Online fraud rarely starts with an obvious warning. A suspicious login, unusual payment, fake account, or automated registration can look normal when viewed from the application itself.
One of the signals businesses can use to investigate that activity is the IP address behind the connection.
That is where Scamalytics comes in.
Scamalytics is a fraud-intelligence company that provides IP risk scoring and related network intelligence to help businesses identify potentially risky connections. Its tools can provide a fraud score, proxy and VPN detection, geolocation information, ISP risk, and other data that can be incorporated into broader fraud-prevention systems.
But there is an important distinction: a high Scamalytics score does not automatically mean that a particular person is a scammer.
The score is a risk signal associated with internet traffic and network infrastructure. Understanding that distinction is essential when interpreting the results.
What Is Scamalytics?
Scamalytics is a fraud-detection and IP-intelligence platform designed primarily for businesses.
Its technology helps organisations evaluate whether an internet connection presents characteristics associated with fraudulent activity. The company offers an online IP checker as well as products for developers and organisations that need to perform checks at larger scale.
The service can be relevant to industries such as:
- Online payments
- Banking and fintech
- E-commerce
- Marketplaces
- Dating platforms
- Social networks
- Identity verification
- Advertising technology
- Online account services
The basic idea is straightforward: before allowing an online action to proceed, a business can examine the network behind the request and use that information as one part of its risk decision.
What Is a Scamalytics Fraud Score?
The central feature is the Scamalytics Risk Score, which ranges from 0 to 100.
A lower number indicates lower observed fraud risk, while a higher number indicates greater observed risk.
Scamalytics currently describes these general ranges:
| Score | Risk level | Possible response |
|---|---|---|
| 0–19 | Low | Generally allow |
| 20–59 | Medium | Additional verification or CAPTCHA |
| 60–89 | High | Stronger authentication or verification |
| 90–100 | Very high | Block or manually review |
These ranges are not universal rules. Scamalytics itself presents them as starting points that businesses should adapt according to their own fraud data and customer-experience requirements.
That flexibility matters because different businesses have different levels of risk tolerance.
A payment processor, for example, may respond differently to a high-risk connection than a discussion forum or content website.
What Does a Scamalytics Score of 70 Mean?
This is one of the most important parts of understanding the service.
According to Scamalytics, a score of 70 means approximately seven out of ten users observed from that IP address have been associated with fraudulent activity within the company’s available data. A score of 0 indicates no known fraud risk in that data.
However, this should not be interpreted as:
“The person using this IP is definitely a scammer.”
An IP address and an individual are not the same thing.
The same address can be shared by many people through:
- Corporate networks
- Universities
- Public Wi-Fi
- Mobile networks
- VPN services
- Hosting infrastructure
- Residential proxy networks
Consequently, an elevated score is better understood as evidence that the connection deserves additional attention, rather than a final verdict about the person using it.
How Does Scamalytics Determine Risk?
Scamalytics says its scoring system uses fraud feedback gathered from a global network of operators that report confirmed fraudulent activity.
It then applies intelligence beyond the individual address, including information from the surrounding network environment. This can include the same subnet, autonomous system number (ASN), or hosting block.
This approach gives the system more context than simply asking whether an IP appears on a blacklist.
The available IP intelligence can include:
- Fraud risk score
- Risk classification
- ISP-level risk
- Proxy detection
- VPN detection
- Tor detection
- Datacenter indicators
- Geolocation
- ASN information
- Organisation information
- External IP reputation information
Scamalytics says its current product integrates information from more than 10 external sources, including services such as Spamhaus, IPinfo, MaxMind GeoLite2, IP2Proxy, FireHOL and others.
What Is the IP-Neighbourhood Effect?
One interesting aspect of Scamalytics is its use of network-neighbourhood intelligence.
Imagine that one IP address has been repeatedly associated with confirmed fraudulent activity.
Instead of treating that address as completely isolated, Scamalytics can consider related infrastructure such as its subnet, ASN, or hosting environment.
This can help identify patterns before every individual IP has accumulated its own history.
At the same time, it creates an important limitation.
An IP can share infrastructure with legitimate users. Therefore, network reputation can indicate infrastructure risk without proving individual intent.
This is why businesses should combine the result with other information rather than automatically treating every high score as malicious.
Scamalytics vs. a Traditional IP Blacklist
A basic IP blacklist usually answers a relatively simple question:
“Has this IP been reported as malicious?”
Scamalytics attempts to provide a broader risk assessment.
Instead of relying exclusively on a yes-or-no blacklist result, it can combine fraud intelligence with network characteristics and other IP-related signals.
