IP & Network Intelligence
Diliguard provides IP and network intelligence to expose masked traffic. We detect residential proxies and VPNs to intercept coordinated fraud rings.
What Is IP & Network Intelligence?
Diliguard’s IP & Network Intelligence module determines an IP address’s physical location, the network or hosting provider it belongs to, and whether it is being routed through a proxy or VPN. Paired with a domain scan, it also verifies whether a website’s DNS and email authentication records are correctly configured.
How IP & Network Intelligence Works
- Geolocation: Resolves an IP address to a country and city or region.
- Network Attribution: Identifies the ASN (the organization that owns the IP block), which distinguishes a residential connection from a datacenter or hosting provider.
- Proxy and VPN Detection: Flags whether the connection is routed through a known proxy or VPN service, the detail that determines whether digital activity’s stated location is real.
- Domain WHOIS and DNS Verification: Checks a domain’s MX, SPF, and DMARC records, and pulls WHOIS registration details including registrar, creation date, and country, to assess whether a website is properly configured or newly registered.
What Diliguard Returns
An IP check returns Location Details (for example “New York, New York, United States”) and Network Details showing the ASN name and a red “Yes” flag if a proxy or VPN was detected. A paired domain scan returns a Domain Summary card marking MX, SPF, and DMARC each as “Yes” (green) or “No” (red), plus WHOIS Records showing the registrar, creation date, and country of registration where available.
Data Sources and Coverage
IP geolocation and ASN attribution query network infrastructure databases directly, which cover public IP address space globally, not a jurisdiction-limited subset. Domain WHOIS and DNS checks query public domain registration and DNS records, which exist for any registered domain regardless of country.
Frequently Asked Questions
Can VPN or proxy detection be bypassed?
No detection method is absolute against every masking technique, but the check flags known commercial VPN and proxy infrastructure, which covers the overwhelming majority of masked-location attempts encountered in onboarding and fraud contexts.
Does a newly registered domain automatically mean it’s fraudulent?
No. A recent WHOIS creation date is a risk signal to weigh alongside other findings, not a standalone determination. Diliguard surfaces the date; the compliance decision remains with the reviewer.
Is this check useful without a paired domain or email?
Yes. The IP check runs independently and is commonly used on its own to verify the origin of a transaction, login, or registration event.
How is this different from a standard IP geolocation lookup?
A standard geolocation lookup stops at country and city. Diliguard adds ASN/network provider attribution and explicit proxy/VPN flagging, which is the layer that actually detects location-masking rather than just reporting an unmasked address.
Where This Fits
IP & Network Intelligence supports Trust & Company Service Providers in detecting coordinated shell-entity formation sessions, and feeds directly into Transaction Risk Scoring and the Crypto Investigation Workflow wherever network origin needs to be checked alongside a financial event.
Architecture and Integration
This scan is available standalone or as a module inside the Crypto Investigation Workflow and the Infrastructure & Cyber Risk workflow. Teams integrate it via the Developer API at api.diliguard.com, authenticated with an API key created from the portal’s Settings page, or call it through the @sluxia/diliguard-mcp MCP server for agent-driven checks.