Skip to content
MyIP.dog

IP reputation check

Check two named threat feeds. See the evidence, its age and its limits before deciding what to investigate.

Your address is checked on our server against cached CINS Army and Emerging Threats public files. We do not send the checked address to either publisher or connect to it.

Shared files refresh at most hourly, with a 15-minute retry delay on failure. Source age limits: CINS Army 48 hours; Emerging Threats 7 days. File dates do not identify when abuse occurred.

Enter an address to compare the two feeds.

Make sense of your result

Understand an IP reputation check

An IP reputation check helps you investigate whether a public address appears in a named threat feed. It is useful when a connection is blocked, a server behaves unexpectedly, or you want context before reviewing an abuse report. The IP reputation check result is evidence from a particular source at a particular time. It cannot certify a person, device or connection as trustworthy.

This IP reputation check compares two public files: CINS Army and Emerging Threats Compromised IPs. In an IP reputation check, each source gets its own result, file date and download date. We avoid combining these observations into a numerical risk score because the files do not provide calibrated probabilities. The names of the lists are not interchangeable with a diagnosis of your current device.

Start with a specific question

Before running an IP reputation check, identify the address involved in the event. A website’s address, your outbound connection address and your mail server’s address may differ. Copy the address from the relevant connection log or use the homepage to identify the public address seen by this website. When interpreting an IP reputation check, remember that a VPN can change the address visible to different services.

An IP reputation check is most useful alongside a timestamp and a concrete symptom. For example, note when a login was refused or which server received suspicious traffic. Your IP reputation check can then compare the right source snapshot with the event. Do not include passwords, account recovery links or private customer information in a report about an address.

How to use this IP reputation check

Enter one public IPv4 or IPv6 address, without a URL, port or network prefix. The IP reputation check validates and normalizes the address before sending a request. Private, loopback and documentation addresses are rejected because they cannot identify a public source in these lists. An IPv4 address embedded in IPv6 notation is normalized to its IPv4 identity.

Select Use my IP to fill the address observed by this website. This does not start the IP reputation check automatically. For your IP reputation check, review the field before submitting, particularly when switching VPNs, networks or devices. The example button fills a public resolver address for learning the workflow; an example does not imply endorsement or a permanently clean result.

Press Check reputation to compare the address with both cached files. This IP reputation check does not scan the target, open ports, attempt a login or contact the entered address. For this IP reputation check, our server downloads the complete public files separately from visitor lookups. The publishers receive those file requests rather than the individual addresses visitors submit.

You can stop an IP reputation check while it runs, edit the input to discard the previous result, or clear the form. A shared source refresh may finish for other visitors after you stop your own request. This IP reputation check has no account history or background monitoring feature. Copying a report deliberately includes the checked address, so review it before sharing.

Read each result independently

A Listed in this snapshot result means the exact IPv4 address appears in that source’s usable file. This IP reputation check shows an exact match rather than extending a listing to adjacent addresses, a whole provider or an entire country. An IP reputation check match deserves investigation, but it does not prove that the current user caused the activity behind the listing.

A Not listed in this snapshot result means the address was absent from a supported, sufficiently recent file. An IP reputation check cannot turn that absence into a guarantee. A source may not observe a particular network, may omit an incident or may remove an address. Newly assigned addresses and newly detected activity also create timing differences.

An Address family not covered result indicates that the selected file covers IPv4 while your input is IPv6. This IP reputation check accepts IPv6 so it can explain the limitation honestly. It does not substitute a nearby IPv4 address or infer a negative result. Different versions can follow different routes and belong to different operational systems.

A Source too old result means the file exceeds our stated age limit. The IP reputation check withholds membership verdicts in that state, including an old positive match. Source details remain available so you can see why the result is unknown. An expired file is not an empty file and is not evidence that a listed problem disappeared.

A Source unavailable result means no usable snapshot could be obtained. This IP reputation check preserves a distinction between a failed request and a negative membership result. If a refresh fails but a previous file remains within the age limit, it can still supply a result with a visible refresh warning. Treat the warning as part of the evidence.

CINS Army: the scope of its public list

The CINS Army portion of this IP reputation check uses the publisher’s public subset of CINS threat intelligence. Its documented criteria involve observations from Sentinel systems and source scoring. The public file contains addresses, not the full private intelligence product, detailed incident narratives or individualized scores. We do not claim access to those additional fields.

When CINS Army produces a match, use the IP reputation check to record the source and date before investigating your own logs. A previous subscriber, a shared exit or an abused server may explain a listing, but these are hypotheses to verify. We cannot determine the explanation from a row in the file or identify a responsible person.

