IPure IP purity check

IP purity report

206.237.115.11

18/ 100

Very high risk

confidence: high

Reputation is burned; almost every platform will block it.

Based on signals observed from public and partner data sources at 2026-09-25 10:17 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.

Profile

What this IP is

Country / region
Hong Kong · Kowloon · Hong Kong
IP type
Business broadband
Native / broadcast
Broadcast IP
Network
AS400618 Prime Security Corp
Reverse DNS
none
Devices seen in subnet
6

Suitability

What it is good for

Each use case weighs the evidence differently; these are not one overall score.

AI services

ChatGPT · Claude · Gemini

—

Region not supported

ChatGPT / Claude / Gemini are not offered in this region and it cannot connect directly; a clean IP in a supported region is needed

Least tolerant of data center and proxy exits: more likely to get degraded service, verification prompts or account limits. Spam history does not matter here

Social sign-up

X · Discord · Telegram · Reddit

55

Borderline

Main issue: Blocklist hit: Spamhaus ZEN

Sign-up is the strictest checkpoint: data center / proxy exits are more likely to be asked for phone verification or refused, and IPs with bulk-registration history are blocked far more often

Streaming / short video

TikTok · Netflix · YouTube

42

Not recommended

Main issue: Broadcast IP

Native IP and low sharing matter most: a broadcast IP reads as a region mismatch, and shared exits get throttled

Gaming platforms

Steam · PSN · Epic · Nintendo

47

Not recommended

Main issue: Broadcast IP

Region locks, regional pricing and gifting all follow the IP's location, so broadcast IPs tend to be treated as cross-region; data center exits carry a high risk of restrictions

Cross-border e-commerce

Amazon · eBay · Shopee

45

Not recommended

Main issue: Blocklist hit: Spamhaus ZEN

Linked-account store closures are driven first by shared IPs, and only then by data center ranges

Email sending

SMTP · marketing email

0

Best avoided

Main issue: Blocklist hit: Spamhaus ZEN

Blocklists make or break deliverability, while sending from a data center IP is normal and is not penalised

Evidence

Why it got this score

  • −45

    Blocklist hit: Spamhaus ZEN

    SBL CSS — automatically detected spam source; XBL — compromised host / open proxy

    What it means
    A Spamhaus listing means this IP was confirmed sending spam, or the machine is compromised and being used as a relay.
    Which uses care
    Cares most: Email sending; Barely looks at it: AI services, Social sign-up, Streaming / short video, Gaming platforms
    Why it is weighted this way
    This is behavioural evidence, not a profile guess, so it is a hard cap and fatal for email. It carries little weight for scenarios that ignore mail reputation, such as AI services.
    Can it be fixed
    Fix the cause first (shut down the compromised service, remove malware), then request removal from Spamhaus; usually resolved within days.
  • −15

    Broadcast IP

    Range registered in US but used in HK (announced across borders)

    What it means
    The country the range is registered in differs from where it is actually used. Common when an international host uses a range registered in country A inside country B, or when a proxy vendor leases ranges.
    Which uses care
    Cares most: Streaming / short video, Gaming platforms; Barely looks at it: Email sending
    Why it is weighted this way
    Region-sensitive platforms (streaming, region-locked gaming) care most: they cross-check several geo databases and treat a mismatch as "wrong region". Little effect on scenarios that ignore region.
    Can it be fixed
    This is a registration attribute of the range and cannot be changed by the user. Platforms use different geo databases, so some may not notice at all.
  • −10

    1 open ports

    Includes admin ports 22: clear evidence of a server rather than home broadband

    What it means
    Scanners see ports open on this IP. With admin ports such as 22 or 3389 it is almost certainly a server, not a home router.
    Which uses care
    Barely looks at it: AI services
    Why it is weighted this way
    Mainly corroboration that "this is a server", which the datacenter item already charged for, so only a few points here; AI-type scenarios weight it at 0.3 to avoid charging the same fact three times.
    Can it be fixed
    Close or restrict ports that do not need public access (firewall, non-default port, fail2ban); scanners update within days, then re-check. One of the few items you can change yourself.
  • −8

    Abuse reports (abuseipdb)

    Confidence 15%, 2 reports in the last 90 days

    What it means
    Someone reported this IP to an abuse database (AbuseIPDB), typically for SSH brute force, port scanning or comment spam. The reporter may have seen a program on this machine, or a previous tenant.
    Which uses care
    Cares most: Social sign-up, Email sending
    Why it is weighted this way
    Counted at half the database's confidence. Sign-up scenarios care most: IPs with bulk-registration or credential-stuffing history are their first priority to block.
    Can it be fixed
    Reports age out; with no new reports for 90 days the score drops. If your machine is the one scanning, check for implanted software first.
  • −5

    No rDNS record

    No PTR record; IPs allocated by established carriers usually have one

    What it means
    This IP has no reverse hostname (PTR record). Addresses allocated by established carriers usually have one.
    Which uses care
    Cares most: Email sending
    Why it is weighted this way
    A few points only: a missing PTR is a weak "unknown origin" signal, not a stain. Email cares more, since receiving servers check it.
    Can it be fixed
    Most hosts let you set a PTR in the control panel; set it to a sensible hostname.
  • −3

    IP type: Business broadband

    Business broadband is broadly trusted, though a small share are proxy exits

    What it means
    A business broadband address: generally trusted, though some corporate exits are used as proxies.
    Which uses care
    Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
    Why it is weighted this way
    A small deduction meaning "slightly less certain than residential".
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
  • +4

    Very low observed sharing

    Only 6 devices observed in the same subnet

    What it means
    Only a few devices were observed in the same subnet. Your behaviour mostly represents you alone.
    Which uses care
    Cares most: Social sign-up, Streaming / short video, Cross-border e-commerce
    Why it is weighted this way
    A small bonus. This is an observation, not proof of true exclusivity.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.

Reputation

Blocklists and abuse history

Listed on 1 of 8 blocklists checked: Spamhaus ZEN.

  • abuseipdb abuse confidence 15%, 2 reports in 90 days

Open ports observed: 22

Limits

What an IP check cannot tell you

Each platform's internal risk labels
Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
Whether the IP is truly exclusive
Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
Which accounts this IP has been tied to
Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
Device, browser and behaviour
Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
Whether the account profile matches the IP
When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.

Sources

Data sources and responses

  • rdap
    89ms
  • team-cymru
    7ms
  • ip-api.com
    32ms
  • proxycheck.io
    59ms
  • abuseipdb
    88ms
  • cloud-ranges
    4ms
  • tor-exits
    4ms
  • rdns
    7ms
  • shodan-internetdb
    27ms
  • ipwho.is
    26ms
  • dnsbl
    225ms

Machine-readable versions of this report: JSON · plain text · 中文报告