IP purity report
16.76.121.32
40/ 100
High risk
confidence: high
Most platforms will add verification or block outright; consider replacing it.
Based on signals observed from public and partner data sources at 2026-09-30 14:15 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.
- VPN exit
- Cloud provider: AWS
Profile
What this IP is
- Country / region
- Japan · Tokyo · Tokyo
- IP type
- Business broadband
- Native / broadcast
- Broadcast IP
- Network
- AS16509 AWS EC2 (ap-northeast-1)
- Reverse DNS
- ec2-16-76-121-32.ap-northeast-1.compute.amazonaws.com
- Devices seen in subnet
- no data
Suitability
What it is good for
Each use case weighs the evidence differently; these are not one overall score.
AI services
ChatGPT · Claude · Gemini
Best avoided
Main issue: Known VPN exit
Least tolerant of data center and proxy exits: more likely to get degraded service, verification prompts or account limits. Spam history does not matter here
Social sign-up
X · Discord · Telegram · Reddit
Best avoided
Main issue: Known VPN exit
Sign-up is the strictest checkpoint: data center / proxy exits are more likely to be asked for phone verification or refused, and IPs with bulk-registration history are blocked far more often
Streaming / short video
TikTok · Netflix · YouTube
Best avoided
Main issue: Known VPN exit
Native IP and low sharing matter most: a broadcast IP reads as a region mismatch, and shared exits get throttled
Gaming platforms
Steam · PSN · Epic · Nintendo
Best avoided
Main issue: Known VPN exit
Region locks, regional pricing and gifting all follow the IP's location, so broadcast IPs tend to be treated as cross-region; data center exits carry a high risk of restrictions
Cross-border e-commerce
Amazon · eBay · Shopee
Not recommended
Main issue: Known VPN exit
Linked-account store closures are driven first by shared IPs, and only then by data center ranges
Email sending
SMTP · marketing email
Borderline
Main issue: Known VPN exit
Blocklists make or break deliverability, while sending from a data center IP is normal and is not penalised
Evidence
Why it got this score
- −20
Known VPN exit
Only 1 data source flags it as a VPN; the evidence is limited, so it counts at half weight
- What it means
- Commercial risk databases mark this address as a VPN server exit. Platforms see "someone on a VPN", not you.
- Which uses care
- Cares most: AI services, Social sign-up, Streaming / short video, Gaming platforms, Cross-border e-commerce
- Why it is weighted this way
- Only one source says so, and a single database can be wrong (public DNS resolvers have been mislabeled), so it counts at half weight. If a second source follows in a few days, this item doubles.
- Can it be fixed
- Self-hosted proxies on VPS ranges are often labeled block-wide; changing the IP is the only fix. Commercial VPN exits are labeled by design.
- −15
Broadcast IP
Range registered in US but used in JP (announced across borders)
- What it means
- The country the range is registered in differs from where it is actually used. Common when an international host uses a range registered in country A inside country B, or when a proxy vendor leases ranges.
- Which uses care
- Cares most: Streaming / short video, Gaming platforms; Barely looks at it: Email sending
- Why it is weighted this way
- Region-sensitive platforms (streaming, region-locked gaming) care most: they cross-check several geo databases and treat a mismatch as "wrong region". Little effect on scenarios that ignore region.
- Can it be fixed
- This is a registration attribute of the range and cannot be changed by the user. Platforms use different geo databases, so some may not notice at all.
- −8
Cloud provider range (AWS)
Public cloud IPs can be rented cheaply by anyone, so they rate below self-run data centers
- What it means
- The address falls inside a public cloud provider's published range; anyone can rent a machine in the same range within minutes.
- Which uses care
- Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
- Why it is weighted this way
- A small extra deduction on top of the datacenter one: public cloud has a lower barrier than private hosting and abuse is more concentrated.
- Can it be fixed
- Range membership cannot be changed; different regions of the same cloud, or independent datacenters, are labeled differently.
- −6
1 open ports
Open ports: 443
- What it means
- Scanners see ports open on this IP. With admin ports such as 22 or 3389 it is almost certainly a server, not a home router.
- Which uses care
- Barely looks at it: AI services
- Why it is weighted this way
- Mainly corroboration that "this is a server", which the datacenter item already charged for, so only a few points here; AI-type scenarios weight it at 0.3 to avoid charging the same fact three times.
- Can it be fixed
- Close or restrict ports that do not need public access (firewall, non-default port, fail2ban); scanners update within days, then re-check. One of the few items you can change yourself.
- −6
rDNS looks like a server
Reverse hostname ec2-16-76-121-32.ap-northeast-1.compute.amazonaws.com matches server naming
- What it means
- The reverse hostname follows server naming (server, vps, host and the like).
- Which uses care
- Cares most: Email sending
- Why it is weighted this way
- A light deduction: one more sign of "this is a server".
- Can it be fixed
- You can change the PTR in the host's panel, but it is only corroboration and barely moves the total.
- −3
IP type: Business broadband
Business broadband is broadly trusted, though a small share are proxy exits
- What it means
- A business broadband address: generally trusted, though some corporate exits are used as proxies.
- Which uses care
- Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
- Why it is weighted this way
- A small deduction meaning "slightly less certain than residential".
- Can it be fixed
- An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
- −2
Abuse reports (abuseipdb)
Confidence 4%, 2 reports in the last 90 days
- What it means
- Someone reported this IP to an abuse database (AbuseIPDB), typically for SSH brute force, port scanning or comment spam. The reporter may have seen a program on this machine, or a previous tenant.
- Which uses care
- Cares most: Social sign-up, Email sending
- Why it is weighted this way
- Counted at half the database's confidence. Sign-up scenarios care most: IPs with bulk-registration or credential-stuffing history are their first priority to block.
- Can it be fixed
- Reports age out; with no new reports for 90 days the score drops. If your machine is the one scanning, check for implanted software first.
Reputation
Blocklists and abuse history
Not listed on any of the 8 blocklists checked (Spamhaus ZEN, SpamCop, PSBL, blocklist.de, UCEPROTECT L1, s5h.net, DroneBL, SpamRats).
- abuseipdb abuse confidence 4%, 2 reports in 90 days
Open ports observed: 443
Limits
What an IP check cannot tell you
- Each platform's internal risk labels
- Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
- Whether the IP is truly exclusive
- Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
- Which accounts this IP has been tied to
- Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
- Device, browser and behaviour
- Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
- Whether the account profile matches the IP
- When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.
Sources
Data sources and responses
- rdap454ms
- team-cymru28ms
- ip-api.com66ms
- proxycheck.io93ms
- abuseipdb229ms
- cloud-ranges5ms
- tor-exits5ms
- rdns491ms
- shodan-internetdb179ms
- dnsbl207ms
Machine-readable versions of this report: JSON · plain text · 中文报告