Active scanning
Objective proxy verification by our own scanner.
Reputation feeds are opinions. SubnetHistory also runs its own active checks, and their findings are measurements: a confirmed proxy was verified by us directly. The report keeps the two kinds of evidence apart. What a check does, and how it chooses what to look at, is not documented.
When a check happens
Looking something up can queue it for a check. Recent results are reused, so most lookups are answered from the archive.
What the report shows
Where an active check has confirmed proxies, the report shows it in three places, never as a raw scan dump:
| Where | What it says |
|---|---|
| A tag on the space | On the address that answered, on its covering /24, and in some cases on the network. |
| Address sampling | A per source row in the sampling detail, beside the reputation feeds, labelled "Confirmed proxy". Its risk column reads n/a. |
| Block summary | On a subnet report, one line such as "12 addresses in this block answered as a proxy on our active check (2026-08-09)". |
If the subject has never been checked, none of these appear (in the API, intel.activeScanBlock is null). Absence means not checked, not clean.
A confirmed proxy carries no score
A confirmation is a finding, not a position on the risk scale. It is published as a label and a tag, and our row reports no number: in the API, riskScore is null on the active scan sample and riskFrom is never activescan.
Risk scores come only from the reputation feeds that measure one. Where no feed has scored the address, the report says so rather than substituting a number, and the risk fields read n/a.
The confirmation is a separate statement from the score. A confirmed proxy sitting beside a feed score of zero is not a contradiction: it means the address is serving as a proxy and that feed has seen no fraud from it.
When a proxy stops answering
Proxy findings go stale quickly. When a later check finds nothing, the tag comes off and the address stops being described as a proxy.
It does not revert to "no signals". It is shown as quiet, with the date we last saw it serving. We keep the history either way.
Two tags, two different claims
A check can prove that an address answered as a working proxy. It cannot show who runs it or whether anyone is selling access, so the finding and the accusation are separate tags:
- Proxy exits is the measurement. Addresses here answered as working proxies when we last checked. It is applied in every kind of network.
- Proxy provider names what an operator does. It is only applied to space already characterised as commercial infrastructure.
Labelling a whole network
An address labels itself, and a block is labelled on the strength of its own addresses. A network is labelled only once a large part of its space has been measured serving proxies, so findings in a few blocks label those blocks and not the operator behind them.
The absence of a network-scope label is not a finding of innocence.
Guardrails
Checking is bounded: recent results are reused, per visitor budgets cap how many new checks one client can trigger, and the heaviest work is throttled. Network operators with questions or concerns can reach [email protected].