That distinction can be particularly useful when dealing with:
- Newly observed addresses
- VPN traffic
- Proxy connections
- Datacenter IPs
- Hosting providers
- Automated traffic
- Suspicious account creation
- Fraudulent infrastructure
A blacklist can therefore be one component of a security process, while an IP-risk platform can provide additional context.
Can Scamalytics Detect VPNs and Proxies?

Yes.
VPN and proxy detection is one of the types of information available through Scamalytics’ IP intelligence.
Its current product documentation describes detection for VPNs, proxies and Tor, along with indicators for datacenter infrastructure and services such as Amazon AWS, Google Cloud and Apple’s iCloud Private Relay.
This information can be useful because anonymisation itself is not necessarily fraudulent.
For example, someone may use a VPN for legitimate privacy reasons.
A fraud system should therefore distinguish between:
“This connection uses a VPN.”
and
“This connection is definitely fraudulent.”
Those are very different conclusions.
How Businesses Use Scamalytics
The platform is primarily useful when IP intelligence needs to become part of a larger fraud-detection workflow.
Account Registration
A website can evaluate a connection when a new account is created.
A high-risk result could lead to additional verification rather than immediate rejection.
Login Protection
Businesses can examine the network behind login attempts to identify unusual or potentially risky connections.
Payment Screening
An IP risk signal can be combined with payment information, account history and other indicators when evaluating transactions.
Marketplace Protection
Marketplaces can use network intelligence when investigating suspicious buyers, sellers, automated accounts or unusual activity.
Identity Verification
IP information can provide another contextual signal during identity and account-verification processes.
Dating and Romance-Fraud Detection
Scamalytics also highlights applications involving dating platforms and romance scams. The company describes a separate user-fraud capability that combines multiple data points and shared intelligence rather than relying solely on IP addresses.
Scamalytics API
For businesses that need automated checks, Scamalytics provides an IP Fraud Risk API.
The company says its API is designed to respond in 50 milliseconds or less, with API infrastructure in Europe and the United States.
An automated integration can make it possible to check IP risk during workflows such as:
- A user creates an account.
- The application identifies the IP address.
- The IP is checked.
- The result is combined with other risk signals.
- The system decides whether to allow, challenge or investigate the activity.
This is considerably more useful for businesses than manually checking individual addresses.
What Is the Scamalytics MMDB?
Scamalytics also provides an on-premises MMDB option.
Instead of sending individual IP lookups to an external service, organisations can maintain the database within their own infrastructure.
According to Scamalytics, the on-premises option is intended for organisations with requirements such as high-volume processing or data-residency concerns. The database is updated daily.
This can be especially relevant to organisations that need large numbers of lookups without relying on a network request for every individual check.
What Is Scamalytics Bulk Lookup?
Not every organisation needs an API integration.
For analysts and investigators working with large datasets, Scamalytics offers bulk IP lookup functionality.
The company says users can upload CSV or TXT files containing IP addresses and receive enriched results containing fraud scores and other IP intelligence.
This can be useful for:
- Fraud investigations
- Security analysis
- Historical traffic reviews
- Large IP datasets
- Abuse investigations
- Risk-team research
Is Scamalytics Free?
Scamalytics offers a free usage tier, while larger requirements are handled through paid plans and additional commercial options.
Its current product information states that the Essential offering includes 5,000 free credits per month, with additional paid capabilities available depending on requirements.
Pricing and commercial terms can change, so businesses should check the official pricing information before making purchasing decisions.
Does a High Scamalytics Score Mean an IP Is Dangerous?
Not necessarily.
A high score means that Scamalytics considers traffic associated with that IP to have elevated fraud risk based on the information available to its system.
It does not prove that:
- The IP owner is a criminal
- Every user behind the IP is fraudulent
- The computer is infected
- The address will always remain high-risk
- A legitimate customer should automatically be blocked
For example, a shared hosting environment can contain both legitimate and abusive activity.
Similarly, VPN users may receive elevated risk assessments even when they are simply trying to protect their privacy.
The safest approach is therefore to treat the score as one security signal among several.
What Should Businesses Do With a High Score?
Instead of automatically blocking every high-risk connection, a business can create graduated responses.
For example:
Low risk:
Allow the user to continue normally.
Medium risk:
Request CAPTCHA or additional verification.
High risk:
Require stronger authentication.
Very high risk:
Send the activity for manual review or temporarily block it.
The correct threshold depends on the business and its historical fraud data. Scamalytics itself recommends adapting the thresholds rather than treating the published ranges as rigid rules.
What Other Signals Should Be Used?
An IP score becomes much more useful when combined with independent signals.
