Scamalytics Explained: How Its IP Fraud Score Detects Risk Before a Scam Reaches Your Platform
One number can change how a website treats a visitor—but what does a Scamalytics score actually reveal about the person behind an IP address?

A suspicious login, a payment attempt from an unusual network, or a new account created through a proxy can look harmless when viewed in isolation. For fraud teams, however, the connection itself can contain useful signals before a user completes a transaction or begins interacting with other customers.
That is where Scamalytics enters the picture. The UK-based fraud-intelligence company provides IP risk scoring, proxy and anonymisation detection, geolocation enrichment, API access, bulk lookups and an on-premises MMDB database designed for organisations that need to assess internet connections at scale. Its products are used across areas including fintech, banking, payments, identity verification, advertising technology, e-commerce and online platforms.
The short answer: what Scamalytics actually does
Scamalytics is an IP fraud-intelligence platform that assigns internet connections a 0–100 fraud-risk score using confirmed fraud feedback, IP-neighbourhood intelligence and additional signals such as proxy, VPN, Tor, ISP and geolocation data. The score helps businesses decide whether a connection should be allowed, challenged, verified or investigated.
Why an IP address can become a fraud signal
An IP address does not identify a person by itself. It identifies a network endpoint, and that distinction matters.
A single IP can represent multiple legitimate users, particularly on mobile networks, corporate networks, universities, public Wi-Fi or shared infrastructure. Conversely, one individual or automated operation can move between many IP addresses.
Scamalytics therefore does not describe its score as proof that a particular person is fraudulent. Its public documentation describes the score as an assessment of the fraud risk associated with traffic observed from an IP address. The company’s own ISP pages also caution that its visibility covers only a portion of internet activity and specifically concerns web connections to websites and applications.
That makes Scamalytics more useful as a risk signal than as a standalone verdict.
The 0–100 Scamalytics Risk Score
The core product is the Scamalytics Risk Score.
According to the company, the score is informed by fraud feedback from a global network of operators reporting confirmed fraudulent activity. Scamalytics then applies intelligence across an IP’s surrounding network neighbourhood, including the same subnet, ASN and hosting block.
Its published interpretation is:
| Score | Scamalytics classification | Suggested response |
|---|---|---|
| 0–19 | Low risk | Generally allow access |
| 20–59 | Medium risk | CAPTCHA or additional verification |
| 60–89 | High risk | Step-up authentication or SMS verification |
| 90–100 | Very high risk | Block or send for manual review |
These are Scamalytics’ suggested starting thresholds rather than universal rules. The company explicitly recommends adjusting decisions according to an organisation’s own fraud data and customer-experience requirements.
What does a Scamalytics score of 70 mean?
This is one of the most frequently misunderstood aspects of the service.
Scamalytics says a score of 70 means approximately 7 out of 10 users seen from that IP address have been linked to fraudulent activity within the company’s observed data. A score of 0 indicates no known fraud risk in its data.
That does not mean:
- the owner of the IP is definitely a scammer;
- every user behind the IP is fraudulent;
- the IP address is permanently malicious;
- the underlying computer has necessarily been compromised;
- a legitimate customer should automatically be banned.
The distinction is especially important for shared networks, VPNs, hosting providers and other environments where many unrelated users can appear behind the same infrastructure.
A responsible fraud system treats the score as one input among several.
What sits behind the score?
Scamalytics combines its proprietary fraud intelligence with additional data sources and network characteristics.
Its current product documentation lists several categories of information returned through its IP Fraud Risk API:
- Scamalytics fraud score from 0–100
- Risk classification
- ISP-level risk
- Proxy detection
- VPN detection
- Tor detection
- Datacentre infrastructure detection
- Apple iCloud Private Relay detection
- Amazon AWS and Google Cloud indicators
- Geolocation information
- IP blacklist information
- ASN and organisation information
- Additional enrichment from more than 10 external sources
The company identifies external sources including MaxMind GeoLite2, IPinfo, Spamhaus DROP, FireHOL, IPsum, IP2Proxy, DB-IP, x4bnet, Google, Amazon AWS and Apple.
This combination is significant because an IP’s reputation is rarely meaningful in isolation.
The IP neighbourhood effect
Scamalytics says its risk intelligence can extend from confirmed fraudulent addresses to nearby addresses within the same subnet, ASN or hosting block. That means an address does not necessarily have to appear in a fraud report individually before it receives an elevated risk assessment.
This approach is designed to capture patterns that a simple blacklist could miss.
It also creates an important limitation: network reputation can describe infrastructure risk rather than prove individual intent.
