Best IP checking tools in 2026: reputation, fraud and history, compared

Search for the best IP checking tool and you get a dozen lists that rank a dozen products against each other as if they did the same job. They do not. Almost all of them answer one question, what is this address right now, and a few answer a different one, what has this address been. Which tool is best depends entirely on which of those you are asking. Here is the 2026 field sorted that way, our own tool included and clearly labelled as ours.

Most IP tools give a strong current score but keep no dated history; one sits in the upper region that does both keeps history strong now
Every dot is a tool, placed by how strong its current signal is (rightward) and whether it keeps dated history (upward). Most cluster lower right: a confident answer about now, nothing about before. The upper region, current signal plus a dated record, is nearly empty, and it is the gap this whole piece is about.

First decide which question you are asking

Three questions send people looking for an IP tool, and they want different products.

  • Is this session risky right now? A signup, a checkout, a login. You want a real-time fraud score or a proxy and VPN verdict, in milliseconds. This is the crowded, well-served part of the market.
  • What is this address, factually? Its geolocation, its ASN, its connection type. Data and enrichment, not a judgement.
  • What has this range been? Who held it before, how its routing changed, and what feeds said about it on the dates they looked, before you bought or leased it. This is the sparsest part of the market, and the reason this site exists.

Pick the wrong family and the best product in it is still the wrong tool. A superb real-time fraud score cannot tell you what a range was doing last spring, and a perfect routing archive will not screen a checkout. So the sections below are grouped by question, not ranked into one false league table.

A disclosure before the list

subnethistory is our own tool, so treat our praise of it with the scepticism that deserves. We have tried to earn it: every other tool below is described by what it genuinely does well and where it is limited, we take no referral or placement fees from any of them, and we claim a first place for our own tool on exactly one narrow axis, dated history, while saying plainly where the others beat us. Facts and free tiers were checked against each vendor's own documentation in August 2026 and change often; verify current terms before you commit.

Reputation and fraud scorers

These answer "is this risky now". Most return a continuously recomputed score or a set of current flags, and most do not expose when an address became what it is.

  • IPQualityScore is the default real-time fraud API: proxy, VPN, Tor and bot detection plus a 0 to 100 fraud score, where it documents scores at or above 75 as suspicious and higher still as abusive. Its strength is a proprietary honeypot network feeding the score; its limit is that the score is an opaque point-in-time estimate. New accounts get 1,000 free lookups.
  • Scamalytics returns a 0 to 100 fraud score bucketed into low, medium and high, with proxy, VPN and Tor detection, via a free web checker, an API or a self-hosted database file. The free API tier is around 5,000 lookups a month. Strong, widely used, and, like the others here, current-state only.
  • Spur is the specialist in anonymity attribution, monitoring a very large set of residential-proxy and VPN services and returning 20-plus transparent attributes about the infrastructure behind an address rather than a single opaque number. Best in class for "which proxy network is this", and an enterprise, paid product; a free single-address lookup exists on its site.
  • IPinfo is primarily a geolocation and enrichment provider whose privacy-detection add-on flags VPN, proxy, Tor, relay and hosting, updated daily. It has a genuinely free country-level tier with unlimited requests; the privacy detection and residential-proxy flags are paid. Best when you mainly want accurate location and ASN data with detection as a bonus.
  • MaxMind minFraud scores whole transactions across a large cross-merchant network and, given an IP, returns a real-time risk score. MaxMind itself distinguishes that live score from a separate seven-day "IP risk snapshot", which is the closest thing in this group to a short history window. Pay as you go, with a free trial allowance.
  • AbuseIPDB is the useful outlier: a community database whose 0 to 100 confidence score is built from dated, categorised abuse reports you can actually read, with a report history and time decay. Free tier of 1,000 checks a day. It is an abuse record rather than a proxy detector, and its reports are crowdsourced and subjective, but it shows its evidence and its dates, which most of this list does not.
  • ipapi.is returns geolocation, ASN, company, hosting, VPN, proxy and Tor detection and an abuser flag, and is refreshingly honest about its limits: it states openly that its proxy flag covers only a subset and that it cannot reliably catch residential and mobile proxies. Free tier around 1,000 requests a day with an account. (Full disclosure: it is one of the feeds subnethistory itself samples.)
  • IP2Location and its IP2Proxy database are the long-established self-hosted option: downloadable files you query offline, covering geolocation and proxy types including public, VPN, Tor and residential. Free API tier of 50,000 geolocation queries a month. Database-driven flags that need regular updates rather than a live behavioural score.
  • Criminal IP pairs reputation scoring with attack-surface and port-scan intelligence, giving separate inbound and outbound risk across five levels alongside proxy, VPN and Tor detection. Useful when you want threat-surface context, not just a verdict; its free allowance is not clearly published.
  • APIVoid, and the free IPVoid web checker built on it, aggregate dozens of blocklists and DNSBLs (80-plus by its own count) into one call with a risk score and proxy, VPN and Tor flags. Best for a fast blocklist-consensus read; it surfaces third-party lists rather than proprietary attribution.

