IP threat intelligence glossary

Plain-language definitions of the terms behind IP scoring, reputation, and monitoring.

Abuse contact

The email address a network operator publishes to receive reports of malicious activity coming from their IP ranges. It is registered in WHOIS records and is the standard channel for reporting spam, scanning, or attacks originating from an address.

Allowlist / Denylist

Two complementary access-control approaches. An allowlist permits only the IPs it names and blocks everything else; a denylist blocks the IPs it names and permits everything else. Modern threat scoring replaces static lists with dynamic reputation, but both remain useful for known-good and known-bad addresses.

Anonymizers

One of the four risk categories a lookup can flag: traffic that hides or disguises where it is really coming from. It covers a proxy relay, a datacenter address, and impossible travel — the same account or session authenticating from two locations too far apart to have travelled between in the time elapsed.

ASN (Autonomous System Number)

A globally unique number identifying an autonomous system — a network of IP ranges under a single administrative authority, such as an ISP or a cloud provider. Grouping traffic by ASN reveals whether an address belongs to a residential provider, a hosting company, or a known abusive network.

Botnet

A network of compromised devices controlled remotely by an attacker, often used for credential stuffing, scraping, or distributed denial-of-service attacks. IPs participating in a botnet share behavioural patterns that raise their threat score.

CIDR

Classless Inter-Domain Routing — the notation for describing a block of IP addresses as a base address plus a prefix length, for example 203.0.113.0/24. It is how networks and reputation systems reason about ranges rather than individual addresses.

Datacenter IP

An address that belongs to a hosting or cloud provider rather than a consumer ISP. Legitimate residential users rarely browse from datacenter ranges, so these addresses carry a higher baseline risk and are common sources of proxies, scrapers, and automated traffic.

Detected Bots

One of the four risk categories a lookup can flag: automated traffic identified by behaviour rather than a known signature, ranging from a simple bot or scraper through device farms and PPC (pay-per-click) ad fraud to a sophisticated bot built specifically to evade detection. It flags automation by behaviour; Known Bots flags it by identity instead.

Geofencing

Allowing or blocking traffic based on the geographic location an IP resolves to. It is used for regulatory compliance, licensing, and fraud reduction — for example, refusing logins from countries where a business has no customers.

GeoIP

The mapping of an IP address to an approximate physical location — country, region, and city — inferred from routing data and provider registrations. It is an estimate, not a GPS fix: accuracy is high at the country level and lower at the city level.

IP address

A numeric label assigned to every device on a network, used to route traffic to and from it. IPv4 addresses look like 8.8.8.8, and they are the only ones IP Raccoon scores today — IPv6 is not currently supported. An IP is the primary identifier threat intelligence scores and monitors.

IP reputation

A rolling assessment of how trustworthy an address is, built from its observed behaviour across many networks — spam, scanning, fraud, and abuse reports. Reputation changes over time as an address is seen behaving well or badly, and it feeds directly into the threat score.

Known Bots

One of the four risk categories a lookup can flag: traffic matched against a registry of named, verified automated clients — search engine crawlers such as Googlebot and Bingbot, AI assistants and their crawlers such as GPTBot and ClaudeBot, and SEO or monitoring services such as AhrefsBot and DataDog. It flags automation by identity; Detected Bots flags it by behaviour instead.

Proxy detection

Identifying addresses that relay traffic on behalf of a hidden origin, masking the real client. Proxies are legitimate in many contexts but are also used to evade blocks and geofencing, so detecting them is a key input to risk scoring.

Rate limiting

Capping how many requests an IP may make in a window of time. It blunts brute-force attempts, scraping, and abuse, and the addresses that repeatedly hit limits become strong candidates for a raised threat score.

Reputation

One of the four risk categories a lookup can flag, built from threat reputation feeds and abuse history: whether the address is linked to a known threat actor (attribution), has been reported for abusive behaviour (abuse), or has taken part in active attacks (attacks) — the risk-scoring counterpart to the general concept of IP reputation.

Residential IP

An address assigned by a consumer ISP to a home connection. Residential ranges carry a lower baseline risk than datacenter ranges, which is exactly why abusive actors pay for residential proxy services to blend in with genuine users.

Risk level

A human-readable band — low, medium, high, or critical — derived from the numeric threat score. It lets teams write simple rules ("block critical, challenge high") without tuning against raw numbers.

Threat score

A single number summarising how dangerous an IP is right now, combining reputation, network type, detected proxying, and recent behaviour. IP Raccoon returns a score with a confidence value so you can weigh how much recent evidence supports it.

Tor exit node

The final relay in the Tor anonymity network, where traffic leaves Tor and reaches its destination — so the destination sees the exit node’s IP, not the user’s. Exit nodes are published openly and are frequently flagged because they anonymise both privacy-conscious users and attackers.

VPN detection

Recognising addresses that belong to virtual private network services, which tunnel a user’s traffic through a remote server and hide their real location. Like proxies, VPNs are legitimate but relevant to fraud and geofencing decisions.

WHOIS

The public directory that records who is responsible for an IP range or domain — the owning organisation, its ASN, and its abuse contact. It is the authoritative source for attributing an address to a network operator.