Scamalytics Explained: IP Fraud Score, Risks & How It Works
If you searched for Scamalytics, you may have seen an IP address, fraud score, risk label, or proxy warning and wondered what it actually means. Scamalytics is not simply a website that labels people as scammers. It provides IP fraud intelligence that businesses can use to assess the risk associated with internet connections.
The confusing part is that an IP score can look like a simple verdict when it is really a risk signal based on network and fraud intelligence. This guide breaks down what Scamalytics does, what information it checks, how its 0–100 score works, and how that score is produced.
What Is Scamalytics and What Does It Do?
Scamalytics is an IP fraud-intelligence service designed to help fraud and risk teams assess internet traffic. Its products provide a proprietary fraud score along with additional information about an IP address, such as proxy detection, ISP-level risk, geolocation, and external intelligence.
In simple terms, Scamalytics helps answer a question like:
“How much fraud risk is associated with this IP address?”
That question can matter when a business receives a new account registration, login, payment attempt, marketplace interaction, or other online request.
Scamalytics offers several ways for organizations to use its IP intelligence, including a real-time API, an on-premises MMDB, and a bulk IP lookup tool. The company says its products are used across areas such as fintech, banking, payment processing, identity verification, e-commerce, adtech, and online platforms.
Scamalytics Is Focused on IP-Level Risk
One distinction is important from the beginning.
Scamalytics evaluates information associated with an IP address and its surrounding network context. That does not mean the service automatically identifies a specific person as a scammer.
An IP can be used by more than one person. Likewise, one person can connect through different IP addresses over time.
So when you see a Scamalytics score, the useful starting question is not:
“Is this person a scammer?”
It is:
“What does this IP-level risk signal tell me about the connection?”
That distinction becomes especially important when interpreting a high score.
What Information Does Scamalytics Check?
A Scamalytics result can contain much more than one number. Its current IP Fraud Risk API documentation shows that the response can include the proprietary Scamalytics score, a risk classification, ISP and organization information, proxy-related indicators, and data from multiple external sources.
Think of the result as a collection of signals rather than a single yes-or-no judgment.
IP Fraud Risk
The central signal is the Scamalytics fraud score, which ranges from 0 to 100.
The score is intended to represent the fraud risk associated with an IP address. Scamalytics describes it as a proprietary signal rather than simply passing through a score from another data provider.
The score can therefore give a business a quick way to classify an IP before deciding whether additional verification or review is appropriate.
Proxy, VPN, and Tor Signals
Scamalytics can also identify various forms of anonymization or infrastructure associated with an IP.
Its API documentation includes indicators for:
- VPN exit nodes
- data-center infrastructure
- residential proxies
- Apple iCloud Private Relay
- Amazon AWS
- Google-related infrastructure
- Tor-related signals through its external data sources
This information can provide useful context around an IP’s risk.
For example, an IP associated with a hosting provider or anonymization service may need to be interpreted differently from a typical residential connection.
However, the presence of a VPN or proxy does not automatically mean the user is committing fraud. People use privacy tools and alternative connections for many legitimate reasons.
ISP and Network Information
Scamalytics can also provide information about the network associated with an IP.
Depending on the product and subscription level, this can include the ISP or organization, along with an ISP-level risk score.
This matters because an IP does not exist in isolation.
Its broader network environment can provide additional context when assessing risk.
Geolocation and External Intelligence
Scamalytics also incorporates geolocation and information from multiple external sources.
Its current API documentation lists sources and signals involving services such as MaxMind GeoLite2, IPinfo, FireHOL, IPsum, Spamhaus DROP, x4bnet, Google, Amazon AWS, and Apple.
The purpose is not simply to collect a large list of data points.
The useful part is bringing different signals together so a business can evaluate an IP from several angles.
What Is a Scamalytics Fraud Score?
The Scamalytics fraud score is a number from 0 to 100 that represents the fraud risk associated with an IP address.
According to Scamalytics, a score of 0 indicates no known fraud risk, while higher scores represent greater observed or inferred risk. The company’s documentation also describes the score as an approximate measure rather than an absolute determination.
