Skip to main content

How IP Scoring Works

6 min read How It Works

Fraudcache uses a sophisticated scoring system to express the likelihood that an IP address is malicious. Understanding how scores are calculated helps you make better decisions about how to use this data.

Understanding Confidence Scores

Unlike traditional blocklists that simply say "blocked" or "not blocked," Fraudcache provides a confidence score from 0 to 100. This score represents our confidence that an IP is involved in malicious activity.

A higher score means more evidence of malicious behavior. This allows you to set your own thresholds based on your risk tolerance.

Scoring Factors

Multiple factors contribute to an IP's confidence score:

Recent Activity

High Impact

Malicious behavior observed in the last 24-48 hours

Source Count

Medium Impact

Number of independent sources reporting the IP

Attack Category

Variable

Type of malicious activity (spam, C2, attacks, scanning)

Time Since Last Activity

Reduces Score

Older activity contributes less to current score

Score Ranges

Here's what different score ranges typically indicate:

0-25

Low Risk

No recent evidence of malicious activity. Safe for most use cases.

26- 50

Moderate Risk

Some suspicious signals. May warrant additional scrutiny.

51-75

High Risk

Strong evidence of malicious activity. Consider blocking or limiting.

76+

Critical Risk

Confirmed malicious source. Active threat that should be blocked.

Score Decay

IP addresses aren't permanently labeled. If an IP stops showing malicious behavior, its score gradually decreases over time. This decay mechanism ensures that IPs can recover their reputation.

The decay rate depends on the severity of past behavior and whether the IP has shown any new suspicious activity. Complete remediation typically takes 7-30 days of clean behavior.

Get Detailed Scoring Data

Our API provides full scoring breakdowns including category-specific scores and historical data.

Ready to Protect Your Infrastructure?

Check any IP address reputation instantly or create a free account to access our full API and threat intelligence feeds.