What Affects the IP Risk Level?
iDenfy sends the client’s IP address — and nothing else — to a third-party risk provider, which returns a single risk level. Use of VPNs, proxies, or anonymizing networks is the strongest driver, alongside the provider’s own reputation data for the address. That reputation data can raise an address’s level when the provider has previously seen patterns such as:- Many different emails used from the same IP
- Many different billing addresses used from the same IP
- Many different payment cards used from the same IP
- A high-risk device previously seen using this IP
- A high-risk email previously associated with this IP
- Unusual or suspicious network activity across the provider’s network
These signals are evaluated on the provider’s side, from data it has gathered across its own network. iDenfy sends only the IP address and receives only the risk level — no email, address, payment card, or device data from your verification is sent to the provider, and no per-signal breakdown or separate VPN, proxy, or Tor flag is returned.
What the Risk Levels Mean
There are five levels, plus a Not checked state. Each level is distinct and is shown as returned — the dashboard does not group them.When You See “Not Checked”
Not checked means no risk level was produced. It appears when:- The provider call failed or timed out.
- The returned score fell outside the scored range.
- No client IP was captured for the session.
- The check is not enabled for your account.
Where the Check Runs
- Identity verification — runs once per verification, and only after a successful result. The level appears in the dashboard and in the
clientIpProxyRiskLevelfield of the result webhook. You can also check any IP on demand with the Proxy Check API. - Business verification — appears among the company’s risk factors. It is skipped when no client IP was captured, which returns Not checked.
IP country match is a different check. It compares the client’s IP country against the company country and is configured as its own custom rule — a mismatch there says nothing about the IP proxy risk level.