Google Cloud IP ranges & what they mean for fraud
Google Cloud Platform publishes its customer-usable ranges separately from Google’s own crawler infrastructure — these pages track the customer ranges.
How Maskbreak uses these ranges
Maskbreak tags traffic from these ranges with the dch (datacenter/hosting) signal in real time. The numbers above come from Google Cloud's own published range feed — the same feed Maskbreak's verdict pipeline refreshes daily, so a new range is scored within a day of publication, not whenever a static database ships.
Range data adds a signal; it never overrides deeper network detection. VPN exits live in datacenters, so a range hit doesn't short-circuit tunnel analysis — an IP in Google Cloud's ranges that is also a VPN exit gets both signals, and your policy sees the full picture in the reasons array.
What these ranges actually cover
Google publishes customer-usable ranges in cloud.json, kept deliberately separate from goog.json, which contains Google's own infrastructure including Googlebot. Maskbreak tracks only the customer list.
That separation matters more here than anywhere else on this page. Matching against Google's combined ranges is how teams accidentally flag Googlebot as datacenter abuse and quietly damage their own crawl coverage. If you build this yourself, use the customer list and nothing else.
Where this provider shows up in abuse
Generous trial credits have long made GCP a favourite for burst scraping and abuse experimentation, while the same ranges carry a very large volume of legitimate server-to-server API traffic.
None of this makes a range match a verdict. In Maskbreak's pipeline a datacenter hit contributes 40 points toward a 0–100 risk score — enough to reach review, never enough to block on its own — and it never short-circuits tunnel detection, because VPN and proxy exits are themselves hosted in datacenters. Which AS announces a given address is a separate question, answered in the ASN directory.
Should you block Google Cloud traffic?
GCP free-tier credits have historically made it a favourite for burst scraping and abuse experiments; its ranges also host plenty of legitimate APIs.
The honest answer is: it depends on the surface. A datacenter IP on a signup, login, or checkout is a strong review signal — humans overwhelmingly arrive from residential and mobile networks. The same IP calling your API is often just a legitimate backend. Maskbreak returns the raw signal so you can apply exactly that asymmetric policy instead of a blanket block.
curl -X POST https://maskbreak.com/v1/evaluate \ -H "Authorization: Bearer sk_test_sandbox" \ -H "Content-Type: application/json" \ -d '{"token":"test_datacenter"}'
The sandbox key returns the documented datacenter-verdict shape (decision, risk_score, network.datacenter) — no signup required. Details in the API docs.
Free tier: 1,000 requests/hour. No card, no expiry.