Skip to content

Spaw vs IPQualityScore

IPQualityScore sells fraud detection across several signals on one lookup credit: proxy and VPN detection, email verification and device fingerprinting all draw from the same monthly quota, and the IP answer carries a fraud score alongside the connection facts.

The table uses IPQualityScore's public pricing and documentation pages as checked on 2026-09-10, and Spaw's own pricing page. A row those pages carry no value for is marked "not on the pages read" rather than guessed at, and that is a statement about the reading and not about what IPQualityScore publishes.

  spaw ipqualityscore
Pricing modelPay-as-you-go credit packs, or optional monthly plans that deposit the same credits every month for less; both through Stripe Checkout, credits from either never expireMonthly plans by lookup quota: Free $0 (1,000 lookups a month), Startup "As low as: $99 / Month" (5,000), SMB Basic "$499" (10,000), SMB+ "$999" (75,000), Enterprise custom. "Any valid request sent to our Proxy Detection, Email Verification, or Device Fingerprinting services including lookups performed through a batch CSV file check will consume a lookup credit."
Free tier10 free credits every month, no card required1,000 lookups a month, capped at 35 a day
Price per 1,000 at about 10k$7.80 (Growth pack: 5,000 credits for $39), or $5.80 on the Growth monthly plan (5,000 credits for $29 a month)not on the pages read
Price per 1,000 at about 100k$4.99 (Volume pack: 100,000 credits for $499), or $3.99 on the Volume monthly plan (100,000 credits for $399 a month)not on the pages read
Addresses no feed covered billedAn answered address costs 1 credit whatever its flags say; a flag no feed could evaluate answers null rather than false, and the answer costs the samenot on the pages read
Reserved and private ranges billedNo: reserved, private, loopback, CGNAT, documentation and multicast ranges answer reason reserved_range and are free, and so are repeats within 7 daysnot on the pages read
Feeds behind the flagsPublic feeds, each named in the answer with the date it was synced: DB-IP Lite and RFC 8805 geofeeds for location, the five registries' delegated statistics for allocation, Spamhaus DROP and ASN-DROP and abuse.ch Feodo Tracker for blocklists, the Tor Project's exit list and Onionoo, the Mullvad, NordVPN and Private Internet Access server lists plus the open X4BNet lists, Apple's iCloud Private Relay egress list, the cloud providers' own published ranges, and the verification files Google, Microsoft, OpenAI, Perplexity, DuckDuckGo and Ahrefs publish for their crawlers.Its own collection rather than published lists: "IPQS gathers data directly from our proprietary honeypots, traps, crawlers, and thousands of live sites opted into our threat intelligence network." The proxy detection answer carries proxy, vpn, tor, active_vpn, active_tor, fraud_score, ISP, organization, ASN, connection_type, recent_abuse, bot_status, is_crawler and the location fields.
Refresh cadenceEvery feed re-syncs daily, the botnet command-and-control list hourly, and the geofeed crawl weekly. Each response names every dataset it consulted with the date it was last synced, and /status lists them all.Not published as a schedule: the documentation says the data is collected continuously, "scanning billions of IP addresses every day", without naming a refresh cycle.
Geolocation sourceThe DB-IP Lite database, overridden wherever the operator publishes the location itself — an RFC 8805 geofeed, Apple's relay list, a VPN provider's server list. location_source says which answered, and location_confidence is graded from a weekly accuracy report rather than asserted.Its own data: country_code, city, region, latitude, longitude, timezone and host come back with the fraud fields.
Bulk limit100,000 addresses per bulk job, with an HMAC-signed completion webhookBatch CSV file checks are offered, and each row consumes a lookup credit; no row limit is published on the pages checked
Batch API1,000 addresses per synchronous request; repeats inside the list are looked up oncenot on the pages read
Rate limit50 requests per second per key on the IP endpoints20 lookups a second on the SMB Basic plan; the other plans' limits are not stated on the page checked
Official SDKsPython, Node.js, PHPnot on the pages read
Data retentionNothing: no history row and no log line carrying the address, only a hashed 7-day marker that makes a repeat free. Bulk input lists and result files are deleted with the job after 30 days.not on the pages read

checked 2026-09-10 · sources: IPQualityScore plans, IPQualityScore proxy detection documentation

When IPQualityScore fits better

Teams that want one vendor, one credit pool and a single fraud score across IP, email and device signals.

  • One credit pool across proxy detection, email verification and device fingerprinting
  • active_vpn and active_tor are separate from vpn and tor, so a listed range and a live connection are different answers
  • The free plan allows 1,000 lookups a month, capped at 35 a day

When Spaw fits better

Developers who want every public IP feed compiled, dated and named for them, with a risk score whose weights are published so it can be recomputed or ignored.

  • Both sell several signals on one balance; IPQualityScore's are IP, email and device, Spaw's are email, phone, IP, address, business identity and the consistency check across them
  • IPQualityScore's data is proprietary; every dataset behind a Spaw IP answer is a public feed named in the response with the date it was synced
  • IPQualityScore's plans are a monthly quota that resets; Spaw's credits never expire and reserved ranges cost nothing
  • Spaw publishes the weight behind every point of its risk score, so the number can be recomputed or ignored

Questions

Does Spaw charge for addresses its feeds do not cover?

Spaw bills per answered address. Reserved, private, loopback, CGNAT, documentation and multicast ranges answer reason reserved_range and are free, and so is a repeat of the same address within seven days. A flag no feed could evaluate answers null rather than false: the address still costs 1 credit, and the null tells you the signal was not checked instead of pretending it was. IPQualityScore does not publish how it bills them.

Can I run a log file or an export through Spaw?

Yes. A bulk run takes up to 100,000 addresses from the dashboard or the API and returns one row per input address, in input order, with every flag, the risk score and the signals that made it. Repeats inside the list are looked up once, reserved ranges cost nothing, and the finish is announced on an HMAC-signed webhook.

Is there a free tier?

Every Spaw account receives 10 free credits at the start of each month with no card on file, and unused credits accumulate. IPQualityScore offers: 1,000 lookups a month, capped at 35 a day.

Try Spaw on your own list

Free credits every month, no card. Upload a list, keep your columns, and download only the rows you want. See the pricing page for every rule, or the IPQualityScore alternatives.

Get your API key

IPQualityScore is a trademark of its owner. Spaw is not affiliated with it. Markdown version: /compare/ipqualityscore.md