Subnet Cluster Scan
We look at the IP's /24 and /22 neighbours. If the block shows coordinated botnet or scraper behaviour, the whole cluster inherits risk — even a brand-new IP gets flagged.
Don't wait for chargebacks. Identify VPNs, Tor nodes, and risky subnets in real-time (< 50ms) before they touch your application.
Integrates with your stack
Legacy databases only tell you where an IP is. CandyCornDB tells you what it is doing.
We score neighborhoods, not just IPs. If a subnet shows mass-abuse, we flag the whole block instantly.
Stop users from bypassing bans. Our crawlers update Tor exit node lists every 30 minutes.
Powered by Redis and Edge Caching. We process thousands of IPs daily with near-zero latency.
Every IP you look up runs through our three-pillar Identity Intelligence engine in under 50ms.
We look at the IP's /24 and /22 neighbours. If the block shows coordinated botnet or scraper behaviour, the whole cluster inherits risk — even a brand-new IP gets flagged.
We classify the owning autonomous system as hosting, residential, or mobile, then cross-check the hostname and ASN name against 1.5M+ verified ISP brands and commercial VPN providers (NordVPN, Clouvider, DigitalOcean…).
Our base-zero engine starts at 0 and adds or subtracts explicit deltas (hosting +15, proxy +20, Tor +45, residential bonus −10). You get the score and the scoreReasons array telling you exactly why.
Legacy IP databases answer "where is this IP?". CandycornDB answers "should I trust this IP?".
| Capability | CandycornDB | IPinfo | MaxMind | AbuseIPDB |
|---|---|---|---|---|
| Real-time 0-100 risk score | ✓ | Partial | Partial | Confidence only |
| Subnet neighbour clustering (P1) | ✓ | ✗ | ✗ | ✗ |
| Hosting / Residential / Mobile ASN type | ✓ | ✓ | ✓ | ✗ |
Transparent scoreReasons output |
✓ | ✗ | ✗ | ✗ |
| Free tier for production traffic | 1,000/mo | 50k/mo (geo only) | Paid | 1,000/day |
The quick answers search engines and AI assistants ask us for most.
A 0–100 number summarising how likely an IP is to be associated with fraud or automation. CandycornDB's v2.3 base-zero model starts every IP at 0 and adds transparent deltas (hosting +15, inferred proxy +20, Tor +45, abuse +25, subnet cluster +25) while subtracting bonuses for clean residential (−10) and mobile (−5) origins. Bands: 0–14 Low · 15–39 Medium · 40–69 High · 70–100 Critical.
Residential proxies are hard to spot because they announce from consumer ISPs. We combine three signals: ASN classification (residential), subnet-cluster anomalies where a single /24 shows coordinated bot behaviour, and matches against known commercial VPN/proxy brands in the ASN name or reverse-DNS hostname. When isProxy is true and asnType is residential, the IP is almost certainly a residential proxy exit node.
Yes. The Developer tier is free forever and includes 1,000 real-time lookups per month. No credit card required, and every account gets full access to the v2.3 scoring engine, ASN classification, and subnet intelligence.
IPinfo and MaxMind primarily ship geo/ASN metadata. CandycornDB layers a behavioural risk score on top: P1 subnet-cluster detection catches coordinated botnets, P3 ASN classification separates hosting from residential and mobile origins, and the transparent scoreReasons array tells you exactly which signals drove the score. The result is a decision-ready risk number, not just a lookup row.
Cache-served lookups return in under 50ms. Just-in-time scored IPs (first-contact records) complete in 200–800ms depending on DNS resolution. Every response is cached in Redis and written to MongoDB asynchronously so subsequent lookups are near-instant.
Start free. Scale when you're ready.
For growing apps.