All systems operationalโ€ขIP pool status
Coronium Mobile Proxies

Free network diagnostic

Free IP Reputation Check: Public Blocklist Lookup

Check whether a public IPv4 address appears in IPsumโ€™s aggregated threat feed. A match includes the number of source lists reported by that feed and its update time. This is one reputation signal, not a universal fraud score.

Coronium compares the address with a downloaded IPsum feed. The entered address is not sent to the feed provider or contacted. This check covers IPv4 only.

What this IP reputation check measures

IPsum aggregates publicly available lists of suspicious or malicious addresses. Its published feed includes each address and a count of the source lists containing it, and the project says it refreshes the feed daily. This tool reads that count directly; it does not generate a new score.

A count of four means the feed reports four source-list occurrences. The count does not establish four confirmed incidents, independent investigations or a 4% probability of fraud. Related lists may share observations. Read the IP reputation guide before comparing this count with a commercial providerโ€™s risk estimate.

Check the address used by the affected application

Start with the public IPv4 address observed during the failing request. What is my IP checks the path used by this browser; a remote AI agent, scheduled job or container may use a different connection. A lookup after rotation can describe a different address from the one that received the error.

Enter one IPv4 address without a port, hostname or subnet suffix. IPv6 and private or reserved ranges are outside this toolโ€™s accepted input. Use the ASN lookup when the question concerns an IPv6 route or its announcing network.

The address is sent to Coronium, where it is compared with the downloaded feed. The query is not forwarded to IPsum, and the checker never opens a connection to the entered address.

Interpret a match without treating it as a verdict

A match is a reason to investigate the source and the networkโ€™s recent use. It does not identify the subscriber or prove that the current user performed the reported activity. Shared addresses, reassignment and source errors can affect interpretation.

Record the address, count, feed update time and check time. If you control the network, review relevant traffic and abuse reports before changing access rules. If you rent the connection, give the provider the dated result and the original request error.

For a platform restriction, follow the IP-ban diagnosis guide. A platformโ€™s own logs or support response can explain a decision that this public feed cannot see. Changing an address does not resolve an account restriction by itself.

No match, stale data and failed checks are different

A successful search with no matching entry produces โ€œNot found in this IPsum snapshot.โ€ That means only that the checked snapshot lacks the address. It does not mean every blocklist is clear, a website will accept the connection or the address has never been reported.

The checker displays the feedโ€™s own update time separately from the time you ran the check. Upstream responses may be cached for one hour. A missing timestamp, a malformed entry, an empty feed, a timestamp in the future or a snapshot older than 72 hours causes an unavailable result. The implementation allows five minutes of clock skew.

If a request fails, the previous result is cleared. The page does not replace the failure with a zero or a reassuring status. The feed can change after you run a check; retain the timestamp when sharing the result.

Why there is no universal IP fraud score

A fraud score belongs to a named provider, product and model. A public blocklist count uses different evidence from a transaction assessment or a request-level bot score. Converting that count into a percentage would add a claim the source does not support.

This free tool therefore answers a narrower, verifiable question: whether this IPv4 address appears in the selected feed, and what occurrence count the feed reports. It does not query a commercial fraud-scoring API, inspect account standing or classify every address as residential, mobile or datacenter.

For an AI-assisted review, pass the source name, timestamps, match state and exact field meaning together. Ask for a summary of the observation and its limits. Keep access decisions tied to your own evidence and review process rather than an AI-generated risk percentage.

Method and sources

Documentation reviewed October 11, 2026. The result panel identifies the source and time of each check. A failed or incomplete check is not a clean result.

Frequently asked questions

Continue the diagnosis

Interpret reputation and fraud scores

Compare the meaning of the field, source and timestamp.

Find the announcing network

Check IPv4 and IPv6 routing information through RIPEstat.

Diagnose an IP ban

Separate network failures from account and application restrictions.

Instagram open-proxy warning

Investigate the warning using the request and account context.