For example, a result might look like this:
Fraud Score: 18
or:
Fraud Score: 72
The number gives a business a quick way to distinguish lower-risk connections from connections that may deserve additional scrutiny.
But the number should not be read without context.
A score is attached to an IP address, not directly to a person’s identity or character.
What Does a Score of 70 Mean?
This is one of the most useful examples for understanding the system.
Scamalytics currently explains that a score of 70 means approximately 7 out of 10 users seen from that IP address have been linked to fraudulent activity within the traffic it can observe. It describes this as an approximation and recommends that businesses fine-tune their own thresholds using their own fraud data.
That wording matters.
It does not mean:
“The person currently using this IP is 70% a scammer.”
Instead, it describes the observed risk associated with traffic from that IP.
This is why the score needs to be combined with other information before making a decision about a particular transaction, account, or user.
What Do Scamalytics Scores From 0 to 100 Mean?
Scamalytics currently groups its scores into four risk categories:
| Score | Scamalytics risk level | General interpretation |
|---|---|---|
| 0–19 | Low | Lower observed fraud risk |
| 20–59 | Medium | Some additional caution may be appropriate |
| 60–89 | High | Greater risk that may justify additional checks |
| 90–100 | Very high | Stronger scrutiny or manual review may be appropriate |
These are the risk ranges published by Scamalytics. They should not be treated as universal rules that every website must follow. Scamalytics specifically describes its suggested thresholds as a starting point and recommends adjusting them according to an organization’s own fraud data and tolerance for customer friction.
0–19: Low Risk
A score between 0 and 19 falls into Scamalytics’ low-risk category.
That generally means the available signals show relatively low observed fraud risk for traffic from the IP.
It does not mean the IP can never be involved in fraudulent activity.
It simply represents a lower risk classification within Scamalytics’ system.
20–59: Medium Risk
Scores from 20 to 59 are classified as medium risk.
A business may decide that this range deserves additional checks rather than automatically blocking the connection.
For example, a website could use another verification step when the account or transaction itself raises additional concerns.
The appropriate response depends on the business and its own fraud data.
60–89: High Risk
Scores from 60 to 89 are classified as high risk.
A high score can be an important warning signal, particularly when other indicators point in the same direction.
But it still should not automatically be interpreted as proof that the individual using the IP is fraudulent.
That distinction becomes especially important with shared networks, proxies, hosting environments, and other situations where multiple users may appear through the same IP.
90–100: Very High Risk
Scores from 90 to 100 fall into the very-high-risk category.
Scamalytics’ published guidance suggests that organizations may consider stronger actions at this level, such as blocking or manual review. However, it also makes clear that these thresholds are starting points that businesses should model against their own data.
So even at the highest range, the practical decision belongs to the organization using the risk data.
How Is a Scamalytics Fraud Score Determined?
The score is not simply a number copied from one public blacklist.
Scamalytics says its proprietary Risk Score is built using fraud feedback gathered from a global network of operators that report confirmed fraudulent activity. It then applies that intelligence across the surrounding IP neighborhood, including related subnet, ASN, and hosting-block context.
This approach helps explain why an IP can have a meaningful risk score even when that exact address has not independently appeared in a public blacklist.
Fraud Feedback and Historical Signals
Scamalytics uses reported fraud activity as part of its intelligence.
This provides a feedback loop: observed fraudulent activity can contribute to the risk understanding of related IP infrastructure.
The important point is that the system is designed around observed fraud intelligence rather than a simple static list of “bad IPs.”
IP and Network Reputation
An IP is part of a larger network.
Scamalytics says its intelligence can be applied across an IP neighborhood, including the same subnet, ASN, and hosting block.
That means the surrounding infrastructure can influence how an IP is assessed.
This is one reason an individual address should not always be interpreted completely independently from its network environment.
Proxy and Anonymisation Signals
Proxy and anonymization information can also contribute useful context.
The current API can identify signals such as VPNs, datacenter infrastructure, residential proxies, Apple Private Relay, and other network characteristics.
