Why is a Cloudflare IP address classified as Anonymizing?
Some IPs belonging to a CDN like Cloudflare are classified as Anonymizing because they're used as the TLS entry point for an anonymizing tunnel service. The connecting client's TLS handshake names a legitimate-looking hostname, and the CDN routes the traffic to unrelated tunnel infrastructure behind it — the named domain and the CDN provider itself aren't involved in or aware of the proxying. In Spur's data this is reflected in the `tunnels` field, which distinguishes an IP's role as a tunnel entrance from its role as an exit. If your use case depends specifically on identifying egress points, you can filter out entrance-only IPs, since these are rarely also used as an exit for other services.
Similar questions
How does Spur integrate with our existing technologies (Cloudflare, etc.)?
Many customers integrate Spur intelligence into web security, fraud prevention, and access control workflows. Available integration methods may vary depending on the platform and use case.
What Proxy or VPN services are known bad?
Some services tend to be more abuse than others. It is important to remember that because abuse is ultimately driven by the users of a service, this can ebb and flow depending on different threat actors, techniques, and targets. We recommend looking for services that explicitly enable anonymous purchases without logging and services that are frequently sourced by malware.
Can a single IP address be associated with more than one proxy or anonymization service?
Yes. Shared infrastructure, reseller arrangements, and overlapping proxy ecosystems can result in an IP being associated with multiple services. Determining the exact service responsible for a specific event often requires additional context and investigation.
How does Spur detect VPNs, residential proxies, and ISP proxies?
Spur uses a combination of network intelligence, infrastructure analysis, behavioral signals, routing characteristics, historical observations, and proprietary research to identify and classify IP addresses. Multiple signals are evaluated together to determine the likelihood that an IP belongs to a VPN, residential proxy network, ISP proxy service, hosting provider, or other category.
Why are residential proxies more difficult to detect than traditional VPNs?
Residential proxies route traffic through real consumer internet connections, causing activity to appear as if it originates from legitimate users. Because the IP addresses belong to trusted ISPs rather than known hosting providers, traditional reputation and geolocation controls are often less effective.