IP Reputation: Where It Comes From and Why It Makes It Easy to Block Real People

IP reputation is an estimate of how far an address can be trusted based on its past: what came from it, who owns it and which network it lives in. It is a strong signal for traffic filtering, but it has blind spots worth knowing before you block anything.

Bots and Fraud11 min read
IP Reputation: Where It Comes From and Why It Makes It Easy to Block Real People
Contents
  1. What is IP reputation
  2. Where bad IP lists come from
  3. ASNs and subnets: reputation is not only about the address
  4. Shared IPs: why one address is not one person
  5. The risk of blocking real people: where IP reputation gets it wrong
  6. How IP reputation works in ArtisanClo
  7. Three visits: how IP reputation affects the decision
  8. Practical recommendations
  9. Bottom line

Every visit arrives with an IP address, and you can learn a lot about it before the browser runs a single line of script: who owns it, which country it is registered in, which network it belongs to and what came from it before. Together this is called IP reputation. Below we break down what it consists of, where bad IP lists come from, and where using them turns from protection into losing buyers.

This is about the reputation of the addresses of your ads' visitors — how a filter evaluates incoming traffic.

What is IP reputation

IP reputation is an estimate of how far a visit from a specific address can be trusted, based on its history and ownership. It is made up of several layers:

Layer Question Example verdict
Ownership Who owns the address and what kind of network is it? Hosting provider, home ISP, mobile carrier
History What has been seen from this address before? Spam, scanning, bots, ad reviews
Neighborhood How do neighboring addresses in the subnet and network behave? The whole subnet is rented out as proxies
Freshness When was the last event? Yesterday — significant; a year ago — barely

Reputation is not a binary good or bad but a degree of trust. It works well as one of the signals and poorly as the only one.

Where bad IP lists come from

Sources of IP reputation data vary widely in accuracy and purpose.

Public abuse lists

The oldest are anti-spam lists (often called DNSBLs): mail servers check senders against them. There are also lists of addresses seen in attacks, port scanning and password brute-forcing. They are publicly available but built for other tasks: an address that sent spam is not necessarily an ad bot, and vice versa.

Honeypots and sensors

Special decoy servers no human should ever visit. Everything that arrives there is automation. This data is accurate about scanners and bots but says little about ad fraud.

Commercial IP intelligence databases

Services that collect information about every address: owner, network type, VPN, proxy, hosting and Tor flags, sometimes a risk score. This is the main source for anti-fraud. How such data is used to detect VPNs and proxies is covered in the article on VPNs, proxies and data center IPs.

The protection service's own observations

The most valuable layer for advertising: addresses where the filtering service caught a bot, an automated browser, an ad platform reviewer or a spy service itself. This data is created precisely for the task — telling reviews and automation apart from a real ad visitor.

Your own blacklist

Addresses you added yourself: a competitor, your own test devices, a persistent bot. How to maintain one is covered in the article on IP blacklists in affiliate marketing.

ASNs and subnets: reputation is not only about the address

A single address is a small unit. It is often more useful to look at the group it belongs to.

An ASN (autonomous system number) identifies a network run by one organization: an ISP, a hosting company, a cloud, a large enterprise. The ASN tells you who owns the address, and it is one of the most reliable signals: a cloud hosting network stays a hosting network, whatever address in it a visit comes from.

A subnet is a range of neighboring addresses, usually written in CIDR notation, for example 203.0.113.0/24, which is 256 addresses. Providers hand out addresses in blocks, and neighboring addresses often belong to the same customer — for example, a proxy service that rented the whole block.

Network- and subnet-level reputation is useful for:

  • data center addresses — a real news reader does not browse from a cloud server;
  • proxy service addresses — they are rented in blocks, and a flagged part of a block says something about its neighbors;
  • platform reviewers, who come from specific networks.

And it is harmful when the network is an ISP for people: blocking the ASN of a large mobile carrier blocks millions of subscribers.

Shared IPs: why one address is not one person

The main trap of IP reputation is assuming one visitor stands behind an address. Often that is not true.

Mobile carriers and CGNAT

IPv4 addresses are scarce, so providers use CGNAT (Carrier-Grade NAT): many subscribers go online through one external address. For mobile carriers this is almost standard. As a result:

  • hundreds or thousands of people sit behind one IP at the same time;
  • a subscriber's address changes on reconnecting, moving between cell towers or toggling airplane mode;
  • if even one subscriber behind that address is infected or runs a bot, the address gets spoiled for everyone.

Dynamic home addresses

Many home ISPs assign addresses temporarily. Today it belongs to one subscriber, next week to another. A record saying «a bot came from this address» quickly loses meaning.

Shared networks

Offices, universities, hotels and cafes with Wi-Fi put people online through one or a few addresses. Dozens of clicks from one IP in a place like that is normal.

Privacy services

Address-hiding features built into browsers and operating systems route traffic through shared relays. The user is an ordinary person, but their address looks like the service's.

Tip. Before blocking an address or subnet, check whose network it is. If it is a mobile carrier or a large home ISP, the block will almost certainly hit random people, while the bot will reconnect from another address within a minute.

The risk of blocking real people: where IP reputation gets it wrong

A reputation filter fails in predictable ways. Typical cases:

  1. Inherited reputation. The address ended up on a list because of a previous owner or a CGNAT neighbor.
  2. Stale records. Lists without expiry pile up addresses for years, and the false positive rate grows.
  3. The wrong context. A list built for email spam is applied to ad traffic, where its accuracy is different.
  4. Overly broad blocks. Blocking an entire subnet cuts all of its customers, not just the culprit.
  5. A hard block instead of a score. One weak signal and the visit is cut, even though everything else points to a real person.

