Scamalytics delivers IP fraud intelligence to fraud and risk teams. When the Scamalytics products are integrated into existing workflows, organisations can make faster and more informed decisions by using the Scamalytics proprietary fraud score and additionally sourced intel data to risk assess every IP address on the internet. Trusted in production since 2011 by over 7,500 users, Scamalytics has helped industries including fintech, banks, payment processors, identity verification providers, adtech platforms, e-commerce businesses, and online platforms to detect and prevent fraud. This IP intelligence is available for data enrichment through three efficient integration options:
For more than a decade, fraud teams have relied on the Scamalytics Risk Score to help determine whether a visitor is likely to be fraudulent, fake or malicious.
How the score is built. The Scamalytics Risk Score is based on fraud feedback gathered from a global network of operators who report confirmed fraudulent activity to Scamalytics. This intelligence is then applied across the surrounding IP neighbourhood, including addresses within the same subnet, ASN, and hosting block. As a result, IPs located near known malicious addresses can receive elevated risk scores before they have been reported individually. Passive and purely geolocation-based data sources cannot provide this type of feedback signal.
A score of 70 means that approximately 7 out of 10 users seen from that IP address have been linked to fraudulent activity. A score of 0 indicates no known fraud risk. Every lookup also returns proxy and anonymisation detection, ISP-level risk, geolocation data, and enrichment from more than ten integrated external sources, all within a single response.
Suggested actions by score range:
Please note: The thresholds above are intended as a starting point. We recommend adjusting them based on your own fraud data to balance fraud prevention against customer experience.
Our IP Fraud Risk API is built to respond in 50ms or less, with API nodes in Europe and the USA to reduce network latency.
What you get:
Essential Plan and Premium Data Add-Ons. We offer a single Essential plan that includes the full Scamalytics fraud score, ISP-level risk, proxy detection, geolocation, and all open-source enrichment feeds. If you need access to additional commercial datasets, optional Premium Data Add-Ons can be enabled on any paid plan.
Included with Essential:
Available as optional Premium Data Add-Ons on any paid plan:
Full details and prices for each add-on are on our API pricing page.
Code examples are available in cURL, Python, Node.js, and PHP. See our API documentation for full details.
Read API documentation Get API access
Privacy: Scamalytics does not log API calls or store the IP addresses submitted by customers. Every lookup is processed in real time, and the data is discarded immediately afterwards.
For organisations with data residency requirements, high-throughput pipelines, or a preference for keeping everything in-house, the On-Premises MMDB stores the entire Scamalytics database within your own infrastructure. Every lookup is performed locally, so no IP addresses are sent to Scamalytics, there are no network round trips, and there are no rate limits.
What you get. The MMDB includes the same fraud intelligence available through the API, delivered as a self-hosted database in the industry-standard MMDB format:
The database is updated daily and delivered securely to your infrastructure over HTTPS. Keeping your data up to date is as simple as replacing the existing file, with no code changes required.
Benefits:
Typical use cases:
Contact us to discuss MMDB access, pricing, and delivery options.
Fraud investigators and analysts can upload a CSV or TXT file containing millions of IP addresses, with no coding required, and receive a fully enriched report in just a few minutes. Every IP is scored and classified using the same intelligence returned by our API, with the results delivered as a CSV that is ready for review and analysis in any spreadsheet application.
How it works:
What the enriched CSV includes:
Typical use cases:
Data retention. Enriched reports are stored securely on Scamalytics servers so you can download them at any time once processing is complete. Reports can be deleted manually at any time and are automatically removed after 30 days. The IP addresses in your uploaded file are used only to generate your report and are not used for any other purpose.
Bulk IP Lookups are available to all API account holders through bulk.scamalytics.com, including users on the free tier.
Go to bulk portal Get an account
All three products are powered by the same fraud intelligence. The right choice depends on how your team prefers to work.
Choose the API if you're building live product integrations. It performs real-time checks in under 50 milliseconds, returns JSON responses for every lookup, and is billed using monthly credits. Every account starts with a free tier of 5,000 credits per month. IP addresses are processed in real time and are never logged or stored.
Choose MMDB if you process high query volumes, operate in a regulated environment, or require the lowest possible latency. Run unlimited lookups on-premises in microseconds for a flat fee, with no data leaving your infrastructure.
Choose Bulk IP Lookups if you're a fraud investigator or analyst who needs to process large volumes of IP addresses without writing code. Upload millions of IPs, receive an enriched CSV within minutes, and download reports whenever you need them. Reports can be deleted on demand and are automatically removed after 30 days. This option is included with every account, including the free tier.
If you'd like help deciding which option best fits your needs, please contact us.