Current connection / live intelligence

What is my Proxy Score?

See what the internet sees first. Then check another IP, one proxy, or an entire proxy list without leaving the page.

Enter an IP, one proxy, or paste a list. The input adapts automatically.

Proxy credentials stay in request memory, remain masked on screen, and never enter URLs or browser storage.

⌘/Ctrl+Enter

What Proxy Score proves

Current connection first. Real proxy test second.

The automatic card describes the public exit IP visible to the internet. A real operational Proxy Score appears only after the engine connects through a submitted proxy to a controlled signed endpoint.

Read the methodology
  1. 01

    Identify

    Read the current or entered IP's location, ASN, network role and proxy/VPN/Tor evidence through IPBot.

  2. 02

    Test

    For a submitted proxy, verify the public endpoint, credentials, protocol, tunnel and complete route.

  3. 03

    Explain

    Keep operational Proxy Score, exit-IP quality and IP Risk separate, then explain failures and evidence.

Transparent scoring

Three labels that never pretend to be the same thing.

IP Score
IPBot cleanliness score for a normal current or entered IP. Higher means cleaner observed network evidence.
Exit IP Score
The same IPBot cleanliness score when the current connection is classified as proxy-like. It is not a route-performance score.
Proxy Score
A 0–100 point-in-time operational score calculated only after a real proxy completes the route test.
IP Risk
A separate 0–100 evidence-derived risk value where higher is riskier. It is not a fraud probability.

Protocol reference

Four protocols, four different things being proven.

Every row below changes what a passing test actually tells you. A proxy that works for plain HTTP can still fail the moment you need TLS or UDP.

How the four supported proxy protocols differ
PropertyHTTPHTTPS CONNECTSOCKS4 /4aSOCKS5
How it moves trafficForwards an HTTP request with an absolute URLOpens a raw TCP tunnel, then your own TLS runs inside itOpens a raw TCP sessionOpens a raw TCP session
Carries non-HTTP protocolsNoYes, once the tunnel is openYesYes, plus UDP where the server supports it
Proxy can read your payloadYes — plain HTTP passes through itNo — it sees the destination host, not the TLS contentsNo — it relays bytesNo — it relays bytes
AuthenticationProxy-Authorization, usually BasicProxy-Authorization, usually BasicUser ID field only — no passwordUsername/password (RFC 1929) or none
Who resolves the hostnameThe proxyThe proxySOCKS4 resolves locally; SOCKS4a lets the proxy resolveThe proxy, when a domain address type is sent
Can leak your IP in headersYes — X-Forwarded-For, Via and friendsNot inside the tunnelNo header layer existsNo header layer exists
What this checker verifiesAn absolute-URI forward that reaches the controlled probeCONNECT plus a completed TLS handshake to the probeA completed SOCKS4 handshake and route to the probeA completed SOCKS5 handshake, auth and route to the probe
Protocol points in Proxy Score6 of 1010 of 1010 of 1010 of 10

Selecting Auto lets the engine infer the protocol from the row itself, including socks5://-style prefixes. Pick an explicit protocol when a provider issues the same host and port for several modes.

Anonymity

What the destination server actually learns about you.

Elite

20 of 20 anonymity points

No proxy-identifying request headers survive the route, and your originating address is absent. The destination sees the exit IP and nothing that marks the request as proxied.

Anonymous

12 of 20 anonymity points

The proxy announces itself — typically through Via or a proxy-agent header — but does not forward your originating address. The destination knows a proxy is involved and still cannot see you.

Transparent

0 of 20 anonymity points

Your originating address is forwarded, usually in X-Forwarded-For or X-Real-IP. This provides no anonymity at all, though it is perfectly valid for caching or bandwidth use.

Unknown

6 of 20 anonymity points

The route completed but forwarding evidence could not be established for it. Tunnelled protocols have no header layer to inspect, so absence of evidence is scored conservatively rather than as elite.

Failed Proxy Decoder

“Dead” is not a diagnosis.

Every failed row carries one of these stable codes instead of a blank status. The code tells you whether to fix a credential, change a protocol, or drop the endpoint.

The proxy never answered

CONNECT_TIMEOUT

No connection in time

No TCP connection was established before the connection budget expired. Retry once, then remove the proxy if the timeout repeats.

CONNECT_FAILED

Connection refused

The host refused the connection or was unreachable from the test engine. Confirm the host and port before dropping it.

RESOLUTION_FAILED

Hostname did not resolve

DNS returned no usable address for the proxy hostname. Ask the provider for a current endpoint.

