IPure IP purity check

IP purity report

2a03:2880:f814:29::

61/ 100

Suspicious

confidence: high

Mediocre reputation; not recommended for long-term use with important accounts.

Based on signals observed from public and partner data sources at 2026-10-01 01:52 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.

Profile

What this IP is

Country / region
United States · New York · New York
IP type
Hosting / data center
Native / broadcast
Broadcast IP
Network
AS32934 Facebook, Inc
Reverse DNS
none
Devices seen in subnet
no data

Suitability

What it is good for

Each use case weighs the evidence differently; these are not one overall score.

Per-use-case suitability does not apply

This is an official address of a well-known public service, not a network exit that users can browse from, so there is nothing to log in or sign up from. The purity score only describes its network reputation.

Evidence

Why it got this score

  • −25

    IP type: Hosting / data center

    Hosting / data center IPs are the main source of automated traffic

    What it means
    This IP sits in a hosting / datacenter range. Platforms assume real people browse from home or a phone, and machines live in datacenters.
    Which uses care
    Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
    Why it is weighted this way
    The most basic signal there is: scrapers, bulk sign-ups and fake traffic overwhelmingly come from datacenters, so risk systems discount the whole range. It says nothing about what you did, only that you share the range.
    Can it be fixed
    The range type cannot be changed. What helps is not stacking other issues on top: stay off blocklists, close unneeded ports, avoid crowded exits.
  • −15

    Broadcast IP

    Range registered in IE but used in US (announced across borders)

    What it means
    The country the range is registered in differs from where it is actually used. Common when an international host uses a range registered in country A inside country B, or when a proxy vendor leases ranges.
    Which uses care
    Cares most: Streaming / short video, Gaming platforms; Barely looks at it: Email sending
    Why it is weighted this way
    Region-sensitive platforms (streaming, region-locked gaming) care most: they cross-check several geo databases and treat a mismatch as "wrong region". Little effect on scenarios that ignore region.
    Can it be fixed
    This is a registration attribute of the range and cannot be changed by the user. Platforms use different geo databases, so some may not notice at all.
  • −12

    Blocklist hit: DroneBL

    Listed by DroneBL

    What it means
    This IP is on a public blocklist. Most lists record addresses that sent spam or took part in scanning or attacks.
    Which uses care
    Cares most: Email sending; Barely looks at it: AI services, Social sign-up, Streaming / short video, Gaming platforms
    Why it is weighted this way
    A single aggregate list is moderate evidence, so about a dozen points; the email scenario more than doubles it because receiving servers query these lists directly.
    Can it be fixed
    Every list has a removal process, provided the cause is gone; some delist automatically after a quiet period.
  • −5

    No rDNS record

    No PTR record; IPs allocated by established carriers usually have one

    What it means
    This IP has no reverse hostname (PTR record). Addresses allocated by established carriers usually have one.
    Which uses care
    Cares most: Email sending
    Why it is weighted this way
    A few points only: a missing PTR is a weak "unknown origin" signal, not a stain. Email cares more, since receiving servers check it.
    Can it be fixed
    Most hosts let you set a PTR in the control panel; set it to a sensible hostname.
  • +3

    No open ports

    Network scans have not observed any open service on this IP

    What it means
    Network scanners have not observed any open service on this IP.
    Which uses care
    Barely looks at it: AI services
    Why it is weighted this way
    A small bonus: a small attack surface means fewer chances of ending up in scanner and abuse databases. Not evidence of home broadband; a well-firewalled server looks the same.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
  • +15

    Whitelisted IP

    Listed as an official address of a well-known service or crawler

    What it means
    This address is listed as the official IP of a well-known service or search engine.
    Which uses care
    All six uses treat it about the same, at the same weight as the overall score.
    Why it is weighted this way
    A bonus, and it also means this is nobody's egress, so scenario assessment does not apply.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.

Reputation

Blocklists and abuse history

Listed on 1 of 3 blocklists checked: DroneBL.

  • abuseipdb abuse confidence 0%, 53 reports in 90 days

Limits

What an IP check cannot tell you

Each platform's internal risk labels
Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
Whether the IP is truly exclusive
Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
Which accounts this IP has been tied to
Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
Device, browser and behaviour
Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
Whether the account profile matches the IP
When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.

Sources

Data sources and responses

  • rdap
    421ms
  • team-cymru
    125ms
  • ip-api.com
    69ms
  • proxycheck.io
    144ms
  • abuseipdb
    228ms
  • cloud-ranges
    10ms
  • tor-exits
    10ms
  • rdns
    1122ms
  • shodan-internetdb
    211ms
  • dnsbl
    200ms

Machine-readable versions of this report: JSON · plain text · 中文报告