IP risk score and snapshot
There are two data fields that provide an assessment of the level of risk associated with an IP address:
- IP risk score (minFraud only)
- IP risk snapshot (GeoIP insights and minFraud)
Both of these scores are given as a percentage that range from 0.01 to 99 where a higher score indicates a higher risk.
The key difference between these fields is how dynamic they are.
- IP risk score is a real-time dynamic score representing current risk associated with an IP.
- IP risk snapshot is a lookback value from the past 3 days.
Further down in this article we cover the difference between IP risk score and IP risk snapshot and how both of these fields provide unique value for fraud and security applications.
IP risk score
The IP risk score is available in all minFraud services: Score, Insights, and Factors.
It is given as a percentage ranging from 0.01 to 99. For example, an IP risk score of 15.40 means that the transaction has a 15.4% chance of being fraudulent based on the IP address alone.
If you're using IP risk scores for manual review as a minFraud Insights or Factors customer, you may also find it helpful to consult the IP risk data to give you a better picture of the transaction. Learn more about risk data related to IP risk reasons.
The IP risk score can be helpful in determining whether the risk score for a transaction is high because the transaction was conducted using a risky IP address. This can be helpful for manual review or if your business sees fraud linked to suspicious IPs and anonymizers.

minFraud Insights and Factors customers can get additional context about the reason for a high IP risk score using the IP risk reasons output, which is part of our risk data. Learn more about IP risk reasons.

The IP risk score is displayed at the top of the transaction review screen in the account portal, to the right of the risk score. Learn how to review transactions using the account portal.
The IP risk score may be returned when you pass the IP address as an input to any of the minFraud services.
Read the API specification for the IP address input on our developer portal:
IP risk snapshot
This field is available in GeoIP Insights, minFraud Insights, and minFraud factors.
This field contains a value that represents the level of risk associated with an IP address observed on our minFraud network in the past 3 days. The value ranges from 0.01 to 99. A higher score indicates a higher risk.
We do not provide an IP risk snapshot for low-risk networks. If this field is not populated, we either do not have signals for the network or the signals we have show that the network is low-risk. If you would like to get signals for low-risk networks, please use the minFraud web services.
Understanding the difference between IP risk score and IP risk snapshot
ip_address/riskis a dynamic score that will return the current level of risk associated with this IP address.trait/ip_risk_snapshotis more static thanip_address/risk, representing the level of risk observed on an IP network from the last three days.
minFraud customers may find the IP risk snapshot output useful to determine whether an IP address is risky based on historical activity versus a current, emerging issue.
- A lower
traits/ip_risk_snapshotscore combined with a higher minFraudip_address/riskwould mean that the IP address is becoming risky in real time based on the traffic on your and other customers’ networks. - A high score in both
trait/ip_risk_snapshotand minFraudip_address/riskwould mean that the IP address has been risky for a longer time.
You can read the API specifications for ip_address/risk and ip_risk_snapshot in our developer portal: