IP and network classification
You use this result to see the public exit for this visit: which network the address belongs to, roughly where it sits, whether intelligence calls it Residential, Datacenter, VPN, Proxy, or a Tor exit, and whether a public blacklist has a record.
Identity and location are on every check. Line type, the proxy mark, and abuse risk appear once network intelligence returns, so you can tell whether this exit fits the job you are about to do. The blacklist tells you, on its own, whether the lists checked this time contain the address.
What one IP can answer
The public exit for this visit
│
├── Network identity
│ ├── IP address
│ ├── ASN
│ └── Operator
│
├── Location
│ ├── Country
│ ├── City
│ └── Timezone
│
└── Quality signals
├── Line type
│ ├── Residential
│ ├── Datacenter
│ ├── VPN
│ ├── Proxy
│ └── Tor exit
├── Proxy / VPN / Tor mark
├── IP blacklist
└── IP abuse riskIdentity says which range this is, and who operates it. Location says roughly where the exit sits. Line type says whether this intelligence result calls it Residential, Datacenter, VPN, Proxy, or a Tor exit. The blacklist says whether a public list has a record.
Together, these are whether the IP is usable. When all four quality signals are normal, the verdict is “No risk signals on this IP.” When any one is marked Review, the verdict is “This IP has signals to review,” and the page names which ones.
Why these four quality signals
Country and operator tell you where the exit is and who runs it. They do not tell you whether the line is usable. A usable exit depends on what kind of network it is, whether it is a known proxy or anonymity exit, whether a public list already has a record, and how strongly it is tied to abuse. Those are the four quality signals: line type, proxy mark, IP blacklist, and IP abuse risk.
When all four are normal, the page says “No risk signals on this IP.” When any one is marked Review, it says “This IP has signals to review” and lists the items that fired. When line type and the blacklist have not come back yet, the verdict is “No quality data right now.” We do not call that IP clean. Re-check in a moment.
| Quality signal | Normal | Review | What you do with it |
|---|---|---|---|
| Line type | Residential | Datacenter, VPN, Proxy, Tor exit | See whether the exit is ordinary access, or hosting or an anonymity exit. Use residential for an account. Datacenter can be the right exit for a server. |
| Proxy mark | No known flags | Known flags found | See whether the address is already recorded as a proxy, VPN, or Tor exit. A known flag means change the line. Datacenter can be Review on type and still have no known flags. |
| IP blacklist | No record | Listed | See whether public abuse lists contain this IP. A listing means do not use it as a clean exit. |
| IP abuse risk | Low | High, Very high | See how strongly this IP is tied to attacks, abuse, and anonymous-network activity. High or Very high means switch to an exit with lower risk. |
For a usable exit, all four cells are Normal. The cell marked Review is the one you change: switch to residential, avoid a flagged line, avoid an address on a list, or move to an exit with lower abuse risk.
Identity: who holds the range
An ASN is the number a block of addresses uses on the internet. It says which network holds or announces that block. The operator name comes from the same location lookup, and says who runs or administers the resource.
The holder, the operator, and the person using the address right now are often not the same party. Ranges are assigned, leased, and used by downstream customers and proxy networks. ASN and operator say where the network comes from. They do not say who is on it now.
The operator name is also not a line type. EnvTrace does not turn a cloud or hosting word in that name into Datacenter. Without network intelligence, the type stays absent.
Location: where the exit sits
Country, city, and timezone estimate the current public exit. The estimate comes from how address databases place that network. It is not GPS, and it does not reach a street, a building, or a person.
The city can be wrong, and the network timezone can differ from the timezone on the computer in front of you. Reading the IP location as “the person is in this city” is the usual mistake.
When the path runs from your network through a proxy or VPN and then to the site, both the site and EnvTrace see the proxy or VPN exit. The location describes that exit, not the network you started from.
