subnethistory docs
Open the appApp
Understanding the report/Address intelligence

Address intelligence

What independent per address feeds say about the space right now.

Registration and routing describe who holds a block. Address intelligence describes how its addresses are used: VPN exits, proxies, Tor relays, and how independent reputation feeds score them.

How sampling works

SubnetHistory samples addresses inside the queried block, and readings accumulate across lookups. The report states which block was sampled and how many addresses have been checked. An unsampled address is not a clean address.

What each address reports

For every sampled address, each feed contributes:

  • Verdicts. Whether the address is a VPN, proxy, Tor node, datacentre address, known abuser, mobile address or blacklisted. Each verdict is true, false or n/a, and which feed said what is preserved.
  • Risk. A 0 to 100 score with the feed's own label, plus a separate operator risk for the ISP as a whole, which says nothing about an individual address inside it.
  • Context. Country, the operating ASN and organisation, the tenant where it differs from the ISP, the detected service, and which public blocklists carry it.

The rollup

The block summary counts each verdict across sampled addresses, worst and average risk, worst operator risk, blocklists hit, detected services, and the organisations and tenants seen.

  • n/a is not zero. Where no feed has an answer the field is n/a, which is not a clean verdict.
  • Blocklist counts. The worst case count is the most lists on any single address, not the union of list names.

When feeds disagree

Each verdict count carries an agreement breakdown:

ReadingMeaning
agreeTwo or more feeds flagged the address and none said otherwise.
soleExactly one feed flagged it and no feed contradicted it.
contestedOne feed flagged it and another explicitly returned false.

Contested claims are hedged rather than shown as fact: the chip reads disputed and the note names the contradiction. Separately, where feeds place an address in different bands of the risk scale no single label is shown, and numbers differing inside one band are not a disagreement.

Address categories and the block map

Each sampled address falls into one of four buckets:

  • anonymity: traffic from it cannot be attributed (VPN, proxy, Tor).
  • infrastructure: not residential (datacentre, hosting), but not anonymising.
  • lapsed: a proxy was caught serving here and has since stopped answering. The note gives the date last seen. See active checking.
  • clean: no feed has anything bad to say and it has never been caught serving. Never caught is not the same as checked and found clear: the address may never have been checked.

The block map first shows how much of the block was sampled against the unsampled remainder, then one cell per sampled address, coloured by its behaviour bucket. Selecting a cell opens that address: its risk, verdict chips with contested ones marked disputed, a note and a risk sparkline. Addresses are also grouped by behaviour with counts.

What sampling may conclude, and what it may not

Tags such as proxy provider, residential proxy, mobile proxy and VPN provider are claims about what a business sells, so sampled evidence alone never applies them. Where a report carries one, an analyst applied it, except proxy provider, which an active check can also apply to space already characterised as commercial infrastructure. Absence of such a tag is not a finding of innocence.

Tags describing address space rather than a business, such as hosting and eyeball ISP, may be applied from sampled evidence.

Over time

  • Flagged share. Twelve months of the flagged percentage of what was sampled each month, plus the worst risk score that month. A month nobody sampled is a gap, not a zero.
  • Trend. Risk over time per feed, with the number of days observed stated.
  • Changes. A feed's verdict flipping between observations is listed with before and after.
Last updated 2026-08-12subnethistory.com