Check proxy IP quality yourself: an IP reputation check
Check proxy IP quality yourself: who owns the IP, a Spamhaus blocklist lookup with dig and Python, geolocation disagreement, fraud scores, and what to do next.
To check proxy IP quality, look at four things: which network owns the address (its ASN), whether it sits on a public blocklist, whether the main geolocation databases agree on its country, and why fraud-score sites rate it the way they do. All four are free to check yourself, so a provider's "clean IPs" claim never has to be taken on trust. Here is how, with code you can run.
What a "clean" IP means
"Clean IP" is a sales word with no fixed definition. Turned into facts you can check, a good-quality proxy IP means:
- The label holds up. Residential, ISP or datacenter, and the country you paid for, match what a lookup shows.
- No abuse record. It is not on the public blocklists that track spam and compromised hosts.
- Location agrees. The main geolocation databases broadly agree on its country.
- The risk score has a reason. When a score is high, you can say which signals caused it.
One thing to accept first: a proxy IP is a proxy. Many databases will flag it as one, and that is accurate, not dirty. What you are looking for is a wrong label or an abuse record. An address that leaves no trace in any database is not the goal.
Step one: find the exit IP and its owner
Ask an echo service which address the target sees, through the proxy. HOST, PORT, USERNAME and PASSWORD are placeholders; the real values are on each service's page in the dashboard.
curl -s -x http://USERNAME:PASSWORD@HOST:PORT https://api.ipify.org
Then look up which autonomous system (ASN) announces the address and who holds it. How to check an IP's type has the full script and how to read it, so it is not repeated here. The owning network comes first for a reason: an address sold as residential that belongs to a hosting company has failed, however clean the rest of the checks come out.
Step two: an IP reputation check against Spamhaus ZEN
Spamhaus runs some of the blocklists most widely used by mail servers and websites. Its ZEN list combines several of them and is queried over DNS: reverse the four parts of the IP, append zen.spamhaus.org, and ask for the A record.
- An answer in
127.0.0.xmeans the address is on one of the lists. - No such name (NXDOMAIN) means it is not listed.
dig does it in one line. The example uses 203.0.113.10, from the TEST-NET range reserved for documentation; put your own exit IP in its place:
IP=203.0.113.10
dig +short "$(echo "$IP" | awk -F. '{print $4"."$3"."$2"."$1}').zen.spamhaus.org"
For several addresses, or to see what each return code means, this script needs only the Python standard library:
import ipaddress
import socket
import sys
ZEN = {
"127.0.0.2": "SBL: known spam source or spam operation",
"127.0.0.3": "SBL CSS: low-reputation sending",
"127.0.0.4": "XBL: exploited or infected host",
"127.0.0.10": "PBL, ISP maintained: end-user range, not a mail server",
"127.0.0.11": "PBL, Spamhaus maintained: end-user range, not a mail server",
"127.255.255.252": "ERROR: typo in the list name",
"127.255.255.254": "ERROR: queried through a public or open resolver",
"127.255.255.255": "ERROR: too many queries",
}
def zen_name(ip):
octets = str(ipaddress.IPv4Address(ip)).split(".")
return ".".join(reversed(octets)) + ".zen.spamhaus.org"
def zen_lookup(ip):
try:
_, _, answers = socket.gethostbyname_ex(zen_name(ip))
except socket.gaierror:
return []
return sorted(answers)
for ip in sys.argv[1:] or ["203.0.113.10"]:
print(ip, "->", zen_name(ip))
answers = zen_lookup(ip)
if not answers:
print(" no answer: not listed, or the resolver gave nothing back")
for code in answers:
print(" " + code, ZEN.get(code, "listed: look it up on spamhaus.org"))
Save it as zen_check.py and run python3 zen_check.py for the example, or python3 zen_check.py YOUR_EXIT_IP for your own. Run the lookups from your own connection; they do not need to go through the proxy.
First, check your resolver can query Spamhaus
This is where most people go wrong. Spamhaus's public mirrors are free for low-volume, non-commercial use, and they do not accept queries relayed through public or open DNS resolvers. In Spamhaus's words: through a public resolver "we can't determine the volume of queries you are making. As a result, we don't allow our DNSBLs to be queried via these means."
In practice that shows up two ways:
- You get
127.255.255.254. That is an error code meaning "query via public/open resolver", and it says nothing about the IP. - You get nothing at all. That reads as "not listed", which is the dangerous case, because a dirty IP looks clean.