These signals do not automatically establish malicious intent.
Instead, they help a fraud system understand what type of connection it is dealing with.
Broader Network Context
Scamalytics also combines its proprietary intelligence with information from external sources.
Its API documentation describes data from more than ten external sources, covering areas such as IP reputation, geolocation, proxy detection, cloud infrastructure, and blacklist information.
The result is a broader risk picture rather than a single isolated indicator.
That distinction is important because fraud detection works better when multiple relevant signals are interpreted together.
What This Score Does — and Does Not — Tell You
At this point, the most important distinction is simple:
A Scamalytics score describes IP-level fraud risk. It does not automatically identify the person behind the IP as a scammer.
For example, a shared network may have many legitimate users. A VPN can route traffic from different people through the same exit IP. A hosting or proxy address can also be used by different customers.
So if you encounter a high Scamalytics score, the correct response is not to jump directly from:
“High IP risk”
to:
“This person is fraudulent.”
Instead, the score should be treated as one piece of evidence that needs context.
Why Can a Legitimate User Have a High Scamalytics Score?
Seeing a high Scamalytics score can be confusing, especially if you are checking your own IP and know that you are not committing fraud.
The key point is that the score is about risk associated with an IP address and its network context. It is not a personal identity score.
An IP address can be shared, reassigned, used through a VPN, connected to hosting infrastructure, or associated with network activity that creates a higher risk signal. Scamalytics also explains that its scoring can be influenced by the surrounding IP neighborhood, including related subnet, ASN, and hosting-block information.
Shared IP Addresses
A single public IP can represent more than one user.
For example, people on the same corporate network, public Wi-Fi connection, or other shared connection may appear to an online service through one public IP.
If some traffic associated with that IP produces higher-risk signals, the IP’s reputation may not represent every individual using it.
This is why you should avoid interpreting:
High IP risk = every user behind the IP is fraudulent.
That conclusion goes beyond what the score itself establishes.
VPN and Proxy Connections
VPNs and proxies can also change how an IP is assessed.
Scamalytics’ API includes indicators for VPN exit nodes, datacenter infrastructure, residential proxies, Tor-related information, and other anonymization signals.
Using a VPN does not automatically mean someone is doing something malicious.
People use VPNs for privacy, remote work, travel, security, and other legitimate reasons.
However, from a fraud-detection perspective, anonymized traffic can provide less direct information about the underlying connection. That can make the IP worth examining more closely.
Datacenter or Hosting Networks
An IP associated with a cloud provider or hosting environment can have a different risk profile from a typical residential connection.
This is partly because servers, automation, bots, proxies, and other services can operate from datacenter infrastructure.
Scamalytics specifically provides indicators for datacenter and cloud-provider infrastructure.
Again, that does not mean every person using a cloud or hosting IP is fraudulent. It simply gives a fraud system additional context.
Network Reputation
An IP can also be affected by the reputation of the broader network around it.
Scamalytics says its intelligence can be applied across nearby addresses within the same subnet, ASN, or hosting block. As a result, an address can receive an elevated risk score even when that exact IP has not individually been reported as fraudulent.
This helps explain why a person may see a surprisingly high score on an IP they have only recently started using.
Changing or Dynamic IP Conditions
Your public IP is not necessarily permanent.
Depending on your internet provider and connection type, your address may change over time. The characteristics and reputation associated with a newly assigned IP can therefore differ from those associated with an IP you previously used.
So if your result changes later, that does not necessarily mean your behavior changed. The underlying IP or the available risk intelligence may have changed.
How Do You Read a Scamalytics IP Report?
If you are looking at a Scamalytics result, the best approach is to read the report as a collection of signals rather than focusing on one number.
The current Scamalytics API can return the fraud score and risk category alongside ISP-level risk, organization information, proxy indicators, datacenter status, external blacklist information, and other enrichment depending on the product level.
Start With the Fraud Score
First, identify the main Scamalytics fraud score.
This gives you the broadest indication of the risk classification associated with the IP.
Do not stop there, though.
A score tells you how the IP is being assessed, while the other fields can help explain why that assessment may exist.
