Vultr IP ranges & what they mean for fraud
Vultr sells hourly VPS instances in dozens of regions, popular for lightweight proxies and automation runners.
How Maskbreak uses these ranges
Maskbreak tags traffic from these ranges with the dch (datacenter/hosting) signal in real time. The numbers above come from Vultr's own published range feed — the same feed Maskbreak's verdict pipeline refreshes daily, so a new range is scored within a day of publication, not whenever a static database ships.
Range data adds a signal; it never overrides deeper network detection. VPN exits live in datacenters, so a range hit doesn't short-circuit tunnel analysis — an IP in Vultr's ranges that is also a VPN exit gets both signals, and your policy sees the full picture in the reasons array.
What these ranges actually cover
Vultr publishes a geofeed covering its cloud compute and bare-metal instances across its global locations.
Vultr's hourly billing and instant provisioning across many countries make it a common choice for operators who want geographic variety cheaply — spinning up in one country, running briefly, and destroying the instance. Geographic diversity within Vultr's own ranges is therefore weak evidence of distinct actors, which matters if you are trying to count how many independent parties you are dealing with.
Where this provider shows up in abuse
The combination of per-hour billing and wide country coverage shows up in geo-targeted abuse, where the operator needs to appear local rather than needing capacity.
None of this makes a range match a verdict. In Maskbreak's pipeline a datacenter hit contributes 40 points toward a 0–100 risk score — enough to reach review, never enough to block on its own — and it never short-circuits tunnel detection, because VPN and proxy exits are themselves hosted in datacenters. Which AS announces a given address is a separate question, answered in the ASN directory.
Should you block Vultr traffic?
Small, cheap, many-region VPS hosts are exactly where one-off proxy exits and bot runners get spun up — and torn down before blocklists catch up.
The honest answer is: it depends on the surface. A datacenter IP on a signup, login, or checkout is a strong review signal — humans overwhelmingly arrive from residential and mobile networks. The same IP calling your API is often just a legitimate backend. Maskbreak returns the raw signal so you can apply exactly that asymmetric policy instead of a blanket block.
curl -X POST https://maskbreak.com/v1/evaluate \ -H "Authorization: Bearer sk_test_sandbox" \ -H "Content-Type: application/json" \ -d '{"token":"test_datacenter"}'
The sandbox key returns the documented datacenter-verdict shape (decision, risk_score, network.datacenter) — no signup required. Details in the API docs.
Free tier: 1,000 requests/hour. No card, no expiry.