How the line type is named
Once network intelligence is available, EnvTrace gives the address one type. The type is there so the result can be read at a glance. Residential, proxy, and hosting are not stacked as a row of labels.
If the intelligence mentions more than one attribute, the more specific name is the one that is kept. The order is Tor exit, then Proxy, then VPN, then Datacenter. If none of those apply, and a country or ASN is still known, the type is Residential.
A proxy mark therefore does not sit beside Residential. If the address is flagged as a proxy, the type is Proxy. If VPN and hosting are both mentioned, the type is VPN. Datacenter describes a hosting or cloud range. It does not automatically mean VPN.
What Residential means here
Residential means this intelligence result did not call the address a Tor exit, a proxy, a VPN, or a datacenter, and the address still maps to a country or an ASN. Treat it as the current default line type, then read the blacklist and abuse risk to see whether the exit has any other record.
Datacenter, VPN, proxy, and Tor
Datacenter means the intelligence treats the range as hosting, cloud, or a facility network. That is the exit you want for a server. If you wanted a residential network, switch to a residential type and then check the blacklist.
VPN, Proxy, and Tor exit mean the intelligence treats the address as that kind of relay or anonymity exit. Remote work, privacy, and cross-region access all use the first two. A Tor exit is a published anonymity node that many sites refuse, so account work usually needs a different exit.
Those types show up in the report as “IP looks like a datacenter,” “IP flagged as VPN,” “IP flagged as proxy,” and “Tor exit node detected.” None of the four appear when network intelligence is absent.
Why the proxy mark is separate from the type
The type answers what this result is called. The other item answers whether a known proxy, VPN, or Tor mark exists. Tor, Proxy, and VPN types carry a known mark. Datacenter and Residential can show no known mark.
The mark comes from addresses already recorded in network intelligence. It does not inspect whether proxy software is open on this computer, and it does not see whether traffic just left this machine.
Names this method does not use
ISP, mobile, native IP, and broadcast IP still circulate as ways to talk about real network differences. They are not classifications in this method.
An ISP is an access provider. The same provider can hold household, business, and hosting space, so EnvTrace prints the operator name it found and does not add an ISP type. Mobile, native, and broadcast are not judged separately either. Their absence means those classifications were not made. It does not mean the address was found to be residential.
Where the blacklist and abuse risk come from
The blacklist is a check against public abuse lists. If those lists contain the address, it is Listed. If they do not, it is No record. A listing means do not use it as a clean exit.
Abuse risk comes from the same network intelligence, and is shown as Low, High, or Very high. High or Very high means switch to an exit with lower risk. When neither result is back yet, those two cells stay empty until you can read them.
How to read an IP result
Read in this order. Each layer answers only its own question:
- IP, country, and city: where the exit appears to be, so you can match it to the region you need.
- Operator and ASN: who operates the range, so you can confirm it is the network you expected.
- Line type: when a type is present, read that one name and decide whether the exit is residential, datacenter, VPN, proxy, or Tor.
- Proxy mark: whether a known proxy, VPN, or Tor mark exists. A known flag means change the line.
- Blacklist: whether public lists have a record. A listing means do not use it as a clean exit.
- IP abuse risk: keep using it when it is Low. High or Very high means switch to an exit with lower risk.
What to read after the type
The type tells you what this exit is called. Read the proxy mark, the blacklist, and abuse risk next, and you can see whether it also has a known relay mark, a public record, or a stronger tie to abuse. When location is already there and the type is not, use the country and operator first, then read the type once intelligence returns.
When the IP itself was not found, the report says “IP intelligence not connected.” Confirm that this visit has a public address, then read the rest.
Version
Version 1.0 is how to read the IP result as it is given now: identity and location of the exit; one line type and a proxy mark once network intelligence is available; the abuse-risk number that source provides; and whether public blacklists have a record. ISP as a type, mobile, native IP, and broadcast IP are not part of this version. A material change to the classification or to how a blacklist is read gets a new version.