Scamalytics Scores on US Carrier IPs
Scamalytics grew out of fraud prevention for dating and social sites, where fake profiles and romance scams are the daily problem. Its public lookup shows a fraud score for an address, a risk label, the ISP behind it, and a set of columns pulled from external blacklists and proxy databases. People paste SpoofProxies line addresses into it because it is free and quick. The result is easy to misread, especially on a carrier network, so this page explains what Scamalytics is measuring, why a mobile address from AT&T, T-Mobile or Verizon usually reads the way it does, and what the lookup leaves out.
Where the number comes from
Scamalytics scores are built from traffic its clients see: sign-ups, logins and messages on the sites that use its service, together with the outcome of those events. An address that has been tied to scam accounts on client sites gains a worse score; an address that shows mostly ordinary activity drifts lower. The lookup also shows a score for the whole ISP, which is an average across that network rather than a statement about your address. Many people read the ISP figure and assume it is theirs. It is not.
For a carrier network the ISP-level figure is usually modest, because the network carries millions of ordinary subscribers and the scam traffic is diluted among them. The address-level figure varies more, because each CGNAT pool address has its own short history.
The blacklist and anonymizer columns
Below the score, Scamalytics lists whether the address appears in several external sources, such as firewall and abuse lists and commercial proxy databases, and whether it is judged to be an anonymizing VPN, a Tor exit, a server, a public proxy or a web proxy. On a carrier address the server and Tor columns should read negative, because the address belongs to a wireless network rather than a data centre. The proxy-database columns are the ones that sometimes read positive, for the same reason as other vendors: a shared carrier address can inherit a label from anything that used the pool before.
Each column is a separate claim from a separate source with its own update cycle. If one list flags the address and the others do not, you are looking at one source's opinion of one moment in that address's life.
How carrier-grade NAT changes the reading
Carrier-grade NAT is the single most important fact about mobile addresses. It means the address is a door many people walk through, and a reputation system that punished the door would be punishing a whole neighbourhood. Scamalytics clients generally understand this and weigh the ISP type alongside the address score. That is the honest reason carrier addresses tend to be treated gently. It is not a guarantee of anything, and it does not protect an account whose behaviour is the problem.
- Many real phones share a carrier address, so any score reflects a crowd, not a single customer.
- Pool addresses are reused over the day, so the history you inherit changes when you rotate.
- Platforms know this, which is why a mobile ISP label usually softens how a score is applied.
- A dedicated line means no other proxy customer shares your device, but the carrier pool is still shared with ordinary subscribers.
What Scamalytics does not measure
The lookup knows nothing about your browser, your cookies, your time zone, the account you are signing into, or how quickly you act. A dating or social site that uses Scamalytics also runs its own checks on photos, message content, reports from other members and payment data. An address that reads low risk will not rescue a profile that behaves like a scam, and an address that reads medium risk is rarely the reason an honest user is challenged. If you manage accounts you are authorised to run and still see friction, look at consistency first: the same device profile, the same metro, sensible hours and no sudden jumps between locations.
It also cannot see that your line is dedicated. From the outside a SpoofProxies line looks like any other subscriber on that carrier, which is the point of a real SIM in a real device.
Using the lookup for diagnosis
The useful way to use Scamalytics is as a first check when something looks wrong. Confirm the address you are actually exiting from, then look it up. If the ISP reads as the carrier and the server columns are negative, the network is behaving as a mobile network should, and your attention belongs on the profile and the account. If an address is on a current abuse list, rotate once and check the new address. Record what you find so the team has a history to compare against rather than a fresh panic each time a number moves. A weekly look is plenty for most teams.
Setting up a Scamalytics proxy on SpoofProxies
- Add a line in the dashboard and pick the metro and carrier that match your work.
- Set the host, port, username and password in the browser profile or app you will use.
- Open an IP checker through the line and copy the exit address shown.
- Look it up on Scamalytics and separate the address score from the ISP score.
- Read the server, Tor and proxy-database columns one by one and note which source says what.
- If a current abuse listing appears, rotate once and repeat the lookup before changing anything else.
Scamalytics proxy questions
Is the ISP score the score of my address?
No. It is an aggregate for the whole network. The address score is the one tied to the specific address you are exiting from, and it can change when you rotate.
Why does one blacklist column say yes and the others no?
Each column is a different external source with its own method and update schedule. A single positive on a shared carrier address usually reflects an earlier user of that pool address.
Will a low Scamalytics score keep an account safe?
No. Sites that use Scamalytics also judge content, reports, payments and behaviour. The score only describes the network address, and platform rules apply regardless of the network path.