IPure IP purity check

IP purity report

54.218.183.98

36/ 100

High risk

confidence: high

No blocklist or abuse records, but several traits point to a datacenter / proxy exit; platforms with strict risk controls will most likely ask for extra verification.

Based on signals observed from public and partner data sources at 2026-09-26 17:12 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.

Profile

What this IP is

Country / region
United States · Oregon · Boardman
IP type
Hosting / data center
Native / broadcast
Native IP
Network
AS16509 AWS EC2 (us-west-2)
Reverse DNS
ec2-54-218-183-98.us-west-2.compute.amazonaws.com
Devices seen in subnet
1

Suitability

What it is good for

Each use case weighs the evidence differently; these are not one overall score.

AI services

ChatGPT · Claude · Gemini

0

Best avoided

Main issue: IP type: Hosting / data center

Least tolerant of data center and proxy exits: more likely to get degraded service, verification prompts or account limits. Spam history does not matter here

Social sign-up

X · Discord · Telegram · Reddit

0

Best avoided

Main issue: IP type: Hosting / data center

Sign-up is the strictest checkpoint: data center / proxy exits are more likely to be asked for phone verification or refused, and IPs with bulk-registration history are blocked far more often

Streaming / short video

TikTok · Netflix · YouTube

17

Best avoided

Main issue: Known VPN exit

Native IP and low sharing matter most: a broadcast IP reads as a region mismatch, and shared exits get throttled

Gaming platforms

Steam · PSN · Epic · Nintendo

14

Best avoided

Main issue: IP type: Hosting / data center

Region locks, regional pricing and gifting all follow the IP's location, so broadcast IPs tend to be treated as cross-region; data center exits carry a high risk of restrictions

Cross-border e-commerce

Amazon · eBay · Shopee

17

Best avoided

Main issue: IP type: Hosting / data center

Linked-account store closures are driven first by shared IPs, and only then by data center ranges

Email sending

SMTP · marketing email

52

Borderline

Main issue: Known VPN exit

Blocklists make or break deliverability, while sending from a data center IP is normal and is not penalised

Evidence

Why it got this score

  • −25

    IP type: Hosting / data center

    Hosting / data center IPs are the main source of automated traffic

    What it means
    This IP sits in a hosting / datacenter range. Platforms assume real people browse from home or a phone, and machines live in datacenters.
    Which uses care
    Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
    Why it is weighted this way
    The most basic signal there is: scrapers, bulk sign-ups and fake traffic overwhelmingly come from datacenters, so risk systems discount the whole range. It says nothing about what you did, only that you share the range.
    Can it be fixed
    The range type cannot be changed. What helps is not stacking other issues on top: stay off blocklists, close unneeded ports, avoid crowded exits.
  • −20

    Known VPN exit

    Only 1 data source flags it as a VPN; the evidence is limited, so it counts at half weight

    What it means
    Commercial risk databases mark this address as a VPN server exit. Platforms see "someone on a VPN", not you.
    Which uses care
    Cares most: AI services, Social sign-up, Streaming / short video, Gaming platforms, Cross-border e-commerce
    Why it is weighted this way
    Only one source says so, and a single database can be wrong (public DNS resolvers have been mislabeled), so it counts at half weight. If a second source follows in a few days, this item doubles.
    Can it be fixed
    Self-hosted proxies on VPS ranges are often labeled block-wide; changing the IP is the only fix. Commercial VPN exits are labeled by design.
  • −8

    Cloud provider range (AWS)

    Public cloud IPs can be rented cheaply by anyone, so they rate below self-run data centers

    What it means
    The address falls inside a public cloud provider's published range; anyone can rent a machine in the same range within minutes.
    Which uses care
    Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
    Why it is weighted this way
    A small extra deduction on top of the datacenter one: public cloud has a lower barrier than private hosting and abuse is more concentrated.
    Can it be fixed
    Range membership cannot be changed; different regions of the same cloud, or independent datacenters, are labeled differently.
  • −8

    24 known vulnerabilities

    Mostly matched from software version banners; it shows the machine is unmaintained, and platform risk systems do not look at this directly: CVE-2022-31629, CVE-2021-21704, CVE-2017-9120 and more

    What it means
    Scanners matched the version banners of exposed services to published CVE numbers. Most are just version matches, not confirmed exploitable holes.
    Which uses care
    Barely looks at it: AI services
    Why it is weighted this way
    It shows the machine is unmaintained, another sign of "server"; platform risk systems never count CVEs on an IP. Capped at 8 points (20 before 2026-09-26, which pushed ordinary VPS into "very high risk" for one fact charged three times).
    Can it be fixed
    Update the system and the services exposed to the internet (sshd above all); scanners update within days, then re-check.
  • −6

    2 open ports

    Open ports: 80, 443

    What it means
    Scanners see ports open on this IP. With admin ports such as 22 or 3389 it is almost certainly a server, not a home router.
    Which uses care
    Barely looks at it: AI services
    Why it is weighted this way
    Mainly corroboration that "this is a server", which the datacenter item already charged for, so only a few points here; AI-type scenarios weight it at 0.3 to avoid charging the same fact three times.
    Can it be fixed
    Close or restrict ports that do not need public access (firewall, non-default port, fail2ban); scanners update within days, then re-check. One of the few items you can change yourself.
  • −6

    rDNS looks like a server

    Reverse hostname ec2-54-218-183-98.us-west-2.compute.amazonaws.com matches server naming

    What it means
    The reverse hostname follows server naming (server, vps, host and the like).
    Which uses care
    Cares most: Email sending
    Why it is weighted this way
    A light deduction: one more sign of "this is a server".
    Can it be fixed
    You can change the PTR in the host's panel, but it is only corroboration and barely moves the total.
  • +4

    Very low observed sharing

    Only 1 devices observed in the same subnet

    What it means
    Only a few devices were observed in the same subnet. Your behaviour mostly represents you alone.
    Which uses care
    Cares most: Social sign-up, Streaming / short video, Cross-border e-commerce
    Why it is weighted this way
    A small bonus. This is an observation, not proof of true exclusivity.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
  • +5

    Native IP

    Registered and used in the same country, allocated directly by a local carrier

    What it means
    Registered and used in the same country, allocated directly by a local carrier: a "native IP".
    Which uses care
    Cares most: Streaming / short video, Gaming platforms; Barely looks at it: Email sending
    Why it is weighted this way
    A bonus: region-based checks will not trip.
    Can it be fixed
    An inherent attribute of the IP or its range; nothing a user can change short of a different IP.

Reputation

Blocklists and abuse history

Not listed on any of the 8 blocklists checked (Spamhaus ZEN, SpamCop, PSBL, blocklist.de, UCEPROTECT L1, s5h.net, DroneBL, SpamRats).

  • abuseipdb abuse confidence 0%

Open ports observed: 80, 443

Limits

What an IP check cannot tell you

Each platform's internal risk labels
Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
Whether the IP is truly exclusive
Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
Which accounts this IP has been tied to
Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
Device, browser and behaviour
Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
Whether the account profile matches the IP
When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.

Sources

Data sources and responses

  • rdap
    427ms
  • team-cymru
    53ms
  • ip-api.com
    98ms
  • proxycheck.io
    119ms
  • abuseipdb
    196ms
  • cloud-ranges
    19ms
  • tor-exits
    19ms
  • rdns
    795ms
  • shodan-internetdb
    209ms
  • ipwho.is
    95ms
  • dnsbl
    791ms

Machine-readable versions of this report: JSON · plain text · 中文报告