A fraud team might also examine:
- Account age
- Device information
- Payment history
- Previous chargebacks
- Login frequency
- Email reputation
- Transaction size
- Behavioural patterns
- Identity-verification results
- Geographic consistency
For example, a high-risk IP combined with a newly created account, unusual payment behaviour and suspicious device activity is more concerning than the IP score by itself.
This layered approach helps reduce false positives.
Does Scamalytics Store the IP Addresses You Submit?
According to Scamalytics, its API does not log API calls or store IP addresses submitted by customers. The company says lookups are processed in real time and the submitted information is discarded immediately afterward.
Businesses should nevertheless review the provider’s current privacy documentation and contractual terms before processing personal data, particularly when operating under specific regulatory requirements.
What Are the Limitations of Scamalytics?
No IP intelligence service can see the entire internet.
Scamalytics itself notes that its fraud-detection network has visibility into millions of internet users each month rather than every internet connection worldwide. Its individual IP and ISP pages also make clear that results reflect the traffic visible to its network.
There are several practical limitations to keep in mind:
Shared IP Addresses
One IP can represent many legitimate users.
VPNs
Privacy-focused users can share infrastructure with other users.
Dynamic IPs
An IP address may be reassigned over time.
Cloud and Hosting Infrastructure
Datacenter addresses can host both legitimate and abusive services.
Incomplete Visibility
No provider has perfect visibility into all internet activity.
For these reasons, Scamalytics should be used as part of a broader risk-management strategy.
Scamalytics in Real-World Investigations
Scamalytics’ data has also appeared in wider investigations of online fraud.
For example, a recent Associated Press investigation into global scam operations used Scamalytics data to help identify the organisations associated with IP addresses and assess potential risk indicators. The investigation also emphasized that these scores are indicators of potential risk rather than definitive proof of fraud.
That distinction reinforces the most important lesson about the platform: risk intelligence is valuable precisely because it provides evidence that can be combined with other evidence.
Who Can Benefit From Scamalytics?
Scamalytics is most relevant to organisations that need to make automated or investigative decisions about internet traffic.
Potential users include:
- Banks
- Fintech companies
- Payment processors
- E-commerce platforms
- Marketplaces
- Dating services
- Social networks
- Identity-verification providers
- Fraud-investigation teams
- Cybersecurity teams
- Online businesses with account systems
For an ordinary internet user, the online IP checker can be useful for understanding what information a particular IP address is associated with.
For businesses, the API, bulk lookup and MMDB products provide more scalable options.
Frequently Asked Questions
1. What is Scamalytics used for?
Scamalytics is used to assess IP and network-related fraud risk. Businesses can use its intelligence to identify potentially suspicious connections and combine those signals with their own fraud-prevention systems.
2. Is Scamalytics a scam?
No. Scamalytics is a fraud-prevention technology company that provides IP risk intelligence and related security products. Its official website offers IP checking, API, bulk lookup and MMDB services.
3. What does a Scamalytics score of 0 mean?
A score of 0 represents no known fraud risk in the information available to Scamalytics. It does not mean that an IP can never be used for fraudulent activity.
4. What does a score of 100 mean?
A score of 100 represents the highest end of Scamalytics’ fraud-risk scale. It indicates very high observed risk, but it still should not automatically be interpreted as proof that every person using that IP is fraudulent.
5. Can Scamalytics identify a person?
An IP risk service does not automatically identify the individual using an IP address. An IP can be shared by many users, particularly through corporate networks, VPNs, mobile networks and other shared infrastructure.
6. Does Scamalytics detect VPNs?
Yes. Its current IP intelligence includes VPN, proxy and Tor detection, along with other network and hosting indicators.
7. Can businesses integrate Scamalytics into their websites?
Yes. Scamalytics provides an API designed for automated IP-risk checks, as well as bulk lookup and on-premises MMDB options.
8. Is a high Scamalytics score always bad?
No. A high score should generally be treated as a reason for additional scrutiny rather than automatic proof of malicious behaviour.
Final Verdict: Is Scamalytics Useful?
Scamalytics is best understood as an IP fraud-intelligence layer, rather than a universal tool that can definitively label people as scammers. Its value comes from combining network-level fraud intelligence with information such as ISP reputation, proxy and VPN detection, geolocation, hosting indicators and external data sources.
For businesses, this information can become an additional layer in account protection, payment screening, fraud investigation and abuse prevention. For individual users researching an IP address, the most important takeaway is simple: A Scamalytics score indicates risk associated with network traffic; it does not automatically tell you who is behind the connection or prove that a specific person is a scammer. That distinction makes the service much more useful—and much less likely to be misunderstood—when its results are interpreted alongside other security and behavioural signals.