SHOWMYIP threat score
A single 0–100 number, plus a reasons[] array so you always know why. Weighted across Tor, blocklists, and network type.
Everything SHOWMYIP returns for an address — geolocation, network owner, reputation, and an explainable risk score — built on open data we ingest into our own database.
A single 0–100 number, plus a reasons[] array so you always know why. Weighted across Tor, blocklists, and network type.
Country, region, city and coordinates for any IPv4/IPv6 address, shown on a map. Served from our own DB — no per-request calls to third parties.
The autonomous system number and the organization that owns the range — ISP, hosting provider, or enterprise.
Tor exit nodes and FireHOL Level 1 blocklists, refreshed automatically. We show which lists an IP appears on, not just a yes/no.
We flag cloud and hosting networks from the ASN — the addresses least likely to be a genuine residential visitor.
Bearer-token auth, per-plan quotas + rate limits, usage headers, developer docs, multiple named keys, and live usage charts.
Every lookup is resolved against our database and the score is computed from weighted signals — Tor membership, the number of threat-list hits, and whether the network is a datacenter. The result is always returned with the contributing reasons, so it's auditable rather than a mystery number.
Data sources today: DB-IP City & ASN Lite (city-level geo + coordinates + network owner), Tor exit nodes, and FireHOL Level 1, plus live reverse DNS — all ingested into our own PostgreSQL and refreshed on a schedule. Proxy/VPN detection and DNSBL checks are on the roadmap.
Free to start — 30,000 lookups a month, no card required.
Create your free account