Check the Risk Category
Look at the accompanying risk label, such as:
- Low
- Medium
- High
- Very high
Scamalytics currently maps these labels to its published score ranges, but it also says those thresholds should be treated as starting points rather than universal rules.
That distinction matters when you are trying to understand why a website accepted, challenged, or blocked a connection.
Review Proxy, VPN, and Tor Signals
Next, check whether the IP has indicators associated with anonymization or proxy infrastructure.
The API can identify whether an IP is detected as a VPN exit node, residential proxy, datacenter/cloud connection, or other supported proxy type.
This can provide useful context.
For example, a high-risk result combined with a detected datacenter or proxy connection may tell a business more than the score alone.
Check ISP and Network Information
The ISP and organization fields can help identify what kind of network the IP belongs to.
Scamalytics also provides an ISP-level risk score, which assesses the broader ISP network rather than only the individual IP.
This is useful when an individual IP has limited history but the surrounding network has a known risk pattern.
Review Other Risk Indicators
Depending on the available product and data, a report can include information from external sources and indicators such as external blacklist status.
Scamalytics’ current API documentation says its response can incorporate data from more than ten external sources.
These signals should be treated as supporting evidence, not as separate proof of wrongdoing.
Consider the Full Context
Finally, ask what is actually happening.
A high score on an IP used for a legitimate corporate connection is a different situation from a high score appearing alongside multiple other suspicious indicators during a high-value transaction.
The most useful interpretation therefore looks like:
Score + network type + proxy status + ISP information + transaction/account context
rather than:
Score alone.
How Do Businesses Use Scamalytics?
Scamalytics is primarily useful when a business needs to make risk decisions about online traffic.
For example, an organization may want to know whether an incoming connection appears associated with elevated fraud risk before allowing a sensitive action.
Possible applications include:
- account registration
- login protection
- payment screening
- marketplace activity
- fraud investigations
- identity verification workflows
- automated risk scoring
- manual review queues
Scamalytics currently offers an IP Fraud Risk API as well as other data-delivery options, including MMDB and bulk lookup capabilities. Its API documentation describes fields that developers can use to incorporate IP risk into their own systems.
Why Businesses Use a Risk Signal Instead of a Simple Blocklist
A simple blocklist asks:
“Is this IP blocked?”
A risk score provides more flexibility.
A business can decide that low-risk traffic should proceed normally, medium-risk traffic should receive additional verification, and higher-risk traffic should receive stronger scrutiny.
Scamalytics itself publishes example actions for different score ranges, but it explicitly recommends adjusting those thresholds using an organization’s own fraud data and customer-experience requirements.
That means the score is intended to support a risk decision, not replace the entire decision-making process.
Is Scamalytics Legit, and How Much Should You Trust Its Results?
There are two different questions here:
- Is Scamalytics an identifiable fraud-detection service?
- Should every score be treated as unquestionable proof?
The available official documentation supports the first point. Scamalytics publishes product documentation, API documentation, Terms of Service, and a Privacy Policy. Its current Terms identify the company as SCAMALYTICS LTD and cover its website, SaaS products, API, and downloadable data formats.
Its Privacy Policy also identifies Scamalytics LTD as the data controller and describes its anti-fraud services and processing activities.
That establishes useful factual context about the service.
But a Legitimate Service Can Still Produce a Result That Needs Context
Being a real fraud-intelligence service does not mean every individual risk score should be treated as an absolute verdict.
Scamalytics itself states that its suggested score thresholds are starting points that organizations should adjust according to their own fraud data.
Its IP results also state that Scamalytics does not have visibility into the entire internet. Its assessments specifically concern the web connections visible to its fraud-detection network.
So the sensible interpretation is:
Scamalytics can provide useful risk intelligence, but an IP score is still one piece of evidence rather than a complete determination about a person.
That distinction is especially important when a business is deciding whether to block, challenge, approve, or manually review someone.
What Should You Do If Your IP Has a High Scamalytics Score?
If you check your IP and receive a high or very-high result, there is no need to immediately assume that something is wrong with you or your account.