So test the resolver first. By convention (RFC 5782), a DNS blocklist keeps a test entry for 127.0.0.2:
python3 zen_check.py 127.0.0.2
If 127.0.0.2 and other codes come back, your resolver is getting real answers. If nothing comes back, or only 127.255.255.254, switch to your internet provider's DNS or run your own resolver. For higher volumes or commercial use, Spamhaus offers a registered Data Query Service (DQS); check its site for who qualifies. For one or two addresses, the IP and Domain Reputation Checker on the Spamhaus website is easier, and manual lookups are what it is for.
A PBL listing is not a dirty IP
The example address returns 127.0.0.11, which is the PBL. The PBL lists end-user ranges: home broadband and office connections that should not be sending mail directly. Internet providers add their own consumer ranges to it.
So a residential or ISP proxy on the PBL often shows the address is a real broadband address. It is not an abuse record. The listings that matter are SBL, CSS and XBL: spam sources, low-reputation sending and compromised hosts.
Step three: compare geolocation databases
Put one IP into a few geolocation databases (ip-api, ipinfo, the MaxMind demo, for example) and the country and city often disagree. The reasons are ordinary:
- Each database draws on different sources: registry records for some, network measurements and user reports for others.
- Address blocks change hands, and a new holder may use one in another country before the databases catch up.
- City-level data is rough by nature, and free databases rougher still.
Read it like this: trust the country, go easy on the city. If most databases say the country you ordered, you are fine. If most say another country, that is worth raising with the provider. You cannot know which database a given site uses, so broad agreement tells you more than any single one being right.
What are fraud score sites, and why do their scores differ?
Some sites rate an IP with a "fraud score" or "risk score". They blend several signals into one number: whether the address is detected as a proxy or VPN, whether it belongs to a hosting company, whether it is on blocklists, whether their own honeypots or customer networks have seen it misbehave, and how recent those records are.
Scores differ because every site has different data and different weights, and none of them publish either. One site rating an address high and another rating it low is not a contradiction. Some ways to use them:
- Read the reasons, not only the number. A good score page lists the signals it matched. "Detected as a proxy" is expected for a proxy IP. "Recent abuse reports" deserves attention.
- Compare, do not measure. On one site, comparing a few candidate addresses tells you more than any absolute figure.
- Do not chase a low score. Trying to make a proxy IP look like something else on a scoring site misses what you need: an address with the right label and no abuse record.
Checklist: check proxy IP quality in four steps
| Check | Tool | Normal | Worth raising |
|---|---|---|---|
| Owning network | RIPEstat, whois | Matches the label | Sold as residential, owned by a hosting company |
| Spamhaus ZEN | dig or the script above |
No answer, or PBL only | SBL, CSS or XBL |
| Geolocation | Several databases | Most say the country you ordered | Most say another country |
| Risk score | Scoring sites | High only because "proxy" | High because of recent abuse |
What if the IP you rented is dirty?
Keep the evidence first: the IP, the time, and the raw output of each lookup. Then there are two cases.
The label is wrong. The country is off, or the network type is (a residential address owned by a hosting company, say). With us that is covered by the promise on the honesty page: "Report a mislabelled IP and we credit back the traffic you spent on it, pull the IP from the pool, and tell you in Discord when it is out."
The label is right, but it is on a blocklist. The address is the type and country it says, and it shows up on SBL or XBL. Bring the lookup output to Discord and we will look at it and tell you what we can do. We have not written down a fixed promise for this case, so this post does not make one.
Two practical notes:
- On per-IP lines, check on day one. ISP and datacenter IPs are yours for the whole term, so run these checks as soon as you have them and raise anything early.
- On rotating lines, look at the share. Residential rotates per request, so one blocklisted exit affects one request and the next one leaves from somewhere else. Sample several exits and look at how many are listed; that says more about the pool than any single address.
Quick answers
Is an IP reputation check free? Every lookup here costs nothing. Spamhaus's public mirrors are for low-volume, non-commercial use, and its terms decide whether your use counts; for a handful of addresses, the lookup tool on its website is the safe route.
Can I query Spamhaus through 8.8.8.8 or another public DNS?
No. Spamhaus does not accept queries through public resolvers, so you get an error code or nothing. Test with 127.0.0.2 first.
Is a residential IP on the PBL dirty? No. The PBL lists end-user ranges that should not send mail directly, and home broadband belongs there. SBL, CSS and XBL are the ones that matter.
Why does one IP get such different risk scores on different sites? Each site uses its own data and weights and publishes neither. The reasons it lists are more useful than the number.
Next step
Put a small top-up on the line you need, take a few addresses, run these checks and save the output. How to test a proxy provider before a big order has the matching test plan, and the rates are on the pricing page. If something looks off, post the output in Discord and we will look at it in the open.