For fraud teams, that makes contextual verification essential.
Scamalytics versus a simple IP blacklist
A traditional blacklist generally asks a relatively narrow question:
Has this IP been identified as malicious?
Scamalytics attempts to answer a broader question:
How much fraud risk is associated with traffic originating from this IP and its surrounding network environment?
That difference can matter when fraud operations move quickly.
An IP may be newly observed, associated with infrastructure resembling known fraudulent activity, connected to anonymisation services, or located within a network where confirmed fraud has previously been reported.
Scamalytics combines these signals rather than relying solely on a static yes-or-no list.
Three ways businesses can use Scamalytics
Scamalytics currently offers three principal delivery methods for its IP intelligence: API, on-premises MMDB and bulk IP lookup.
1. Real-time API
The API is designed for applications that need an IP decision during a live workflow.
Scamalytics says its IP Fraud Risk API is designed to respond in 50 milliseconds or less, with API nodes in Europe and the United States.
Typical use cases can include:
- account registration;
- login risk assessment;
- payment screening;
- marketplace activity;
- identity verification;
- promotional-abuse detection;
- suspicious account creation;
- automated traffic analysis.
2. On-premises MMDB
The MMDB option is aimed at organisations that want the database inside their own infrastructure.
Scamalytics says its on-premises database enables local lookups, removes network round trips and means IP addresses do not need to be sent to Scamalytics for each lookup. The database is updated daily.
That can be particularly relevant for organisations with high query volumes or stringent data-residency and compliance requirements.
3. Bulk IP Lookups
The bulk service targets fraud analysts and investigators who need to examine large numbers of addresses without building an API integration.
The company says users can upload CSV or TXT files and receive enriched results containing fraud scores, risk classification and additional IP intelligence.
Scamalytics pricing: what is free and what costs money?
Scamalytics currently publishes a tiered pricing structure for its IP Address Fraud Check API and bulk lookup service.
| Monthly lookups | Monthly price |
|---|---|
| 5,000 | Free |
| 25,000 | $25 |
| 50,000 | $50 |
| 100,000 | $100 |
| 250,000 | $125 |
| 500,000 | $150 |
| 1 million | $200 |
| 5 million | $600 |
| 10 million | $1,000 |
| 50 million | $3,000 |
| 100 million | $5,500 |
The published pricing page also lists annual billing discounts and says unused monthly lookups do not carry forward. Higher-volume and custom arrangements are available.
Scamalytics’ product page separately states that accounts receive a 5,000-credit monthly free tier for the Essential offering.
Pricing can change, so businesses evaluating the service should verify the current commercial terms directly with Scamalytics before budgeting or integrating.
What happens when an IP gets a high score?
A high score should normally trigger more scrutiny, not an automatic accusation.
For example, an e-commerce platform could combine the Scamalytics score with:
- account age;
- payment history;
- device fingerprint;
- transaction amount;
- login velocity;
- previous chargebacks;
- email reputation;
- behavioural signals;
- identity-verification results.
A high IP score alongside several independent risk signals may justify stronger verification.
A high IP score attached to a long-standing legitimate customer with a consistent device and payment history may warrant a less aggressive response.
This is why Scamalytics itself presents its score thresholds as starting points rather than fixed rules.
Privacy matters: does Scamalytics store submitted IP addresses?
Scamalytics states that its API does not log API calls or store the IP addresses submitted by customers. It says each lookup is processed in real time and the submitted data is discarded immediately afterwards.
That statement applies to the API lookup process described by the company. Organisations considering the service should still review the current privacy documentation, contractual terms and their own regulatory obligations before processing personal data.
Scamalytics’ current Terms of Service also govern access to its website, SaaS products, API and downloadable datasets. The version currently published is effective from 3 July 2026.
Scamalytics has been operating in fraud prevention for years
Scamalytics says its products have been trusted in production since 2011 and that more than 7,500 users have used its services. Its stated customer sectors include fintech, banks, payment processors, identity-verification providers, adtech, e-commerce and online platforms.
The company also says its technology has received media attention in connection with fraud and online scams. Its website cites appearances or use by organisations including the BBC, Ars Technica, talkRADIO and WIRED.
Earlier Scamalytics material also describes its work in online-dating fraud detection and discusses the value of combining specialist external intelligence with systems operated internally by dating platforms.
A practical Scamalytics decision framework
For businesses considering IP intelligence, the strongest implementation is rarely “score high = block”.
A more defensible workflow looks like this:
- Identify the IP and connection type.