NON_PUBLIC_HOST

Private address rejected

The endpoint resolves to a private, loopback or reserved address. This is refused by design — the checker will not scan internal networks.

The credentials or the row were wrong

AUTH_FAILED

Credentials rejected

The endpoint answered and refused the supplied credentials or authentication method. Confirm both the account and the protocol.

AUTH_UNSUPPORTED

Authentication not supported

The protocol cannot carry the credential shape you supplied. Use SOCKS5 for username/password, or drop the password from a SOCKS4 row.

CREDENTIAL_TOO_LONG

Credentials exceed protocol limits

The username or password is longer than the protocol permits. Use the provider-issued value without added metadata.

INVALID_TARGET

Invalid proxy row

The host, port or credential structure could not be parsed. Use host:port, user:pass@host:port or a supported protocol URL.

INVALID_PROTOCOL

Unsupported protocol

The selected protocol is outside HTTP, HTTPS, SOCKS4 and SOCKS5.

The tunnel opened and then broke

TUNNEL_FAILED

Outbound tunnel rejected

The proxy answered but would not open the requested outbound route. Check whether it permits HTTPS or external destinations at all.

TUNNEL_CLOSED

Tunnel closed early

The connection was closed before the diagnostic completed. Repeated early closes mean an unstable or restricted endpoint.

TIMEOUT

Response timed out

The endpoint connected but did not finish within the response budget. Treat it as too slow for latency-sensitive work.

PROBE_TLS_FAILED

TLS through the proxy failed

The tunnel opened but encrypted traffic to the controlled endpoint did not complete. Do not use this proxy for HTTPS workloads.

The route completed but did not prove itself

FORWARD_NOT_PROXY

Not actually a proxy

It accepted an HTTP-shaped request without proving it routed the absolute destination. This is often a web server or a transparent relay.

PROBE_STATUS

Unexpected probe status

The route completed but the controlled endpoint did not return the expected status. Review whether the proxy rewrites responses.

PROBE_INVALID

Probe response was invalid

The response could not prove a valid end-to-end route. Treat the endpoint as unusable unless a clean retry succeeds.

RESPONSE_TOO_LARGE

Response exceeded the limit

The endpoint returned more data than the bounded diagnostic permits. Treat it as misconfigured.

CHECK_FAILED

No narrower class available

The test failed without a more specific failure class. Retry once with the correct protocol before removing it.

Reading the numbers

Which band a number lands in, and what to do about it.

Proxy Score — this live route

Operational Proxy Score bands
RangeBandWhat it means for use
90–100ExcellentFast, tunnel-capable and anonymous in this test. Suitable for latency-sensitive work.
75–89GoodA solid route with one weaker component, usually latency.
55–74UsableIt works, but either the speed or the anonymity level will be noticeable.
35–54WeakCompleted the route with substantial penalties. Keep it as a fallback only.
0–34PoorTechnically reachable and not worth using for real work.

Reachability is worth 35 points on its own, so any completed route starts at 35. That is why a working-but-terrible proxy never scores zero.

IP Risk — the exit address

IP Risk bands
RangeBandWhat it means for use
0–39LowNo material adverse evidence surfaced for this address.
40–69MediumEvidence exists that some policies act on. Expect occasional friction.
70–100HighStrong adverse evidence. Sensitive flows will challenge or block it.

IP Risk is evidence-derived, not a calibrated probability of fraud. A high value says a great deal was observed about the address, not that a person did anything.

Questions

The things people ask after their first result.

Why did my Proxy Score change between two runs of the same proxy?

Because it is a point-in-time measurement, not a rating. Latency alone is worth 35 points and moves with route congestion, engine load and the provider's own rotation. A score that swings by ten points between runs is normal; one that swings by forty is telling you the endpoint is unstable.

The proxy works but shows high IP risk. Which number do I trust?

Both, because they answer different questions. Proxy Score says the route functions. IP Risk says the exit address carries adverse evidence. A fast proxy on a heavily-flagged address is genuinely fast and will still be challenged at a payment page. That combination is reported as “Fast, risky exit” rather than collapsed into one misleading number.

What is the difference between IP Score and IP Risk?

They are two directions of the same evidence set. IP Score rises as the observed evidence looks cleaner; IP Risk rises as adverse evidence accumulates. They are not required to sum to 100 — each is computed from its own components, which the full report breaks out individually.

Can this page detect the proxy configured in my browser?

