Security

What is IP Reputation?

IP reputation is the trust score a website, mail server or anti-bot system assigns to an IP address based on the traffic it has produced before. Spam complaints, request patterns, past abuse reports, hosting type and ASN ownership all feed that score. A poor one earns CAPTCHAs where a good one passes, or a refusal with no explanation.

No central authority publishes one score. Each consumer keeps its own. Mail providers weigh spam complaints and sending volume, while anti-bot vendors weigh request patterns and failed challenges. A single online store may keep nothing more than a counter of failed logins per address. The inputs overlap heavily. An ASN lookup tells any of them who owns the range, and reverse DNS hints at whether an address belongs to a hosting company or to a broadband subscriber. Public abuse feeds add a listing history that costs one query to read.

Address type drives most of the outcome. An ASN lookup identifies a datacenter range in a single query, and plenty of sites apply a standing penalty to anything registered to a cloud host, because ordinary shoppers do not browse from a rented server. Carrier-assigned mobile ranges score the opposite way. CGNAT puts large numbers of paying subscribers behind one address, so blocking it costs the site real customers. Traffic leaving a mobile IP also looks like traffic from a phone, which is why PROXIES.SX runs on 4G/5G carrier ranges.

Reputation attaches to the address, not to you. A mobile IP that a carrier hands your modem this morning carries whatever the previous holder did with it, which is why a clean-looking address sometimes draws a CAPTCHA on the first request. Scores decay once the abuse stops, though the rate is unpublished and differs by vendor. Mail blacklists are the exception, since many expose both a lookup and a delisting form, so you can at least read the listing that a web anti-bot system would never show you.

Watch the challenge rate rather than the block rate. A rising share of CAPTCHAs, soft 403s or empty result sets usually arrives before an address stops working altogether, and it is the earliest warning that a target has downgraded its opinion of the IP. Concentration does the damage. Ten accounts signing in from one address, or a scraper firing requests at a pace no human produces, teaches the target something about that IP that no later rotation schedule undoes.

Where you meet it

You meet IP reputation when a script that ran fine yesterday starts collecting CAPTCHAs, or when a signup form accepts every address except the one you are testing from. It also decides which proxy type fits a job, because a target that penalises datacenter ranges leaves you buying mobile or residential IPs whatever the price difference. Before blaming your headers or your fingerprint, load the target in a clean browser through the same IP and see what it returns.

Common questions

How do I check the reputation of a proxy IP?

For the mail side, query the public DNS blacklists through any aggregate lookup service. For the web side, an IP intelligence provider will show you how the address is labelled by ASN and usage type. The test that settles it is your own. Request the real target through that IP and compare its challenge rate against a known-good address.

Do mobile proxies always have good IP reputation?

No. They start from a better baseline because the range belongs to a carrier and CGNAT hides many real subscribers behind each address, which makes sites reluctant to block. Addresses still recycle between subscribers, so you inherit the previous holder's behaviour, and some carrier ranges are listed by policy on mail-focused blacklists.

Can a burned IP recover?

Usually, given time and no further abuse. Most scoring systems decay old signals, and a carrier will eventually reassign a mobile address to someone else entirely. There is no way to force a web anti-bot vendor to reset its opinion, and nothing is guaranteed, so plan around rotation rather than around rehabilitating a specific address.

Related terms

Blacklist
A blacklist is a list of IP addresses, domains or ranges that a service refuses or restricts. Public DNS blacklists such as Spamhaus target mail abuse, while anti-bot vendors, CDNs and individual sites keep private ones. An address lands on a list after abuse reports, spam or automated traffic, and removal ranges from automatic expiry to a manual delisting request.
Anonymity
Anonymity, in proxy terms, is how much a destination server can learn about the client behind a connection. Proxy listings grade it by whether the proxy forwards your real IP or announces itself in request headers, though DNS, WebRTC and TLS details can give away the same information a header would.
Anonymous Proxy
An anonymous proxy hides the client's real IP address from the destination server but still identifies itself as a proxy, typically through a Via or Proxy-Connection header. The site learns that an intermediary is in the path and can act on that, without ever learning where the request originated.
Elite Proxy
An elite proxy, also called a high-anonymity or level 1 proxy, forwards requests without adding Via, X-Forwarded-For or any other header that reveals an intermediary. To the destination server the traffic reads as an ordinary direct connection from the proxy's own IP address. That address can still be classified.
Transparent Proxy
A transparent proxy intercepts traffic without any client configuration and passes the client's real IP to the destination, usually in an X-Forwarded-For header alongside Via. ISPs, schools and corporate networks deploy them for caching and content filtering. They give the user no privacy and are visible to any server that reads headers.
Whitelist
A whitelist is an explicit list of IP addresses, ranges or identities that a system allows, with everything else denied by default. Firewalls, admin panels, API gateways, database hosts and proxy providers all use them. On the proxy side, whitelisting your server's public IP lets it connect without sending a username and password.
IP Authentication
IP authentication authorizes a proxy client by the source address of its connection instead of a credential. You register the public IP of the machine that will connect, and the provider's gateway accepts sessions from it while refusing the rest. There is no Proxy-Authorization header to send and no password sitting in a config file.

Real 4G/5G mobile and residential IPs

PROXIES.SX runs carrier IPs in 100+ countries with HTTP and SOCKS5 on every endpoint. $4/GB down to $2.40/GB at volume, free endpoints and rotation, and your GB never expire.