Know who is really signing in. huntback classifies every visitor at login and signup in real time: VPN, proxy, Tor exit, datacenter and residential-proxy, with a risk score. Allow, flag or block, in milliseconds.
One call classifies the anonymisation layer a fraudster is hiding behind.
Commercial VPN providers (NordVPN, ExpressVPN, Surfshark and dozens more) by ASN and server lists.
The live public Tor exit list, so anonymised Tor traffic is flagged at the door.
Traffic from cloud and hosting ASNs, a real human rarely signs up from a server.
Behavioural residential-proxy signals (Oxylabs, BrightData and honeypot-observed exits).
Known scanners, open proxies and abuse.ch / FireHOL anonymiser feeds.
A single 0 to 100 score you can drop straight into your fraud rules.
Call huntback with the IP at login or signup. It classifies the network (VPN, commercial proxy, Tor exit, datacenter/hosting, residential or mobile) and returns a risk score, in milliseconds, from a local dataset with full IPv4 coverage plus the live Tor and VPN lists.
Yes. Use the network type and risk score to allow, step-up (extra verification), flag for review, or block, according to your own policy.
No. Classification is a local lookup with no third-party API call, so it returns in milliseconds.
Geo-IP tells you a country. huntback tells you the anonymisation layer (is this a VPN, a Tor exit, a datacenter, a residential proxy?) and cross-references it with attacks seen on our deception network.
Get a free API key and classify your first visitors in minutes.