Instead, work through the result systematically.
1. Confirm the Exact IP
Make sure you are checking the public IP that the relevant website or service actually sees.
Your device may have a private local IP, while websites see a different public IP.
2. Review the Risk Score and Category
Note the actual number and its associated risk classification.
Do not rely on a vague message such as “high risk” without checking the underlying result.
3. Check Proxy and VPN Indicators
Look for indicators showing whether the IP is associated with:
- VPN infrastructure
- proxy services
- Tor
- datacenter/cloud infrastructure
- residential proxy activity
These indicators can help explain why the connection is receiving additional scrutiny.
4. Check the ISP and Network
Review the ISP or organization associated with the address and, where available, the ISP-level risk score.
A high ISP-level risk can provide context that an individual IP result alone cannot.
5. Consider Whether the IP Is Shared
Think about how you are connecting.
Are you using:
- home internet?
- office Wi-Fi?
- public Wi-Fi?
- mobile data?
- a VPN?
- a proxy?
- cloud infrastructure?
A shared or anonymized connection can make IP-level results less directly attributable to one person.
6. Do Not Treat the Score as Personal Proof
A high score does not automatically establish that you personally committed fraud.
It is a risk indicator associated with the connection and the intelligence available to the system.
If another website has blocked or challenged you, its own review or verification process is the appropriate place to resolve that decision.
7. Look for Changes Later
If you are using a dynamic connection, your public IP can change.
A different IP can produce a different result because the risk information associated with that address and its network may differ.
Frequently Asked Questions About Scamalytics
Can a Scamalytics score change over time?
Yes, an IP’s risk assessment can change as new fraud intelligence and network information become available. Scamalytics describes its score as being based on fraud feedback and broader network intelligence, so the assessment is not necessarily permanent.
Does Scamalytics identify the person behind an IP address?
An IP score should not be interpreted as direct proof of a person’s identity or behavior. The score describes risk associated with an IP and its network context. An IP can also be shared by multiple users.
Can a VPN affect a Scamalytics result?
Yes. Scamalytics detects various VPN, proxy, Tor, and datacenter-related signals, and these characteristics can contribute useful context to an IP risk assessment. VPN use by itself does not prove malicious behavior.
Can two people using the same IP receive different fraud decisions?
Yes. A shared IP can be one signal in a larger fraud-detection system. Businesses can combine IP intelligence with account, transaction, device, identity, and other signals when making decisions. The same IP therefore does not necessarily produce the same final decision for every user.
Does Scamalytics replace a complete fraud-detection system?
Not necessarily. Scamalytics provides IP fraud intelligence that can become one component of a broader fraud-prevention workflow. Its API is designed to supply risk and enrichment data that businesses can incorporate into their own systems.
Why might a high Scamalytics score not result in a blocked connection?
A business decides how to use risk information.
Scamalytics publishes example actions for different score ranges, but says organizations should adjust those thresholds according to their own fraud data and customer-experience requirements.
A company may therefore use a high score as a reason for additional verification rather than automatically blocking the connection.
Conclusion
Scamalytics is best understood as an IP fraud-intelligence service, not a simple tool that declares whether a person is a scammer. Its central fraud score runs from 0 to 100 and is supported by additional information about network risk, proxy and anonymization signals, ISP reputation, geolocation, and external intelligence.
The most important thing to remember is that an IP-level risk score is not the same as a personal fraud verdict. A shared network, VPN, proxy, hosting environment, or broader network reputation can affect what an IP looks like to a fraud-detection system.
If you are checking your own result, start with the score, then examine the risk category, proxy status, ISP information, and other available signals. If a website has challenged your connection, use its own verification or support process rather than assuming that one Scamalytics number tells the whole story.
For businesses, the practical value is different: Scamalytics can provide an additional risk signal that can be combined with other information to decide whether traffic should be allowed, challenged, or reviewed.
In short, Scamalytics helps answer “How risky does this IP appear?” — not “Is this person definitely a scammer?” That distinction is the key to interpreting its results correctly.