Our data is also available as API and MMDB

Products

Scamalytics delivers IP fraud intelligence to fraud and risk teams at fintechs, banks, payment processors, identity verification providers, adtech platforms, e-commerce businesses, and online platforms. The same proprietary risk signal, a fraud score for every IP address on the internet, is available in three ways: a real-time API for live integrations, a bulk IP lookup tool for investigators who need no coding, and an on-premises MMDB for teams with the highest performance and compliance requirements.

Our proprietary risk score has been in production since 2011, serves 7,500+ users globally, responds in under 50ms via the API, and draws on more than ten integrated data sources.

Risk Score API MMDB Bulk IP Lookups Compare Products

The Scamalytics Risk Score

For over a decade, fraud teams have relied on the Scamalytics score to judge whether a visiting user is likely to be fraudulent or fake.

How the score is built. The Scamalytics score is based on human-sourced fraud feedback collected from a global network of operators who report confirmed fraudulent activity back to Scamalytics. That signal is then propagated across each IP's neighbourhood: neighbouring addresses in the same subnet, ASN, and hosting block. Newly fraudulent IPs adjacent to known-bad ones inherit elevated risk before they have been reported individually. Passive and purely geolocation-based feeds do not include this feedback signal.

A score of 70 means that roughly 7 in 10 users seen from that IP have been associated with fraudulent behaviour. A score of 0 means no known risk. Beyond the score, every lookup returns proxy and anonymisation detection, ISP-level risk, geolocation, and enrichment from more than ten integrated external sources, in a single response.

Suggested actions by score range:

Please note: The thresholds above are a starting point. We recommend calibrating against your own fraud data to balance fraud prevention against customer friction.

IP Fraud Risk API

Our API has been engineered to respond within 50ms or less, with API nodes in Europe and the USA to minimise network latency.

What you get:

Essential Plan and Premium Data Add-Ons. There is one plan: Essential. It includes the full Scamalytics score, ISP-level risk, proxy detection, geolocation, and all open-source enrichment feeds. You can then enable Premium Data Add-Ons on any paid plan to unlock additional commercial data sources.

Included with Essential:

Available as Premium Data Add-Ons on any paid plan:

Full details and prices for each add-on are on our API pricing page.

US and EU nodes available. Code examples in cURL, Python, Node.js, and PHP. A free tier with 5,000 credits per month lets you evaluate in production before committing. See our API pricing for all volume tiers and add-on prices.

Read API documentation Get API access

Privacy: Scamalytics does not log API calls and does not store the IP addresses submitted by customers. Each lookup is processed in real time and discarded immediately.

On-Premises MMDB

For teams with data residency requirements, high-throughput pipelines, or a preference for zero external dependencies at query time, the MMDB option puts the entire Scamalytics database inside your own infrastructure. Lookups run locally, so no IP address is transmitted to Scamalytics, there is no network round-trip, and no rate limit applies.

What you get. The same fraud intelligence available in the API, delivered as a self-hosted database in the industry-standard MMDB format:

The file is updated regularly and delivered to your infrastructure over HTTPS. Updating to the latest data is as simple as switching out the file. No code changes required.

Benefits:

Typical use cases:

Contact us to discuss MMDB access, pricing, and delivery options. We typically respond within 24 hours.

Request MMDB access

Bulk IP Lookups

Fraud risk investigators can upload a CSV or TXT file containing millions of IP addresses, with no coding required, and receive a fully enriched report back within minutes. Every IP is scored and classified with the same data returned by the API, delivered as a CSV ready for review and analysis in any spreadsheet tool.

How it works:

  1. Prepare a CSV or TXT file with a column of IP addresses. No specific formatting is required beyond that.
  2. Upload the file at bulk.scamalytics.com.
  3. Download the enriched CSV once processing is complete. For large files this typically takes a few minutes.

What the enriched CSV contains:

Typical use cases:

Data retention. Enriched reports are stored on Scamalytics servers so you can download them at any time after processing. You can delete a report manually at any point, and all reports are automatically deleted after 30 days. The IP addresses in your uploaded file are not used for any purpose other than generating your report.

Bulk IP Lookups are available to all API account holders at bulk.scamalytics.com, including the free tier.

Go to bulk portal Get an account

Which Product Is Right for You?

All three products run on the same fraud intelligence. Which one suits you depends on how your team works.

Choose the API if you are building live product integrations. Real-time, per-connection checks returned as JSON in under 50ms per lookup, priced on monthly credits, with a free tier of 5,000 credits per month. IP addresses are processed in real time and never logged or stored.

Choose Bulk IP Lookups if you are a fraud investigator or analyst. Batch analysis of millions of IPs per upload with no coding required, delivered in minutes as an enriched CSV. Reports are stored for download, deletable on demand, and automatically deleted after 30 days. Included with every account, including the free tier.

Choose MMDB if you run high volumes, operate under regulation, or need the lowest possible latency. Unlimited on-premises lookups in microseconds for a flat fee, with no data leaving your environment. Contact us for pricing.

If you would like advice on which option suits you best, please contact us.