IP purity report
192.42.116.20
0/ 100
Very high risk
confidence: high
Reputation is burned; almost every platform will block it.
Based on signals observed from public and partner data sources at 2026-09-22 10:23 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.
- Tor exit node
- Proxy exit
Profile
What this IP is
- Country / region
- The Netherlands · North Holland · Amsterdam
- IP type
- Hosting / data center
- Native / broadcast
- Native IP
- Network
- AS215125 TOR Exit and More
- Reverse DNS
- this-is-a-tor-exit-node-hviv120.hviv.nl
- Devices seen in subnet
- 661
Suitability
What it is good for
Each use case weighs the evidence differently; these are not one overall score.
AI services
ChatGPT · Claude · Gemini
Unusable
Main issue: Tor exit node
Least tolerant of data center and proxy exits: more likely to get degraded service, verification prompts or account limits. Spam history does not matter here
Social sign-up
X · Discord · Telegram · Reddit
Unusable
Main issue: Tor exit node
Sign-up is the strictest checkpoint: data center / proxy exits are more likely to be asked for phone verification or refused, and IPs with bulk-registration history are blocked far more often
Streaming / short video
TikTok · Netflix · YouTube
Unusable
Main issue: Tor exit node
Native IP and low sharing matter most: a broadcast IP reads as a region mismatch, and shared exits get throttled
Gaming platforms
Steam · PSN · Epic · Nintendo
Unusable
Main issue: Tor exit node
Region locks, regional pricing and gifting all follow the IP's location, so broadcast IPs tend to be treated as cross-region; data center exits carry a high risk of restrictions
Cross-border e-commerce
Amazon · eBay · Shopee
Unusable
Main issue: Tor exit node
Linked-account store closures are driven first by shared IPs, and only then by data center ranges
Email sending
SMTP · marketing email
Unusable
Main issue: Blocklist hit: Spamhaus ZEN
Blocklists make or break deliverability, while sending from a data center IP is normal and is not penalised
Evidence
Why it got this score
- −90
Tor exit node
Most risk systems reject Tor exit IPs outright
- −50
Abuse reports (abuseipdb)
Confidence 100%, 837 reports in the last 90 days
- −45
Blocklist hit: Spamhaus ZEN
PBL — range judged dynamic by Spamhaus; XBL — compromised host / open proxy; SBL CSS — automatically detected spam source
- −30
Proxy IP
2 data sources flag it as a proxy exit, without identifying the type
- −25
IP type: Hosting / data center
Hosting / data center IPs are the main source of automated traffic
- −20
rDNS looks like a proxy
Reverse hostname this-is-a-tor-exit-node-hviv120.hviv.nl contains proxy/VPN keywords
- −12
Blocklist hit: SpamCop
Listed by SpamCop
- −12
Blocklist hit: UCEPROTECT L1
Listed by UCEPROTECT L1
- −12
Blocklist hit: s5h.net
Listed by s5h.net
- −12
Blocklist hit: SpamRats
Listed by SpamRats
- −6
Attack activity on record
5 events recorded: Login Attempt ×4, Vulnerability Probing ×1
- −6
4 open ports
Open ports: 443, 9001, 9002, 9006
- −6
Heavily shared exit
661 devices observed in the same subnet; higher risk of guilt by association
- −6
rDNS looks like a server
Reverse hostname this-is-a-tor-exit-node-hviv120.hviv.nl matches server naming
- +5
Native IP
Registered and used in the same country, allocated directly by a local carrier
Reputation
Blocklists and abuse history
Listed on 5 of 8 blocklists checked: Spamhaus ZEN, SpamCop, UCEPROTECT L1, s5h.net, SpamRats.
- proxycheck.io 5 attack events recorded
- abuseipdb abuse confidence 100%, 837 reports in 90 days
Open ports observed: 443, 9001, 9002, 9006
Limits
What an IP check cannot tell you
- Each platform's internal risk labels
- Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
- Whether the IP is truly exclusive
- Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
- Which accounts this IP has been tied to
- Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
- Device, browser and behaviour
- Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
- Whether the account profile matches the IP
- When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.
Sources
Data sources and responses
- rdap786ms
- team-cymru94ms
- ip-api.com96ms
- proxycheck.io149ms
- abuseipdb184ms
- cloud-ranges11ms
- tor-exits11ms
- rdns876ms
- shodan-internetdb131ms
- ipwho.is94ms
- dnsbl205ms
Machine-readable versions of this report: JSON · plain text · 中文报告