Hence the practical rules:

  • separate networks by type: reputation for data centers can be kept for a long time, for home and mobile addresses only briefly;
  • only add proven cases to shared lists: a confidently caught bot or reviewer, not just a dubious network;
  • use reputation in a trust score: a weak signal adds a penalty, and the decision is made on the sum of signals;
  • watch the pass rate not as a verdict but as a breakage signal. A high pass rate for traffic with a verified click ID is normal. It is alarming when almost no one reaches the offer: that means the rules are cutting real people.

How to recognize automation by signals other than the address is covered in the articles signs of bot traffic and headless browsers and browser fingerprinting.

How IP reputation works in ArtisanClo

In ArtisanClo address reputation is taken into account at several levels, each with its own strictness.

  • Shared bot list. If an ad verification service, a platform preview robot, a program instead of a browser or a browser robot with proven signs is confidently identified at any customer, the address is remembered across the whole service. Its next visit to any flow gets the White Page immediately, with the reason «Known bot address» in the log. Real visitors with a dubious network, a VPN or no JavaScript are never added to this list.
  • Expiry by network type. Data center and hosting addresses stay on the shared list practically indefinitely, home and mobile ones for 14 days: such an address quickly passes to another subscriber.
  • Shared IP blacklist. An address caught on automation at several customers at once is added to the shared IP blacklist within an hour.
  • Your blacklist. IPv4 and IPv6 addresses and subnets in CIDR notation; subnets wider than /8 for IPv4 and /16 for IPv6 are not accepted, since a block that broad almost always hits people. The list applies only to your account.
  • The network in the trust score. VPN, proxy, data center, IPv6 or a visit without an ISP is not necessarily an instant rejection: the signals add up to a trust score, and the visit goes to the White Page only if too much suspicious evidence accumulates. The «Strict» level makes these signals weigh more; «Soft» keeps only the blacklists and obvious bots.
  • Networks and providers in Audience rules from the Professional plan: you can allow or block specific ASNs and providers for an individual flow.
  • The flow's IP whitelist. Your own addresses and subnets for test clicks pass without checks, including bypassing the shared bot list.
  • The click card. In the click log every visit shows its network — provider and VPN, proxy and data center flags — and the reason for the decision.

Connection works as usual: a JS tag or a PHP file on your server. More on the ArtisanClo features page.

Three visits: how IP reputation affects the decision

To make it concrete, let us look at three hypothetical visits to the same flow.

Visit 1. A cloud hosting address. The network belongs to a cloud server provider, and the browser claims to be a regular mobile one. A real reader does not go online like that: a phone does not connect to the internet through a data center. The network check cuts the visit at the very first step, before the browser check — the cheapest and most accurate filtering there is.

Visit 2. A mobile carrier, the address is on someone else's spam list. The address belongs to a large mobile carrier and sits behind CGNAT. A week ago one of the subscribers behind it was sending spam. If you block hard on such a list, you will cut a random person on their phone. It is better to treat the record as a weak signal and look at the rest: the browser, JavaScript, the ad click ID. If everything checks out, the visit should go through.

Visit 3. A home ISP, the address was caught on automation yesterday. Yesterday a windowless browser with clear signs of program control came from this address. Today there is another visit. Here the history matters: a day has passed, and the address most likely still belongs to the same owner. But in a couple of weeks that record should expire — the address may move to another subscriber.

In all three cases, what decides is not a single bad IP but the network type, freshness and how well-proven the record is, together with the visit's other signals.

Practical recommendations

  1. Block by network type, not blindly by third-party lists. A data center is a strong signal; a home or mobile address is a weak one.
  2. Do not block mobile carrier subnets. Even if a bot came from there, the next click from those addresses will most likely be a person.
  3. Let records expire. A week-old reputation record for a home address means almost nothing.
  4. Check the consequences. Before tightening rules, see how many conversions came from addresses the new rule would have cut.
  5. Investigate disputed clicks. If a buyer complains they cannot see the offer, find their visit in the log and look at the reason — it is faster than guessing.

Bottom line

IP reputation is a strong but blunt signal. Data center addresses and confidently caught bots can be cut without hesitation; home and mobile addresses, especially behind CGNAT, need care: thousands of people can sit behind one IP, and an address changes owners within hours. Use reputation as part of a trust score, keep records according to network type and let them expire — then the filter cuts automation without hitting buyers. The overall approach to traffic protection is collected in the article on how to filter bot traffic.

Frequently asked questions

01

What is IP reputation?

It is a trust rating for an address built from its history and ownership: whether spam, attacks, bots or reviews have been seen from it, and whether it belongs to a data center, a mobile carrier or a home ISP. The more negative records and the more recent they are, the lower the trust in a visit from that address.

02

How do I check the reputation of an IP address?

Look up the address owner and its ASN, the network type (hosting, home ISP, mobile carrier) and whether the address appears in public abuse lists. For ad traffic filtering it is more practical when a protection service does this automatically on every visit and shows the verdict in the click card.

03

Can a real person have an IP with a bad reputation?

Yes, and fairly often. Mobile carriers and many home ISPs put hundreds or thousands of subscribers online through shared addresses. If one of them is infected or runs a bot, the bad reputation falls on everyone else, even though they had nothing to do with it.

04

What is CGNAT?

Carrier-Grade NAT is a technology that lets a provider put many subscribers online through a single external address. Providers use it to save scarce IPv4 addresses. For filtering, it means one IP is not one person, and blocking an address can hit many people at once.

05

How long does a bad IP reputation last?

It depends on the network. A hosting address belongs to the same owner for years, so its reputation changes slowly. A home or mobile address passes from subscriber to subscriber within hours or days, so an old record about it quickly loses meaning and should expire.

Read next

See your traffic for real

Connect ArtisanClo to your site, see who actually arrives from your ads, and why every click got its decision.