Spaw vs IPQualityScore
IPQualityScore sells fraud detection across several signals on one lookup credit: proxy and VPN detection, email verification and device fingerprinting all draw from the same monthly quota, and the IP answer carries a fraud score alongside the connection facts.
The table uses IPQualityScore's public pricing and documentation pages as checked on 2026-09-10, and Spaw's own pricing page. A row those pages carry no value for is marked "not on the pages read" rather than guessed at, and that is a statement about the reading and not about what IPQualityScore publishes.
| spaw | ipqualityscore | |
|---|---|---|
| Pricing model | Pay-as-you-go credit packs, or optional monthly plans that deposit the same credits every month for less; both through Stripe Checkout, credits from either never expire | Monthly plans by lookup quota: Free $0 (1,000 lookups a month), Startup "As low as: $99 / Month" (5,000), SMB Basic "$499" (10,000), SMB+ "$999" (75,000), Enterprise custom. "Any valid request sent to our Proxy Detection, Email Verification, or Device Fingerprinting services including lookups performed through a batch CSV file check will consume a lookup credit." |
| Free tier | 10 free credits every month, no card required | 1,000 lookups a month, capped at 35 a day |
| Price per 1,000 at about 10k | $7.80 (Growth pack: 5,000 credits for $39), or $5.80 on the Growth monthly plan (5,000 credits for $29 a month) | not on the pages read |
| Price per 1,000 at about 100k | $4.99 (Volume pack: 100,000 credits for $499), or $3.99 on the Volume monthly plan (100,000 credits for $399 a month) | not on the pages read |
| Addresses no feed covered billed | An answered address costs 1 credit whatever its flags say; a flag no feed could evaluate answers null rather than false, and the answer costs the same | not on the pages read |
| Reserved and private ranges billed | No: reserved, private, loopback, CGNAT, documentation and multicast ranges answer reason reserved_range and are free, and so are repeats within 7 days | not on the pages read |
| Feeds behind the flags | Public feeds, each named in the answer with the date it was synced: DB-IP Lite and RFC 8805 geofeeds for location, the five registries' delegated statistics for allocation, Spamhaus DROP and ASN-DROP and abuse.ch Feodo Tracker for blocklists, the Tor Project's exit list and Onionoo, the Mullvad, NordVPN and Private Internet Access server lists plus the open X4BNet lists, Apple's iCloud Private Relay egress list, the cloud providers' own published ranges, and the verification files Google, Microsoft, OpenAI, Perplexity, DuckDuckGo and Ahrefs publish for their crawlers. | Its own collection rather than published lists: "IPQS gathers data directly from our proprietary honeypots, traps, crawlers, and thousands of live sites opted into our threat intelligence network." The proxy detection answer carries proxy, vpn, tor, active_vpn, active_tor, fraud_score, ISP, organization, ASN, connection_type, recent_abuse, bot_status, is_crawler and the location fields. |
| Refresh cadence | Every feed re-syncs daily, the botnet command-and-control list hourly, and the geofeed crawl weekly. Each response names every dataset it consulted with the date it was last synced, and /status lists them all. | Not published as a schedule: the documentation says the data is collected continuously, "scanning billions of IP addresses every day", without naming a refresh cycle. |
| Geolocation source | The DB-IP Lite database, overridden wherever the operator publishes the location itself — an RFC 8805 geofeed, Apple's relay list, a VPN provider's server list. location_source says which answered, and location_confidence is graded from a weekly accuracy report rather than asserted. | Its own data: country_code, city, region, latitude, longitude, timezone and host come back with the fraud fields. |
| Bulk limit | 100,000 addresses per bulk job, with an HMAC-signed completion webhook | Batch CSV file checks are offered, and each row consumes a lookup credit; no row limit is published on the pages checked |
| Batch API | 1,000 addresses per synchronous request; repeats inside the list are looked up once | not on the pages read |
| Rate limit | 50 requests per second per key on the IP endpoints | 20 lookups a second on the SMB Basic plan; the other plans' limits are not stated on the page checked |
| Official SDKs | Python, Node.js, PHP | not on the pages read |
| Data retention | Nothing: no history row and no log line carrying the address, only a hashed 7-day marker that makes a repeat free. Bulk input lists and result files are deleted with the job after 30 days. | not on the pages read |
checked 2026-09-10 · sources: IPQualityScore plans, IPQualityScore proxy detection documentation
When IPQualityScore fits better
Teams that want one vendor, one credit pool and a single fraud score across IP, email and device signals.
- One credit pool across proxy detection, email verification and device fingerprinting
- active_vpn and active_tor are separate from vpn and tor, so a listed range and a live connection are different answers
- The free plan allows 1,000 lookups a month, capped at 35 a day
When Spaw fits better
Developers who want every public IP feed compiled, dated and named for them, with a risk score whose weights are published so it can be recomputed or ignored.
- Both sell several signals on one balance; IPQualityScore's are IP, email and device, Spaw's are email, phone, IP, address, business identity and the consistency check across them
- IPQualityScore's data is proprietary; every dataset behind a Spaw IP answer is a public feed named in the response with the date it was synced
- IPQualityScore's plans are a monthly quota that resets; Spaw's credits never expire and reserved ranges cost nothing
- Spaw publishes the weight behind every point of its risk score, so the number can be recomputed or ignored
Questions
Does Spaw charge for addresses its feeds do not cover?
Spaw bills per answered address. Reserved, private, loopback, CGNAT, documentation and multicast ranges answer reason reserved_range and are free, and so is a repeat of the same address within seven days. A flag no feed could evaluate answers null rather than false: the address still costs 1 credit, and the null tells you the signal was not checked instead of pretending it was. IPQualityScore does not publish how it bills them.
Can I run a log file or an export through Spaw?
Yes. A bulk run takes up to 100,000 addresses from the dashboard or the API and returns one row per input address, in input order, with every flag, the risk score and the signals that made it. Repeats inside the list are looked up once, reserved ranges cost nothing, and the finish is announced on an HMAC-signed webhook.
Is there a free tier?
Every Spaw account receives 10 free credits at the start of each month with no card on file, and unused credits accumulate. IPQualityScore offers: 1,000 lookups a month, capped at 35 a day.
Try Spaw on your own list
Free credits every month, no card. Upload a list, keep your columns, and download only the rows you want. See the pricing page for every rule, or the IPQualityScore alternatives.
IPQualityScore is a trademark of its owner. Spaw is not affiliated with it. Markdown version: /compare/ipqualityscore.md