Blog

How an IP blocking API decides who is a bot

A plain-English look at ASNs, datacenter ranges and why the network behind an IP tells you more than the IP itself.

When people hear "IP blocking" they usually picture a giant list of bad IP addresses. That approach exists, but it ages badly. Bad actors rent new addresses every day, and yesterday's list is already stale.

A better approach is to look one level up: not at the address, but at the network that owns it.

Every IP belongs to a network

The internet is made of tens of thousands of networks. Your home broadband provider is one. Your mobile carrier is another. Amazon Web Services, DigitalOcean, and every VPN company you have heard of all run their own.

Each of these networks has an ID called an ASN, short for Autonomous System Number. Every IP address on the internet sits inside a block owned by one of them. So if you know the IP, you can find out which network it belongs to and who runs it.

Why the network matters more than the address

A VPN company can hand out thousands of different IP addresses, but they all come from networks the company controls. A scraper renting servers can rotate addresses every minute, but those addresses still come from the same few hosting providers.

So instead of chasing individual addresses, you keep a list of networks that real customers rarely browse from:

  • Commercial VPN providers
  • Proxy and residential proxy services
  • Tor exit relays
  • Cloud and hosting companies
  • Known scraping and crawling operators

Fraudex tracks more than 741 of these networks. When an IP comes in, it finds the owning network and checks it against that list.

How it stays fast

The full map of IP ranges to networks is loaded into memory when the service starts. Looking up an address is a binary search through sorted ranges, which takes microseconds. There is no database call and no request to anyone else while your visitor waits. That is why the answer comes back in under a millisecond, for IPv4 and IPv6 alike.

What it cannot tell you

Network checks are a strong signal, not a lie detector. A real customer might be on a corporate VPN. A fraudster might use a hacked home computer. That is why the best setups combine the IP verdict with other things you already know: the billing country, the card's issuing country, how old the account is, and how fast the form was filled in.

Think of the IP check as the first filter. It removes a large share of junk cheaply, so your more expensive checks only run on what is left.