Emerging Threats: a second source with distinct limits

The Emerging Threats portion of this IP reputation check uses its Compromised IPs file. The publisher’s community licensing explanation identifies third-party contributions and GPL version 2 availability. Its plain address file does not provide an incident timestamp, confidence score or attack category for each entry. For the IP reputation check, those missing details remain unknown in the result.

Agreement between sources adds context to an IP reputation check, but it does not establish statistical independence. Publishers may observe overlapping activity or draw on related reports. Disagreement is also possible because of different collection methods and removal schedules. Within an IP reputation check, keep each observation separate instead of treating two listings as twice the probability of malicious behavior.

Understand the dates and content fingerprint

This IP reputation check shows Source file modified, taken from the download’s HTTP Last-Modified header. It describes the file, not when a particular address was observed engaging in abuse. The Downloaded time records when our service retrieved that file. Neither timestamp should be presented as the exact start or end of an incident.

Source details in the IP reputation check include the number of unique addresses, supported address family and a SHA-256 fingerprint of the downloaded UTF-8 text. An IP reputation check fingerprint identifies file content for comparison. It is not a publisher signature and does not independently authenticate the underlying observations. The source link opens the publisher’s current file, which may have changed.

Shared files refresh at most once per hour. After a failed refresh, the IP reputation check waits at least fifteen minutes before another source attempt. Our freshness limits are forty-eight hours for CINS Army and seven days for Emerging Threats. These are this service’s operational limits, not promised publisher schedules or statements that every entry remains active that long.

What this IP reputation check cannot establish

An IP reputation check is not a malware scan of your device. A compromised machine may use an unlisted address, while an address in a feed may have been reassigned or remediated. To investigate a device, review security alerts, updates, account activity and endpoint protections. Use competent incident-response support when you have evidence of an actual compromise.

The IP reputation check also does not establish whether an address is residential, hosted, a VPN or a Tor exit. Those are separate network classifications. Our proxy checker presents named range and exit observations with their own limitations. Using privacy software is not itself evidence of abuse, and hosting infrastructure supports many legitimate services.

For email delivery, complement the IP reputation check with the mail blacklist checker. Mail-oriented lists use different policies and evidence. A delivery failure may instead involve authentication, sending practices, recipient policy or configuration. Preserve the actual rejection message and inspect the sending server’s address before assuming a general threat feed caused the problem.

Geographic information is another separate question. An IP reputation check does not locate a person or verify a street address. Registration, routing and approximate geolocation may offer context, but they do not establish who performed an action. Shared gateways and carrier networks can represent many subscribers behind one public address at the same time.

Investigate a listing without making assumptions

After a positive IP reputation check, confirm the address and event time against your own records. Determine whether you control the address, rent it from a provider or share it with other users. Review outbound traffic and service logs within your authorization. Avoid testing or scanning someone else’s infrastructure simply because a public file contains an address.

Save the IP reputation check report if you need to compare a later result. Include only information needed by your hosting provider or security team. If you request a correction, follow the publisher’s contact and removal process and provide relevant evidence of remediation or reassignment. Our website cannot remove an entry from either publisher’s list or promise a response time.

If the IP reputation check returns unknown, first inspect the source date and coverage. Retrying continuously will not bypass shared refresh limits. A genuinely urgent incident requires your own telemetry and appropriate security response. An unavailable public feed should neither delay a response to strong local evidence nor create a new accusation without supporting facts.

Common IP reputation check questions

Why can another service show a different answer?

Another IP reputation check may use paid reports, different sensors, mail lists or proprietary scoring. Compare the named datasets, dates and address families before comparing conclusions. A red badge with no supporting information offers less context than a specific dated observation. We disclose the limited feeds used here rather than claiming comprehensive coverage of every reputation provider.

Can changing my public address solve a listing?

A new address can change an IP reputation check result, but it does not repair a compromised device, stolen account or insecure service. Fix the underlying cause where evidence supports one. Providers also reassign addresses over time, so a listing can predate the current subscriber. Record reassignment evidence instead of assuming either innocence or responsibility from the address alone.

Is an unlisted address safe to allow automatically?

No. An IP reputation check should support a broader decision that includes authentication, behavior, least privilege and operational context. Automatically allowing every unlisted address creates a gap in protection. Automatically blocking every listed address can disrupt legitimate users. Choose controls appropriate to your service and provide a way to review mistaken restrictions.

How is my input handled?

The IP reputation check sends the entered address to our service over HTTPS for matching. The catalog stores public source data and refresh state, not a visitor lookup history. Results are not placed in the URL, browser storage or a shared response cache. Hosting infrastructure still processes requests; see the privacy policy for the wider data flow.

Where can I verify the method and sources?

The IP reputation check follows our testing methodology and source documentation. Read CINS Army’s explanation, the Emerging Threats licensing clarification, and our dataset notices. These links explain provenance and reuse terms; they do not imply that either publisher endorses this website.