IP purity report
64.253.120.178
91/ 100
Clean
confidence: high
Good reputation; at the IP level it rarely draws extra verification.
Based on signals observed from public and partner data sources at 2026-09-29 06:26 UTC. This describes IP-level risk only; platforms' internal risk data is not visible to us.
- Proxy exit
Profile
What this IP is
- Country / region
- United States · Kentucky · Louisville
- IP type
- Residential
- Native / broadcast
- Native IP
- Network
- AS4364 IgLou Internet Services
- Reverse DNS
- a120-178.iglou.com
- Devices seen in subnet
- 4
Suitability
What it is good for
Each use case weighs the evidence differently; these are not one overall score.
AI services
ChatGPT · Claude · Gemini
Excellent fit
No notable obstacle found for this use case
Least tolerant of data center and proxy exits: more likely to get degraded service, verification prompts or account limits. Spam history does not matter here
Social sign-up
X · Discord · Telegram · Reddit
Excellent fit
No notable obstacle found for this use case
Sign-up is the strictest checkpoint: data center / proxy exits are more likely to be asked for phone verification or refused, and IPs with bulk-registration history are blocked far more often
Streaming / short video
TikTok · Netflix · YouTube
Excellent fit
No notable obstacle found for this use case
Native IP and low sharing matter most: a broadcast IP reads as a region mismatch, and shared exits get throttled
Gaming platforms
Steam · PSN · Epic · Nintendo
Excellent fit
No notable obstacle found for this use case
Region locks, regional pricing and gifting all follow the IP's location, so broadcast IPs tend to be treated as cross-region; data center exits carry a high risk of restrictions
Cross-border e-commerce
Amazon · eBay · Shopee
Excellent fit
No notable obstacle found for this use case
Linked-account store closures are driven first by shared IPs, and only then by data center ranges
Email sending
SMTP · marketing email
Excellent fit
No notable obstacle found for this use case
Blocklists make or break deliverability, while sending from a data center IP is normal and is not penalised
Evidence
Why it got this score
- −15
Proxy IP
Only 1 data source flags it as a proxy; the evidence is limited, so it counts at half weight
- What it means
- A source marks this address as a proxy exit without saying whether it is a VPN, a datacenter proxy or something else.
- Which uses care
- Cares most: AI services, Social sign-up, Streaming / short video, Gaming platforms, Cross-border e-commerce
- Why it is weighted this way
- Only one source says so, so it counts at half weight.
- Can it be fixed
- These labels are usually applied to whole ranges and are hard to clear by behaviour; moving to an unlabeled range is the practical fix.
- −6
8 open ports
Open ports: 1701, 10000, 10001, 10004, 11000, 12000, 12500, 12502
- What it means
- Scanners see ports open on this IP. With admin ports such as 22 or 3389 it is almost certainly a server, not a home router.
- Which uses care
- Barely looks at it: AI services
- Why it is weighted this way
- Mainly corroboration that "this is a server", which the datacenter item already charged for, so only a few points here; AI-type scenarios weight it at 0.3 to avoid charging the same fact three times.
- Can it be fixed
- Close or restrict ports that do not need public access (firewall, non-default port, fail2ban); scanners update within days, then re-check. One of the few items you can change yourself.
- −5
7 known vulnerabilities
Mostly matched from software version banners; it shows the machine is unmaintained, and platform risk systems do not look at this directly: CVE-2025-62168, CVE-2026-50012, CVE-2026-32748 and more
- What it means
- Scanners matched the version banners of exposed services to published CVE numbers. Most are just version matches, not confirmed exploitable holes.
- Which uses care
- Barely looks at it: AI services
- Why it is weighted this way
- It shows the machine is unmaintained, another sign of "server"; platform risk systems never count CVEs on an IP. Capped at 8 points (20 before 2026-09-26, which pushed ordinary VPS into "very high risk" for one fact charged three times).
- Can it be fixed
- Update the system and the services exposed to the internet (sshd above all); scanners update within days, then re-check.
- +4
Very low observed sharing
Only 4 devices observed in the same subnet
- What it means
- Only a few devices were observed in the same subnet. Your behaviour mostly represents you alone.
- Which uses care
- Cares most: Social sign-up, Streaming / short video, Cross-border e-commerce
- Why it is weighted this way
- A small bonus. This is an observation, not proof of true exclusivity.
- Can it be fixed
- An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
- +5
Native IP
Registered and used in the same country, allocated directly by a local carrier
- What it means
- Registered and used in the same country, allocated directly by a local carrier: a "native IP".
- Which uses care
- Cares most: Streaming / short video, Gaming platforms; Barely looks at it: Email sending
- Why it is weighted this way
- A bonus: region-based checks will not trip.
- Can it be fixed
- An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
- +8
IP type: Residential
Residential broadband is the IP type risk systems trust most
- What it means
- A residential, mobile, education or government network address: the kind of source risk systems trust most.
- Which uses care
- Cares most: AI services, Social sign-up, Gaming platforms, Cross-border e-commerce; Barely looks at it: Email sending
- Why it is weighted this way
- A bonus: the vast majority of real people come from these networks, so the default stance is to let them through.
- Can it be fixed
- An inherent attribute of the IP or its range; nothing a user can change short of a different IP.
Reputation
Blocklists and abuse history
Not listed on any of the 8 blocklists checked (Spamhaus ZEN, SpamCop, PSBL, blocklist.de, UCEPROTECT L1, s5h.net, DroneBL, SpamRats).
- abuseipdb abuse confidence 0%
Open ports observed: 1701, 10000, 10001, 10004, 11000, 12000, 12500, 12502
Limits
What an IP check cannot tell you
- Each platform's internal risk labels
- Platforms keep their own IP reputation data and ban records and do not publish them. No hit in public sources does not mean a platform has nothing on this IP.
- Whether the IP is truly exclusive
- Sharing is only the number of devices observed in the same subnet. It cannot show who else is using this exit right now, or what they are doing.
- Which accounts this IP has been tied to
- Account-to-IP links exist only inside each platform. Accounts previously banned on this IP are invisible to us.
- Device, browser and behaviour
- Risk systems look at IP + device fingerprint + behavioural rhythm together. A clean IP with an odd fingerprint or behaviour still gets blocked.
- Whether the account profile matches the IP
- When sign-up country, phone number, payment method, language or time zone disagree with the IP's location, platforms verify further. That is unrelated to IP purity.
Sources
Data sources and responses
- rdap242ms
- team-cymru70ms
- ip-api.com68ms
- proxycheck.io141ms
- abuseipdb199ms
- cloud-ranges9ms
- tor-exits9ms
- rdns563ms
- shodan-internetdb160ms
- ipwho.is73ms
- dnsbl247ms
Machine-readable versions of this report: JSON · plain text · 中文报告