Live: Tor + abuse feeds refreshed every 6 hours

LayerCall

IP Intelligence

Uncover risky addresses before they reach you.

GET/v1/score/ip

What it detects

  • Commercial VPN detection
  • Proxy and residential-proxy egress
  • Tor exit nodes (IPv4 and IPv6)
  • Datacenter and hosting ASNs
  • Country, city, ASN and ISP
  • Abuse reputation across the network

When to use it

Anywhere you see a visitor's IP: signup, login, checkout, or an abuse investigation.

Questions

Should I block every VPN user?

No, and this is the single most common mistake. Most VPN users are privacy-conscious people, remote workers and travellers. Blocking all of them is the top false-positive complaint about fraud tools. Treat VPN as one input among several — a VPN plus a disposable email plus a brand-new domain is a very different picture from a VPN alone.

How is Tor detection kept current?

Exit nodes rotate constantly, so a static list is worthless within days. We pull from the live Tor directory including IPv6 nodes, with a staleness bound — if the feed is unhealthy we stop caching scores rather than serving confident answers from stale data.

Do you handle IPv6?

Yes, including IPv4-mapped IPv6 addresses like ::ffff:1.2.3.4, which are canonicalised before scoring. That form is a common way to slip past naive checks.

How to do this

Step-by-step, with the trade-offs named.

Other products