- Check the Scamalytics fraud score.
- Review proxy, VPN, Tor and hosting indicators.
- Consider ISP and ASN reputation.
- Compare geolocation with the user’s expected location.
- Combine the result with account, device and transaction signals.
- Apply an action based on the organisation’s measured fraud tolerance.
- Record outcomes so thresholds can be recalibrated.
This approach reduces the risk of turning a probabilistic security signal into an unnecessarily blunt access-control mechanism.
The bigger lesson behind Scamalytics
The most useful idea behind Scamalytics is not the number itself.
It is the shift from treating an IP address as a technical identifier to treating network infrastructure as one component of a broader fraud signal.
That matters because online fraud increasingly involves infrastructure choices: hosting providers, proxies, VPNs, cloud environments, anonymisation services and reused network resources. Detecting those patterns early can give fraud teams another layer of evidence before a suspicious session becomes a confirmed loss.
But no IP reputation service can see everything. Scamalytics itself states that its network has visibility into many millions of internet users per month rather than the entire internet. Its public ISP pages explicitly frame results as the company’s assessment based on the information available to it.
That limitation is not a weakness unique to Scamalytics. It is a fundamental reason why modern fraud detection works best as a layered system.
Scamalytics FAQ: the questions users actually ask
What is Scamalytics?
Scamalytics is a UK-based fraud-intelligence company that assesses the risk associated with internet connections. Its core products include an IP fraud score, proxy and anonymisation detection, geolocation enrichment, API access, bulk IP lookups and an on-premises MMDB database. Businesses use the intelligence to help detect and prevent fraudulent or suspicious online activity.
What does a Scamalytics score mean?
A Scamalytics score is a 0–100 estimate of fraud risk associated with an IP address based on the company’s observed fraud intelligence. Scamalytics says a score of 70 corresponds to approximately seven in ten users observed from that IP being linked to fraudulent activity. The score should be treated as a risk signal rather than proof that a specific individual is fraudulent.
Is a high Scamalytics score proof that an IP is malicious?
No. A high Scamalytics score indicates elevated observed fraud risk, but it does not establish that every user behind the IP is malicious. Shared networks, hosting providers, VPNs and other infrastructure can be used by legitimate users as well as bad actors. Scamalytics recommends using its published score ranges as starting points and combining them with an organisation’s own fraud signals.
Does Scamalytics detect VPNs and proxies?
Yes. Scamalytics says its IP intelligence includes proxy, VPN and Tor detection, along with indicators for datacentre infrastructure and services such as Apple iCloud Private Relay, Amazon AWS and Google Cloud. Additional premium proxy intelligence is also available through its paid data add-ons.
Is Scamalytics free?
Scamalytics offers a free tier for its IP Address Fraud Check API and bulk lookup service. Its published pricing currently starts at 5,000 monthly lookups for free, while paid plans begin at 25,000 monthly requests for $25. Larger usage tiers and custom agreements are available. Prices should be checked directly with Scamalytics because commercial terms can change.
Who uses Scamalytics?
Scamalytics says its IP intelligence is used by organisations in fintech, banking, payment processing, identity verification, adtech, e-commerce, social platforms and other online services. The company also describes specific applications involving fraud prevention and dating or romance-scam detection.
The final signal is not the final verdict
Scamalytics is best understood as an IP fraud-intelligence layer, not a universal scam detector.
Its strength lies in turning network-level information—fraud feedback, IP neighbourhoods, ISP reputation, anonymisation indicators and external intelligence—into a structured signal that businesses can incorporate into their own decision systems.
The score can help answer an important question early: “Does this connection deserve more scrutiny?”
It cannot, by itself, answer the much harder question: “Is this individual definitely a fraudster?”
That distinction is the line between useful risk intelligence and an unreliable automated accusation.
Sources & Verification
- Scamalytics official website — company overview, products and fraud-detection capabilities.
- Scamalytics IP Fraud Intelligence products — Risk Score methodology, integrations, signals and recommended score ranges.
- Scamalytics API pricing — current published API and bulk-lookup pricing.
- Scamalytics Terms of Service — current service terms, effective 3 July 2026.
- Scamalytics contact page — current UK company contact information.
Editorial Disclaimer
This article is intended for informational and editorial purposes. Scamalytics scores and classifications are risk indicators based on the company’s available data and should not be treated as definitive evidence that a particular person, organisation or device is fraudulent. Product features, pricing, thresholds and policies may change; readers should verify current information directly with Scamalytics before making commercial, technical, security or compliance decisions.



