IPure IP purity check

IP purity report

1.162.28.153

57/ 100

Suspicious

confidence: high

Mediocre reputation; not recommended for long-term use with important accounts.

Based on signals observed from public and partner data sources at 2026-09-26 14:01 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.

Profile

What this IP is

Country / region
Taiwan · Taipei City · Taipei
IP type
Residential
Native / broadcast
Native IP
Network
AS3462 Chunghwa Telecom Co. Ltd.
Reverse DNS
1-162-28-153.dynamic-ip.hinet.net
Devices seen in subnet
43

Suitability

What it is good for

Each use case weighs the evidence differently; these are not one overall score.

AI services

ChatGPT · Claude · Gemini

56

Borderline

Main issue: Abuse reports (abuseipdb)

Least tolerant of data center and proxy exits: more likely to get degraded service, verification prompts or account limits. Spam history does not matter here

Social sign-up

X · Discord · Telegram · Reddit

16

Best avoided

Main issue: Abuse reports (abuseipdb)

Sign-up is the strictest checkpoint: data center / proxy exits are more likely to be asked for phone verification or refused, and IPs with bulk-registration history are blocked far more often

Streaming / short video

TikTok · Netflix · YouTube

50

Borderline

Main issue: Abuse reports (abuseipdb)

Native IP and low sharing matter most: a broadcast IP reads as a region mismatch, and shared exits get throttled

Gaming platforms

Steam · PSN · Epic · Nintendo

60

Borderline

Main issue: Abuse reports (abuseipdb)

Region locks, regional pricing and gifting all follow the IP's location, so broadcast IPs tend to be treated as cross-region; data center exits carry a high risk of restrictions

Cross-border e-commerce

Amazon · eBay · Shopee

40

Not recommended

Main issue: Abuse reports (abuseipdb)

Linked-account store closures are driven first by shared IPs, and only then by data center ranges

Email sending

SMTP · marketing email

24

Best avoided

Main issue: Abuse reports (abuseipdb)

Blocklists make or break deliverability, while sending from a data center IP is normal and is not penalised

Evidence

Why it got this score

  • −41

    Abuse reports (abuseipdb)

    Confidence 82%, 23 reports in the last 90 days

    What it means
    Someone reported this IP to an abuse database (AbuseIPDB), typically for SSH brute force, port scanning or comment spam. The reporter may have seen a program on this machine, or a previous tenant.
    Which uses care
    Cares most: Social sign-up, Email sending
    Why it is weighted this way
    Counted at half the database's confidence. Sign-up scenarios care most: IPs with bulk-registration or credential-stuffing history are their first priority to block.
    Can it be fixed
    Reports age out; with no new reports for 90 days the score drops. If your machine is the one scanning, check for implanted software first.
  • −15

    Proxy IP

    Only 1 data source flags it as a proxy; the evidence is limited, so it counts at half weight

    What it means
    A source marks this address as a proxy exit without saying whether it is a VPN, a datacenter proxy or something else.
    Which uses care
    Cares most: AI services, Social sign-up, Streaming / short video, Gaming platforms, Cross-border e-commerce
    Why it is weighted this way
    Only one source says so, so it counts at half weight.
    Can it be fixed
    These labels are usually applied to whole ranges and are hard to clear by behaviour; moving to an unlabeled range is the practical fix.
  • −6

    Attack activity on record

    5 events recorded: Login Attempt ×5

    What it means
    A commercial risk database recorded attacks from this IP: credential stuffing, bulk registration, comment spam and the like.
    Which uses care
    Cares most: Social sign-up, Email sending
    Why it is weighted this way
    Tiered by count rather than linear: 1 and 8 are about the same (someone used it), hundreds are a different story. The cap is kept low because the same record already feeds that vendor's overall score.
    Can it be fixed
    Same as abuse reports: stop the source and the record fades with time.
  • −6

    1 open ports

    Open ports: 10026

    What it means
    Scanners see ports open on this IP. With admin ports such as 22 or 3389 it is almost certainly a server, not a home router.
    Which uses care
    Barely looks at it: AI services
    Why it is weighted this way
    Mainly corroboration that "this is a server", which the datacenter item already charged for, so only a few points here; AI-type scenarios weight it at 0.3 to avoid charging the same fact three times.
    Can it be fixed
    Close or restrict ports that do not need public access (firewall, non-default port, fail2ban); scanners update within days, then re-check. One of the few items you can change yourself.
  • +5

    Native IP

    Registered and used in the same country, allocated directly by a local carrier

    What it means
    Registered and used in the same country, allocated directly by a local carrier: a "native IP".
    Which uses care
    Cares most: Streaming / short video, Gaming platforms; Barely looks at it: Email sending
    Why it is weighted this way
    A bonus: region-based checks will not trip.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
  • +6

    Spamhaus ZEN: residential range declaration

    PBL — range judged dynamic by Spamhaus

    What it means
    Spamhaus PBL declares this range as dynamic residential space that should not send mail directly. Not a stain: it is evidence of home broadband.
    Which uses care
    Cares most: Email sending; Barely looks at it: AI services, Social sign-up, Streaming / short video, Gaming platforms
    Why it is weighted this way
    Counted as a bonus because it indirectly confirms a real access network.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
  • +6

    rDNS looks residential

    Reverse hostname 1-162-28-153.dynamic-ip.hinet.net matches residential broadband naming

    What it means
    The reverse hostname follows residential naming (prefixes like dyn, pppoe, cust).
    Which uses care
    Cares most: Email sending
    Why it is weighted this way
    A bonus: the carrier's naming indirectly confirms an access network.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
  • +8

    IP type: Residential

    Residential broadband is the IP type risk systems trust most

    What it means
    A residential, mobile, education or government network address: the kind of source risk systems trust most.
    Which uses care
    Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
    Why it is weighted this way
    A bonus: the vast majority of real people come from these networks, so the default stance is to let them through.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.

Reputation

Blocklists and abuse history

Not listed on any of the 7 blocklists checked (Spamhaus ZEN, SpamCop, PSBL, blocklist.de, UCEPROTECT L1, s5h.net, DroneBL, SpamRats). 1 list(s) could not be queried this time.

  • proxycheck.io 5 attack events recorded
  • abuseipdb abuse confidence 82%, 23 reports in 90 days

Open ports observed: 10026

Limits

What an IP check cannot tell you

Each platform's internal risk labels
Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
Whether the IP is truly exclusive
Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
Which accounts this IP has been tied to
Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
Device, browser and behaviour
Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
Whether the account profile matches the IP
When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.

Sources

Data sources and responses

  • rdap
    353ms
  • team-cymru
    36ms
  • ip-api.com
    77ms
  • proxycheck.io
    168ms
  • abuseipdb
    166ms
  • cloud-ranges
    16ms
  • tor-exits
    16ms
  • rdns
    1067ms
  • shodan-internetdb
    193ms
  • ipwho.is
    73ms
  • dnsbl
    1060ms

Machine-readable versions of this report: JSON · plain text · 中文报告