcast are marked as "invalid_scope" and do not consume credits.

What information do you return?

Score 0-100, risk (low/medium/high/critical), network (ASN, organization, country, reverse DNS, FCrDNS valid or not), reputation (listed on DNSBLs, Tor node), and signals explaining the score.

How long is reputation data cached?

DNSBL results are cached up to 15 minutes to avoid overloading public lists. If an IP just left a blacklist it may take a few minutes to update. ASN and country data are local and updated periodically.

Can I block by IP alone?

We recommend using IP as one signal, not as the sole reason. A shared VPN may have 10,000 legitimate users and some abusive ones: cross with email, phone and behavior for better signal.

Is there IP bulk?

Not publicly today. If you have a use case contact hello@byebouncer.com and we will evaluate.

Try it with 500 free credits

No credit card. Start using the API as soon as you sign up.

Create account