Routing and ownership history tools

These answer "what has this been". They are excellent at the parts of history they cover, routing and registration, and mostly silent on the part that decides a purchase, dated reputation.

  • RIPEstat is the free workhorse of routing history: its data calls return prefix announcement history and origin ASNs from the RIPE routing collectors, which have been archiving BGP since around 1999, plus versioned registry history for RIPE-region objects and reconstructed allocation history. If you want the routing past of a prefix, start here. It does not give you a reputation timeline.
  • bgp.tools is the modern BGP explorer most operators now reach for, especially since the widely used bgpview.io shut down in November 2025. It has a free non-commercial tier, and a paid feature added in 2024 lets you travel back to previous snapshots of its database to see how a prefix grew. Routing and structure, not reputation.
  • Hurricane Electric's BGP Toolkit is the free, no-signup standby for whois, IRR and prefix and adjacency history views. Its per-prefix propagation graphs cover a rolling recent window rather than a deep archive, but for a quick look at a network it is hard to beat.
  • Team Cymru, PeeringDB and Spamhaus each hold a slice. Team Cymru's enterprise platform offers around 90 days of historical telemetry; PeeringDB has no built-in history, though CAIDA archives daily snapshots back to 2010; and Spamhaus's commercial intelligence API can return listing history, but capped at a 12-month window and gated to subscribers. All real, all partial, and none a free per-address reputation timeline.

Where subnethistory fits, and where it does not

Here is the disclosed part. Across the tools above, we could not find a free one that keeps a dated, accumulating reputation record for an arbitrary address. Routing and registration history are well served; reputation history is either current-only, a short rolling window, enterprise-gated, or absent. That specific gap is what subnethistory was built to fill, and it is the one axis on which we will claim first place.

A single lookup merges registration, routing and ownership history, the origin ASNs a prefix has had over time, and per-address reputation sampled from independent feeds, including some named above, into one report where every fact carries its source and its date. Because each reading is archived, the record accumulates: a range that was quiet in March and flagged in July shows both, and a proxy we confirmed ourselves and later found switched off is marked as lapsed with the date we last saw it, rather than quietly reverting to clean. When feeds disagree, the report says contested instead of picking a winner. It is free, and it has an open API.

Now the honest limits, because a review that only flatters its own product is not one. subnethistory is not a real-time fraud engine for every address on earth: it samples addresses inside a block rather than scoring all of them, so for high-volume per-session screening at a checkout, a dedicated API like IPQualityScore, Spur or MaxMind is the right tool and we are not pretending otherwise. Its per-address feeds are a subset of the commercial universe. And its deepest value is on space that has been looked at before, because that is what builds the archive. Use it for the question it owns, what has this range been, and use a fraud API for the question that one owns.

The field at a glance

What each tool answers, and whether it keeps dated history. Free access as of August 2026.
Tool Best at Dated history Free access
IPQualityScoreReal-time fraud scoreNo1,000 lookups
ScamalyticsFraud score, proxy/VPN/TorNo~5,000/month
SpurProxy/VPN attributionNoSingle-IP lookup
IPinfoGeolocation, ASN dataNoCountry-level, unlimited
MaxMind minFraudTransaction risk7-day snapshotTrial allowance
AbuseIPDBDated abuse reportsYes, abuse reports1,000/day
ipapi.isEnrichment, detectionNo~1,000/day
IP2LocationSelf-hosted geo/proxy DBNo50,000/month
Criminal IPAttack-surface + riskNoUsage-based
APIVoid / IPVoidBlocklist consensusNoWeb checker
RIPEstatRouting/registry historyYes, routingFree
bgp.toolsBGP explorerPaid snapshotsNon-commercial
Hurricane ElectricWhois, IRR, prefixesRolling windowFree
subnethistoryDated ownership + reputation historyYes, all threeFree, open API

How to choose

Match the tool to the question and the choice makes itself. To block a risky session in real time, use a fraud API: IPQualityScore, Spur or MaxMind, with Scamalytics or ipapi.is as lighter options. To read accurate location and network data, IPinfo or IP2Location. For a fast blocklist consensus, IPVoid or AbuseIPDB, the latter with the rare benefit of dated evidence. To trace how a prefix has been routed, RIPEstat, bgp.tools or Hurricane Electric. And to answer what a range has actually been before you buy, lease or send from it, the combined ownership-and-reputation history, that is the one we built, and you can run a lookup right now and judge it against everything else on this list.

The genuinely careful answer is usually two tools, not one: a fraud API for the live decision, and a history tool for the due diligence behind it. They are answering different questions, and the mistake the ranking lists make is pretending they are not.

Look up any address, prefix or AS number on the front page and compare what comes back with your current tool. The report shows the date and the source behind each claim, and says plainly when nobody has checked something.