Scamalytics Fraud Score: What the Number Means

What a Scamalytics fraud score of 0-100 actually measures, why a clean proxy IP can score high, and how to read the flags before you buy.

VoidMob Team
8 min read

A Scamalytics fraud score is a 0 to 100 number that estimates roughly what share of the users seen from an IP's neighbourhood have been linked to fraud. A 70 means about 7 in 10 of the traffic reported from that address space was flagged, not that your specific session is suspicious. Scamalytics groups scores into four bands: 0-19 low risk, 20-59 medium, 60-89 high, 90-100 very high, and says itself that these thresholds are a starting point that operators tune to their own tolerance (scamalytics.com/products).

Scope of this page

This explains what the score measures so you can judge proxy quality for account management, scraping and ad verification. It is not a guide to influencing a merchant's payment screen, a chargeback decision, or any identity or KYC check.

How to read the four bands

Score bandScamalytics labelWhat it means for a proxy buyer
0-19Low riskTypical for carrier mobile ranges and untouched residential lines
20-59MediumUsually the ISP average showing through, not a fault in your specific IP
60-89HighThe subnet or hosting block has reported history; expect friction on strict sites
90-100Very highDatacenter, public proxy or heavily reported range; replace the IP

Where the number comes from

The core input is fraud feedback reported by a network of operators using Scamalytics. That feedback is not applied to a single address in isolation: it is spread across the surrounding subnet, the ASN and the hosting block. On top of that, an IP score blends in an ISP-level risk score, open-source proxy, VPN and Tor detection, and external lists including MaxMind GeoLite2, IPinfo, Spamhaus DROP, FireHOL, IPsum and x4bnet.

When Scamalytics has no direct traffic from an address at all, it falls back to the ISP's overall risk. That is the single most misread part of the system: a brand new, entirely unused IP can carry a medium or high score purely because of the company that owns it. Scamalytics publishes per-ISP pages and a monthly high-risk ISP list for exactly this reason.

Each IP page also lists a set of boolean flags: Datacenter, External Blacklists, Anonymizing VPN, Tor Exit Node, Server, Public Proxy, Web Proxy and Residential Proxy. Note that residential proxy detection is a paid add-on, so the free page you looked at may show that flag as negative even when the address belongs to a resale pool.

Why a clean proxy IP can score high

Because scoring works at the neighbourhood and ISP level, three things follow:

  • A good IP in a bad block scores badly. If your address sits next to a range that hosted abuse, the reputation travels. Nothing you do on that IP changes the number quickly.
  • Datacenter and hosting ranges carry their ISP's history. A server ASN reads as infrastructure and its ISP score reflects everything else hosted there, which is why a cheap datacenter proxy can score high before it has sent a single request. That is the same mechanism behind a mobile proxy that shows as datacenter when routing or ASN registration is wrong.
  • Carrier mobile IPs usually score low. A mobile exit address behind CGNAT is shared by real subscribers at the same moment you are using it. Reports against those ranges are diluted across many ordinary users, and blocking them means blocking paying customers. In our experience the same property that makes mobile IPs awkward to blacklist tends to keep their fraud scores down.

A practical reading rule before you buy

Score alone is a weak signal. Read the flags first, then the score:

  1. Datacenter, Server, Public Proxy, Web Proxy or Tor Exit Node set to yes. Treat as disqualifying for account work. The IP announces what it is regardless of the number next to it.
  2. External Blacklists set to yes. Check which lists. A Spamhaus DROP hit means the whole netblock is on Spamhaus's do-not-route list; for any hit, confirm with an independent IP blacklist check before you accept the address.
  3. High score with no flags set. Usually ISP-level or subnet reputation. Rotate and re-check: if the next IP from the same pool scores similarly, the pool's ASN is the problem, not the individual address. If scores vary widely, you got unlucky once.
  4. Medium score, no flags, carrier ASN. Usually fine. Carriers serve a lot of mixed traffic, so a medium ISP-level score is common, and chasing a 0 has no payoff.

What to do in each case: re-check after rotation first, replace the IP if the flags are structural, and move off datacenter or heavily resold residential pools onto carrier mobile exits if the whole pool scores badly. The difference between the three IP types is covered in datacenter vs residential vs mobile proxies.

Start with what your exit actually is. If you do not know the ASN and type of the IP you are paying for, the fraud score is uninterpretable.

Check your exit IP type and carrier

How IPQualityScore differs

IPQualityScore returns its own 0-100 fraud score with explicitly different thresholds. Its documentation puts 75 and above at suspicious and likely a proxy, VPN or Tor, 85 and above at high risk, and recommends flagging or blocking at 90 and above (IPQS response parameters). Critically, IPQS also separates the proxy flag from recent_abuse. A high score with proxy: true and recent_abuse: false says "this looks like a proxy", which is a detection outcome, not an abuse history. A recent_abuse: true result is the signal worth acting on.

Because the scales differ, a score from one vendor is not comparable to a score from the other. Use both for direction, never as a pass mark.

When the score stops predicting anything

Reputation scores describe the address. Scamalytics' number says nothing about your browser, TLS stack, timezone or session behaviour, and those are where many blocks actually come from. An IP with a score of 3 still gets challenged if your fingerprint and IP geography disagree, and a high-scoring IP can pass quietly on a permissive site. If you are troubleshooting real blocks rather than shopping for an IP, proxy detected: what it means and how to fix it works through the full detection stack. For ad verification specifically, where you need the score and the carrier geography to both hold, the ad verification proxy guide covers the setup.

What does a fraud score of 85 mean?

In Scamalytics terms it sits in the 60-89 high risk band, meaning a large share of reported traffic from that neighbourhood was linked to fraud. In IPQualityScore terms 85 is its own high-risk threshold. In both cases check the flags: if Datacenter or a blacklist hit is set, the address is structurally bad; if nothing is flagged, the score is likely inherited from the ISP or subnet.

How do I check my fraud score?

Look the address up on the vendor's IP page (Scamalytics and IPQualityScore both publish per-IP lookups). If you use the page that detects your own address, open it through the proxy, or you will score your home line; a lookup by IP works from any connection. Confirm the ASN and IP type separately with an IP type checker so you know what you are reading.

What is a good fraud score for a proxy?

For account work and scraping, low band with no Datacenter, Server, Public Proxy or blacklist flags. Carrier mobile exits commonly land in the low to low-medium range. A medium score on a carrier ASN with clean flags is fine; a low score on a hosting ASN is not, because the site will read the ASN anyway.

Why does my brand new proxy IP already have a high score?

Because scoring is applied across the surrounding subnet, ASN and hosting block, and because Scamalytics falls back to the ISP's overall risk score when it has no direct traffic from an address. A never-used IP on a poorly regarded ISP inherits that ISP's number.

Can I lower the fraud score on an IP I am using?

Not meaningfully, and not quickly. The score reflects reports from an entire range plus third-party lists you do not control. The practical move is to rotate to a different exit, or change pool type, rather than trying to rehabilitate one address.

Buy exits that score like real subscribers

Dedicated 4G/5G devices or a pay-per-GB mobile pool, both on carrier ranges behind CGNAT.