IP Intelligence
LiveUncover risky addresses before they reach you.
Detects the anonymisation layer someone is hiding behind, and returns the geo and network context around it. Built on live Tor exit-node feeds, datacenter ASN ranges, published VPN and proxy ranges, and reputation gathered across the LayerCall network.
What it detects
- Commercial VPN detection
- Proxy and residential-proxy egress
- Tor exit nodes (IPv4 and IPv6)
- Datacenter and hosting ASNs
- Country, city, ASN and ISP
- Abuse reputation across the network
When to use it
Anywhere you see a visitor's IP: signup, login, checkout, or an abuse investigation.
Questions
Should I block every VPN user?
No, and this is the single most common mistake. Most VPN users are privacy-conscious people, remote workers and travellers. Blocking all of them is the top false-positive complaint about fraud tools. Treat VPN as one input among several — a VPN plus a disposable email plus a brand-new domain is a very different picture from a VPN alone.
How is Tor detection kept current?
Exit nodes rotate constantly, so a static list is worthless within days. We pull from the live Tor directory including IPv6 nodes, with a staleness bound — if the feed is unhealthy we stop caching scores rather than serving confident answers from stale data.
Do you handle IPv6?
Yes, including IPv4-mapped IPv6 addresses like ::ffff:1.2.3.4, which are canonicalised before scoring. That form is a common way to slip past naive checks.