An IPQualityScore (IPQS) fraud score runs from 0 to 100. The IPQS documentation calls 75 and above suspicious and likely a proxy, VPN or Tor connection, though not necessarily a fraudulent user. It treats 90 and above as high risk. A score of 85 means IPQS reads the IP as an anonymizing connection with some suspicious signals. It does not mean the IP is confirmed abusive.
For a proxy buyer, the number alone tells you little. The fields that come back with it tell you whether the IP is fine for account work, scraping and ad verification, or whether it is burned.
What do the IPQS fraud score bands mean?
IPQS publishes the bands in its response parameters documentation (as of September 2026). The prose on that page says:
- 75 and above: suspicious, likely a proxy, VPN or Tor connection, but not necessarily a fraudulent user. These may be users who are protecting their privacy.
- 90 and above: high-risk users likely to engage in malicious behavior.
The same page labels three bands:
- Suspicious: previous reputation issues or a low-risk proxy or VPN.
- High Risk: suspicious behavior signals.
- Frequent Abusive Behavior: frequent abuse over the past 24 to 72 hours.
An 85 falls in the band labeled High Risk, which sits below the 90 cut-off that the prose treats as likely malicious. In plain terms, IPQS sees an anonymizing connection plus some behavior signals, but not the level of recent abuse it reserves for the top of the scale.
The score is also not a fixed property of the IP. IPQS bases fraud_score on the IP, the user agent, the language and any other variables the site passes. The same exit IP can score differently for two visitors with different browsers. Scamalytics uses a separate scale with its own cut-offs, covered in Scamalytics fraud score.
Why does the same IP score higher on some sites than on the free lookup?
The score depends on the settings of whoever runs the query. According to the IPQS advanced options documentation, strictness runs from 0 to 3. IPQS recommends starting at 0 and says levels 2 and above are very strict and produce false positives. A separate option, lighter_penalties, lowers scores for mixed-quality IPs.
The free front-end IP lookup on the IPQS site runs with strictness 0, allow_public_access_points, lighter_penalties and mobile set to true. That combination gives the most suppressed scores IPQS produces.
A site that calls the API with its own key and its own settings can therefore see a higher number for the same IP than the free lookup shows you. Treat the free lookup as a lenient reading, not as what every site sees.
Which IPQS fields matter more than the fraud score?
The IPQS response fields explain why the number is high. These are the ones that matter for proxy work:
proxy: the IP is a suspected proxy of any kind, including SOCKS, elite, anonymous, VPN or Tor.vpn,tor: VPN or Tor suspicion.active_vpnandactive_toridentify an active VPN connection or Tor exit.recent_abuse: IPQS has verified abuse from this IP across its network within the past few days. Examples include chargebacks, account takeover, fake registrations and bot attacks.bot_status: the IP shows bot activity.abuse_velocity: how often the IP has been abusive recently. The value is high, medium, low or none.connection_type: the network class, one of Residential, Corporate, Education, Mobile or Data Center.mobile: describes the user agent, not the carrier.
mobile is not connection_type
The mobile field reports whether the visitor's user agent looks like a phone. A desktop browser on a carrier IP returns mobile: false and connection_type: Mobile. To judge whether a proxy delivers carrier IPs, read connection_type.
How should a proxy buyer read an IPQS result?
Read the flags first and the number second. Expect a carrier proxy to come back with proxy: true in most lookups, because traffic really does pass through a proxy.
Carrier IPs also sit behind carrier-grade NAT, where many subscribers share one public address. A reputation lookup on that address therefore reflects a whole crowd of phones, not just you.
A score between 75 and 89 on a mobile proxy is not a defect on its own. Read it together with the abuse fields below.
| Field | Expected on a healthy carrier proxy | Points to a burned or wrong IP |
|---|---|---|
| fraud_ | Can be 75 or higher | Not decisive on its own |
| proxy | true | Not decisive on its own |
| connection_ | Mobile | Data Center: provider is not delivering carrier IPs |
| recent_ | false | true: replace the IP |
| abuse_ | none | high: replace the IP |
| bot_ | false | true: replace the IP |
The rule reduces to three cases.
- High score,
proxy: true,connection_type: Mobile,recent_abuse: false,abuse_velocity: none. Nothing here points to a problem: the IP reads as a carrier proxy with no recent abuse on record. recent_abuse: true,abuse_velocity: highorbot_status: true. The IP carries someone else's recent history. For account sessions, scraping jobs or ad checks, the practical move is to replace it rather than work around it.connection_type: Data Centeron a proxy sold as mobile. IPQS does not see a carrier IP. If several exits from the same provider read that way, the provider is likely not delivering carrier IPs, and no rotation fixes that. See mobile proxy shows as datacenter for how to confirm the ASN and what it means.
Before blaming the score, confirm the basics. The IP Type Checker shows the connection type, carrier and ASN of your current exit. If a target site is already returning block pages, IP reputation is only one layer. Proxy detected: what it means and how to fix it covers the fingerprint, TLS and header checks that sit alongside it.
How do you replace a burned IP on VoidMob?
Replacing an IP on VoidMob depends on the product. VoidMob runs mobile proxies on real 4G/5G devices behind carrier CGNAT, sold two ways.
- Dedicated device: one device is yours, and the IP stays until you rotate it. Every dedicated device has a private rotation link (
https://dashboard.voidmob.com/r/<token>). A plain GET or POST to that link rotates the IP, with the same 60-second cooldown as the dashboard button. Rotate, then re-check the new exit before resuming work. - Shared pay-per-GB proxy list: rotation follows the list's rotation setting, which is per request by default. On a sticky list, regenerate the list password to force a new identity. The old password stops working immediately.
The cheapest way to see what a carrier exit looks like in IPQS is the 1 GB shared plan at $3.99.
What does an IPQS fraud score of 85 mean?
IPQS reads the IP as an anonymizing connection, such as a proxy or VPN, with some suspicious behavior signals. An 85 falls in the band IPQS labels High Risk, below the 90 cut-off it treats as likely malicious. For a mobile proxy, check recent_abuse, abuse_velocity and bot_status before drawing conclusions.
Why is my IP fraud score high on a mobile proxy?
A proxy is an anonymizing connection, so IPQS flags proxy: true and the score rises. Carrier IPs are also shared by many subscribers behind carrier NAT. A high score with connection_type Mobile, no recent abuse and abuse_velocity none is the normal result for a carrier proxy.
What is a high IPQS fraud score?
IPQS calls 75 and above suspicious and likely a proxy, VPN or Tor connection, though not necessarily a fraudulent user. It treats 90 and above as high risk, meaning users likely to engage in malicious behavior.
What is a good IP reputation score on IPQS?
Below 75, IPQS does not label the IP suspicious. For a proxy, a score above 75 is expected. The better measure of a clean proxy IP is recent_abuse false, abuse_velocity none, bot_status false and connection_type matching what you bought.
How can I check my IPQS fraud score?
Use the free IP lookup on the IPQS site, or query the IPQS API with your own key. The free lookup uses the most lenient settings, so sites calling the API with stricter settings may see a higher number. To confirm connection type, carrier and ASN, run the exit through an IP type checker as well.
Carrier IPs you can rotate on demand
VoidMob: mobile proxies on real 4G/5G devices, non-VoIP SMS verification and eSIM. Dedicated devices with a rotation link, or pay-per-GB pools.