Is 185.228.168.9 a VPN? No — Daniel Cid.
No VPN/proxy indicators — 2 signals matched across 2 intelligence sources. Overall risk: low.
BGP routing topology
RIPE NCC routing-information service. Single-homed ASes and unannounced prefixes.
ASN AS205157 is single-homed (1 upstream, 1 total neighbours) — lone-wolf BGP footprint common to proxy-operator ASes
ASN classification
Team Cymru allocation data + PeeringDB self-declared network type.
trusted public-DNS anycast IP — datacenter/hosting signals suppressed
Should I block this IP?
Practical guidance by use case — fraud, ad-ops, streaming, and general websites.
No VPN, proxy, datacenter, or Tor signals matched. The IP looks like a real consumer or business broadband line. Treat as a normal user.
- Fraud / risk teams
- Apply your standard risk model. No IP-based step-up needed.
- Ad ops / programmatic
- Bid normally. This IP is in your billable, real-human pool.
- Streaming / geo-licensing
- Allow. Geo-licensing rules still apply, but VPN evasion is not a concern here.
- General sites & forums
- Standard access. Use other signals (device fingerprint, behavior, account age) for risk scoring.
About IP address 185.228.168.9
185.228.168.9 is an IPv4 address routed via AS205157 (Daniel Cid) and geo-located to United States. The verdict above combines six free, no-auth intelligence sources: local db-ip ASN data, the Tor Project exit list, public proxy feeds (TheSpeedX / Proxifly / FireHOL), Team Cymru + PeeringDB for ASN classification, RIPE NCC for BGP topology and abuse contacts, and Shodan InternetDB for ~30-day port observation.
Verdicts are recomputed on every page load and cached for up to one hour upstream. No data about your browser or identity is persisted.