---
title: "How Spur IP Classifications Work: Observed Behavior, Not IP Ownership"
type: "explainer"
url: "https://docs.spur.us/knowledgebase/explainers/ip-classifications-observed-behavior"
category: "Security Operations"
product: "general"
publishedAt: "2026-09-15T00:00:00.000Z"
updatedAt: "2026-09-15T14:17:19Z"
---

# How Spur IP Classifications Work: Observed Behavior, Not IP Ownership

Spur classifications describe what was observed happening on an IP during a given window, not who owns the IP or ASN — a key distinction when investigating a classification that looks wrong.

Spur classifications are based on observed network behavior, not on ASN or IP block ownership records. An IP can be classified as a proxy, VPN, or tunnel endpoint because Spur observed that kind of traffic passing through it — independent of who the registered owner of that IP space is.

This is why an IP that resolves to a well-known, reputable organization in WHOIS or allocation records can still carry a proxy or anonymizing classification: shared infrastructure, misconfigured egress points, or recruited consumer devices can produce that traffic pattern regardless of who holds the registration.

When investigating a classification that looks unexpected, the useful questions are about the observation itself — what activity was seen, and during what time window — rather than about registration records alone. Classifications reflect a point in time; the same IP can carry different classifications, or none, at a different time as the traffic it carries changes.