No, and no site can. A browser visit reveals the public exit address, not the host, port, username or password you configured locally. When the exit address itself carries proxy, VPN, Tor or relay evidence, the page reports that as Current Proxy Detail — but it never invents endpoint fields it cannot observe, and it never shows an operational Proxy Score for a connection it did not test.

Why does my result say “Datacenter” but not “Proxy”?

Because hosting is not proof of proxying. A great deal of ordinary traffic originates from cloud infrastructure. Datacenter evidence is shown as infrastructure context and left out of the proxy verdict unless proxy, VPN, Tor, residential-proxy or privacy-relay evidence is present as well.

What is the proxy header hint, and why do you refuse to trust it?

The Worker reports the names of proxy-style headers observed on your request — never their values. Any intermediary can add, rewrite or fabricate those headers, so they cannot prove anything. They are shown because their presence is genuinely informative, and labelled untrusted because acting on them would be wrong.

Do you store my proxy list or credentials?

No. Submitted rows are held in request memory for the duration of the run. They are never placed in the URL, localStorage, sessionStorage, the Worker cache or an application database, and raw rows and credentials are excluded from operational logs. Reloading the page clears everything.

Why was my proxy rejected with NON_PUBLIC_HOST?

Because it resolved to a private, loopback or reserved address. The engine refuses those by design so the public checker cannot be used to probe internal networks through someone else's server.

What are the limits?

Thirty IP lookups and five proxy runs per minute, up to one hundred rows per run and a 64 KB request body. Duplicate and malformed rows are reported before the run rather than silently consuming budget.

Why does the batch table sometimes disagree with a single check of the same proxy?

Because each row is an independent live route test. Under a batch the endpoint handles concurrent sessions, which is exactly when overloaded or connection-capped proxies reveal themselves. If a proxy passes alone and fails in a batch, that difference is the finding.

Public API

The same endpoints this page calls.

No key, no signup, no separate quota — which also means no guarantees. These are the routes the browser uses, documented so you do not have to read the network tab. Every response is JSON, is sent no-store, and is excluded from indexing.

GET/api/v1/score?ip=<address>

Full intelligence for any public IPv4 or IPv6 address. This is what powers the report on this page, so the response contains every field the board renders — location, network, routing, score, scores, classification, evidence, decision, scenarios and explanation.

GET/api/v1/current

The same payload for the calling connection's own public exit address, plus meta.connection_context: observed proxy-style header names only, never their values, and a bounded set of Cloudflare edge fields.

GET/api/v1/health · /api/v2/proxies/health

Build identifier, schema version and whether each dependency is configured. Neither route performs a lookup, so neither consumes lookup budget.

POST/api/v2/proxies/check

A Server-Sent Events stream. Send {"proxies": "<newline-separated rows>", "settings": {"protocol": "auto"}} and read meta, then one result per row interleaved with progress, ending in a terminal done or error. Each row is a real live route test through the controlled probe — it is the most expensive thing on this site and the most tightly limited.

Limits and headers

Enforced per calling address
LimitValue
IP lookups30 per 60 seconds
Proxy runs5 per 60 seconds
Rows per run100 non-empty rows
Request body65,536 bytes
Keyed onA truncated SHA-256 of CF-Connecting-IP — rotating headers does not evade it
Lookup cache24 hours, dropping to 1 hour for high-risk addresses

Successful lookups carry X-RateLimit-Policy: 30;w=60, X-Proxy-Score-Cache: hit|miss and Server-Timing. Exceeding a limit returns 429 with Retry-After.

Response envelope

{
  "ok": true,
  "data": {
    "ip": "8.8.8.8",
    "stack": "ipv4",
    "location": { "country_code": "US", "city": "…" },
    "network":  { "asn": "AS15169", "org": "Google LLC" },
    "routing":  { "prefix": "8.8.8.0/24", "rpki_status": "valid" },
    "score":    { "ip_score": 88, "risk_score": 12, "band": "excellent" },
    "scores":   { "trust_score": 90, "abuse_score": 0 },
    "classification": { "usage_type": "public_dns_resolver" },
    "evidence": { "signals": [] },
    "decision": { "action": "allow", "risk_level": "low" },
    "scenarios": { "payment": { "action": "allow" } },
    "explanation": { "drivers": [] }
  },
  "meta": {
    "schema_version": "proxy-score-v1-2026-07-30",
    "cache": "hit",
    "source": "IPBot"
  }
}

Errors replace it with {"ok": false, "error": {"code", "message", "request_id"}}. Quote the request_id if you report a problem.

Behaviour worth knowing before you write a client

  • No CORS headers are sent. A browser on another origin cannot call these routes. Call them server-side.
  • GET means GET. Lookup routes reject every other method — including HEAD — with 405 and an Allow header.
  • A trailing slash redirects. /api/v1/health/ answers 308 to the canonical path; follow redirects or drop the slash.
  • Private and reserved addresses are refused on both the lookup and the proxy routes. This is not a network scanner.
  • Nothing is versioned by promise. meta.schema_version tells you what you received; it can change without notice.
  • The quota is shared and metered upstream. Cache what you fetch, do not poll for changes that arrive daily, and do not build a product on an endpoint that offers you no availability commitment.

Credential privacy

Test the proxy, not your trust.

Submitted proxy strings are processed only for the requested run. They are not cached by the Worker, saved in browser storage, placed in the URL, or included in operational logs. Credentials stay masked until you deliberately reveal, copy or export them.

Privacy details

Current connection evidence

Connection details

Proxy detail

Methodology

How current IP and proxy results differ

Proxy Score separates network intelligence that can be observed from a browser visit from operational facts that require a real proxy route test.

1. Automatic current connection

Cloudflare supplies the public connection IP to the Worker. IPBot then analyzes that address's location, ASN, network role, proxy/VPN/Tor traits, evidence, IP Score and IP Risk. A browser visit cannot reveal a configured proxy host, port, username or password.

2. Dynamic current detail

The page says Current Proxy Detail only when IPBot detects proxy, VPN, Tor, residential proxy or privacy relay evidence. Datacenter hosting alone is shown as infrastructure, not treated as proof of proxy use.

3. Proxy header hint

The Worker may report the names of observed proxy-style headers, never their values. These names are untrusted hints and are not used as proxy proof because forwarding headers can be added or changed by intermediaries.

4. Operational Proxy Score

Reachability · 35
A complete end-to-end route.
Latency · 35
A bounded curve from 250 ms or faster to over 4 seconds.
Anonymity · 20
Elite, anonymous, transparent or unknown forwarding evidence.
Protocol · 10
Tunnel capability receives more credit than plain HTTP forward mode.

5. Separate IP evidence

After a successful route, IPBot analyzes the exit IP. Its IP Score and 0–100 IP Risk remain separate from the operational Proxy Score and are not calibrated fraud probabilities.

Privacy

What Proxy Score processes

Effective August 4, 2026.

Current connection

Cloudflare supplies the public connection IP needed to deliver and secure the site. The Worker sends that address to IPBot for the automatic current-connection result. Browser name, operating system, timezone and language are derived in your browser for display and are not submitted as score inputs.

Submitted proxy data

Proxy strings—including credentials when present—travel over HTTPS to the Cloudflare Worker and through a signed server-to-server bridge to the controlled proxy-testing engine. They are used only to perform the requested check.

No proxy-list history

The application does not place submitted proxy lists in URLs, localStorage, sessionStorage, Cache API or an application history database. Reloading clears the in-memory proxy input and results.

Masking and exports

Credentials are masked in results and safe JSON. Full values are exposed only when you deliberately reveal, copy, retry or export a credential-bearing proxy. TXT and CSV export ask for confirmation when credentials are present.

Operational records

Operational events contain bounded counts, duration, outcome and stable error classes. The design does not log raw submitted rows, usernames, passwords, IPBot keys, bridge secrets or full upstream response bodies.

Service providers

Cloudflare
Hosting, routing, static assets, connection IP, rate limiting and the same-origin bridge.
Proxy test engine
Connects through submitted proxies to the controlled signed probe.
IPBot
Analyzes current and successful proxy exit IPs.

Terms

Use Proxy Score responsibly

Effective August 4, 2026.

Authorized endpoints only

Submit only proxies you own, are authorized to use, or have a lawful right to test. Do not use the service to access private networks, bypass controls, attack third parties, validate stolen credentials or facilitate unlawful activity.

Point-in-time diagnostics

IP classification, working status, latency, anonymity, location, scores and failure reasons can be incomplete, delayed or wrong. Results are provided without a guarantee of accuracy, availability, fitness or future performance.

Fair use

Do not evade limits, automate abusive volumes, interfere with the service, resell the public interface or use many identities to extend free capacity.

High-impact decisions

Proxy and IP intelligence describes network endpoints, not people. Do not use it as the sole basis for legal, credit, employment, housing, healthcare or other high-impact decisions.