IP purity report
153.67.85.49
15/ 100
Very high risk
confidence: high
Reputation is burned; almost every platform will block it.
Based on signals observed from public and partner data sources at 2026-10-09 14:49 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.
- Proxy exit
Profile
What this IP is
- Country / region
- Madagascar · Analamanga Region · Antananarivo
- IP type
- Residential
- Native / broadcast
- Broadcast IP
- Network
- AS14593 SpaceX Starlink
- Reverse DNS
- customer.jhngzaf1.isp.starlink.com
- Devices seen in subnet
- 202
Suitability
What it is good for
Each use case weighs the evidence differently; these are not one overall score.
AI services
ChatGPT · Claude · Gemini
Borderline
Main issue: Proxy IP
Least tolerant of data center and proxy exits: more likely to get degraded service, verification prompts or account limits. Spam history does not matter here
Social sign-up
X · Discord · Telegram · Reddit
Not recommended
Main issue: Proxy IP
Sign-up is the strictest checkpoint: data center / proxy exits are more likely to be asked for phone verification or refused, and IPs with bulk-registration history are blocked far more often
Streaming / short video
TikTok · Netflix · YouTube
Not recommended
Main issue: Broadcast IP
Native IP and low sharing matter most: a broadcast IP reads as a region mismatch, and shared exits get throttled
Gaming platforms
Steam · PSN · Epic · Nintendo
Not recommended
Main issue: Proxy IP
Region locks, regional pricing and gifting all follow the IP's location, so broadcast IPs tend to be treated as cross-region; data center exits carry a high risk of restrictions
Cross-border e-commerce
Amazon · eBay · Shopee
Not recommended
Main issue: Blocklist hit: Spamhaus ZEN
Linked-account store closures are driven first by shared IPs, and only then by data center ranges
Email sending
SMTP · marketing email
Best avoided
Main issue: Blocklist hit: Spamhaus ZEN
Blocklists make or break deliverability, while sending from a data center IP is normal and is not penalised
Evidence
Why it got this score
- −45
Blocklist hit: Spamhaus ZEN
PBL — range judged dynamic by Spamhaus; XBL — compromised host / open proxy
- What it means
- A Spamhaus listing means this IP was confirmed sending spam, or the machine is compromised and being used as a relay.
- Which uses care
- Cares most: Email sending; Barely looks at it: AI services, Social sign-up, Streaming / short video, Gaming platforms
- Why it is weighted this way
- This is behavioural evidence, not a profile guess, so it is a hard cap and fatal for email. It carries little weight for scenarios that ignore mail reputation, such as AI services.
- Can it be fixed
- Fix the cause first (shut down the compromised service, remove malware), then request removal from Spamhaus; usually resolved within days.
- −15
Proxy IP
Only 1 data source flags it as a proxy; the evidence is limited, so it counts at half weight
- What it means
- A source marks this address as a proxy exit without saying whether it is a VPN, a datacenter proxy or something else.
- Which uses care
- Cares most: AI services, Social sign-up, Streaming / short video, Gaming platforms, Cross-border e-commerce
- Why it is weighted this way
- Only one source says so, so it counts at half weight.
- Can it be fixed
- These labels are usually applied to whole ranges and are hard to clear by behaviour; moving to an unlabeled range is the practical fix.
- −15
Broadcast IP
Range registered in US but used in MG (announced across borders)
- What it means
- The country the range is registered in differs from where it is actually used. Common when an international host uses a range registered in country A inside country B, or when a proxy vendor leases ranges.
- Which uses care
- Cares most: Streaming / short video, Gaming platforms; Barely looks at it: Email sending
- Why it is weighted this way
- Region-sensitive platforms (streaming, region-locked gaming) care most: they cross-check several geo databases and treat a mismatch as "wrong region". Little effect on scenarios that ignore region.
- Can it be fixed
- This is a registration attribute of the range and cannot be changed by the user. Platforms use different geo databases, so some may not notice at all.
- −12
Blocklist hit: s5h.net
Listed by s5h.net
- What it means
- This IP is on a public blocklist. Most lists record addresses that sent spam or took part in scanning or attacks.
- Which uses care
- Cares most: Email sending; Barely looks at it: AI services, Social sign-up, Streaming / short video, Gaming platforms
- Why it is weighted this way
- A single aggregate list is moderate evidence, so about a dozen points; the email scenario more than doubles it because receiving servers query these lists directly.
- Can it be fixed
- Every list has a removal process, provided the cause is gone; some delist automatically after a quiet period.
- −9
Abuse reports (abuseipdb)
Confidence 17%, 7 reports in the last 90 days
- What it means
- Someone reported this IP to an abuse database (AbuseIPDB), typically for SSH brute force, port scanning or comment spam. The reporter may have seen a program on this machine, or a previous tenant.
- Which uses care
- Cares most: Social sign-up, Email sending
- Why it is weighted this way
- Counted at half the database's confidence. Sign-up scenarios care most: IPs with bulk-registration or credential-stuffing history are their first priority to block.
- Can it be fixed
- Reports age out; with no new reports for 90 days the score drops. If your machine is the one scanning, check for implanted software first.
- −6
Heavily shared exit
202 devices observed in the same subnet; higher risk of guilt by association
- What it means
- Many devices share this exit. Whatever others do on it gets attributed to you as well.
- Which uses care
- Cares most: Social sign-up, Streaming / short video, Cross-border e-commerce
- Why it is weighted this way
- Cross-border e-commerce and social sign-up care most: shared IPs are the leading cause of linked-account bans.
- Can it be fixed
- Move to a dedicated or low-share exit; sharing levels vary widely between plans from the same vendor.
- +3
No open ports
Network scans have not observed any open service on this IP
- What it means
- Network scanners have not observed any open service on this IP.
- Which uses care
- Barely looks at it: AI services
- Why it is weighted this way
- A small bonus: a small attack surface means fewer chances of ending up in scanner and abuse databases. Not evidence of home broadband; a well-firewalled server looks the same.
- Can it be fixed
- An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
- +6
rDNS looks residential
Reverse hostname customer.jhngzaf1.isp.starlink.com matches residential broadband naming
- What it means
- The reverse hostname follows residential naming (prefixes like dyn, pppoe, cust).
- Which uses care
- Cares most: Email sending
- Why it is weighted this way
- A bonus: the carrier's naming indirectly confirms an access network.
- Can it be fixed
- An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
- +8
IP type: Residential
Residential broadband is the IP type risk systems trust most
- What it means
- A residential, mobile, education or government network address: the kind of source risk systems trust most.
- Which uses care
- Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
- Why it is weighted this way
- A bonus: the vast majority of real people come from these networks, so the default stance is to let them through.
- Can it be fixed
- An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
Reputation
Blocklists and abuse history
Listed on 2 of 8 blocklists checked: Spamhaus ZEN, s5h.net.
- abuseipdb abuse confidence 17%, 7 reports in 90 days
Limits
What an IP check cannot tell you
- Each platform's internal risk labels
- Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
- Whether the IP is truly exclusive
- Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
- Which accounts this IP has been tied to
- Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
- Device, browser and behaviour
- Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
- Whether the account profile matches the IP
- When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.
Sources
Data sources and responses
- rdap443ms
- team-cymru64ms
- ip-api.com98ms
- proxycheck.io126ms
- abuseipdb301ms
- cloud-ranges7ms
- tor-exits7ms
- rdns1330ms
- shodan-internetdb181ms
- dnsbl327ms
Machine-readable versions of this report: JSON · plain text · 中文报告