
MaxMind's GeoIP IP Risk database contains IP networks associated with
non-corporate proxies, VPNs, and other anonymous IP addresses, as well as IP
addresses associated with risky activity.

To learn more about the GeoIP IP Risk database, please see the
[GeoIP IP Risk database overview](https://get.maxmind.com/hubfs/Marketing/GeoIP%20IP%20Risk%20database/GeoIP%20IP%20Risk%20database%20product%20overview.pdf).
If you are interested in purchasing the database, please
[contact our Enterprise Business team](https://www.maxmind.com/en/solutions/connect-with-a-geoip-expert)
for assistance.

 **Data Privacy**

To comply with data privacy regulations, please monitor our
[Do Not Sell My Personal Information Requests](https://www.maxmind.com/en/accounts/current/do-not-sell-requests)
page (login required) for IP addresses and networks that should not be used for
advertising or marketing purposes. You can automate retrieval of this list using
our [privacy exclusions API](/geoip/privacy-exclusions-api). 


## Binary Database

Binary databases make use of the
[MaxMind DB file format](https://maxmind.github.io/MaxMind-DB/).

You can use the [mmdbinspect tool](https://github.com/maxmind/mmdbinspect) (in
beta), a command line interface built with Go, to look up one or more IPs from
one or more MMDB databases and receive output in a parsable JSON format.

[Learn about the fields in the binary version of this database on our binary
database field reference page.](binary/)

## CSV Database

In addition to our MaxMind DB binary format, we also offer GeoIP and GeoLite
databases in a CSV format suitable for importing into a SQL database. The CSV
files are shipped as a single
[zip file](<https://en.wikipedia.org/wiki/Zip_(file_format)>).




The zip file itself is named `GeoIP2-IP-Risk-CSV_{YYYYMMDD}.zip`.
The downloaded zip file contains a single directory which in turn
contains several files. That directory is named
`GeoIP2-IP-Risk-CSV_{YYYYMMDD}`.


The files in this zip archive are:

| Filename | Description |
|----------|-------------|
| `LICENSE.txt` | End user license |
| `COPYRIGHT.txt` | Copyright statement |
| `GeoIP2-IP-Risk-Blocks-IPv4.csv` | CSV file containing data on IPv4 addresses |
| `GeoIP2-IP-Risk-Blocks-IPv6.csv` | CSV file containing data on IPv6 addresses |


All the CSV files start with a single header row containing column names. The
specific column names and their contents are detailed below. The files are
encoded as UTF-8.


### Blocks Files

There are two CSV files for network blocks, one each for IPv4 and IPv6 blocks.
These are named `GeoIP2-IP-Risk-Blocks-IPv4.csv` and
`GeoIP2-IP-Risk-Blocks-IPv6.csv` respectively.



<div class="table">
  <table>
    <tbody>
      <tr>
        <th>Data field name</th>
        <th>Type</th>
        <th>Data field description</th>
      </tr>

      <tr>
        <td>network</td>
        <td>IP network as a string</td>
        <td>
          This is the IPv4 or IPv6 network in CIDR format such as
          "2.125.160.216/29" or "2001:c50::/32". We offer a utility to convert
          this column to start/end IPs or start/end integers. See
          <a href="#conversion-utility">the conversion utility section</a> for
          details.
        </td>
      </tr>

      <tr>
        <td>ip_risk</td>
        <td>decimal</td>
        <td>
          <p>
            This field contains the risk associated with the IP address. The
            value ranges from 0.01 to 99. A higher score indicates a higher
            risk.
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/minfraud-ip-risk-score"
            >
              Learn more about the IP risk score on our Knowledge Base.
            </a>
          </p>
          <p>min: 0.01, max: 99</p>
        </td>
      </tr>

      <tr>
        <td>is_anonymous</td>
        <td>boolean</td>
        <td>
          <p>
            1 if the IP address belongs to any sort of anonymous network. Blank
            if not.
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind#anon-detection"
              >Learn more about anonymizer and proxy detection on our Knowledge
              Base.</a
            >
          </p>
        </td>
      </tr>

      <tr>
        <td>is_anonymous_vpn</td>
        <td>boolean</td>
        <td>
          <p>
            1 if the IP address is registered to an anonymous VPN provider.
            Blank if not. If a VPN provider does not register subnets under
            names associated with them, we will likely only flag their IP ranges
            using the
            <code>is_hosting_provider</code> flag.
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind#VPN"
              >Learn more about VPNs on our Knowledge Base.</a
            >
          </p>
        </td>
      </tr>

      <tr>
        <td>is_hosting_provider</td>
        <td>boolean</td>
        <td>
          <p>
            1 if the IP address belongs to a hosting provider. Blank if not.
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind#hosting-provider"
              >Learn more about hosting providers used for anonymizing on our
              Knowledge Base.</a
            >
          </p>
        </td>
      </tr>

      <tr>
        <td>is_public_proxy</td>
        <td>boolean</td>
        <td>
          <p>1 if the IP address belongs to a public proxy. Blank if not.</p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind#public-proxies"
              >Learn more about public proxies on our Knowledge Base.</a
            >
          </p>
        </td>
      </tr>

      <tr>
        <td>is_tor_exit_node</td>
        <td>boolean</td>
        <td>
          <p>1 if the IP address is a Tor exit node. Blank if not.</p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind#tor-exit-nodes"
              >Learn more about Tor exit nodes on our Knowledge Base.</a
            >
          </p>
        </td>
      </tr>

      <tr>
        <td>is_residential_proxy</td>
        <td>boolean</td>
        <td>
          <p>
            1 if the IP address is on a suspected anonymizing network and
            belongs to a residential ISP (does not include peer-to-peer proxy
            IPs). Blank if not.
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind#residential-proxies"
              >Learn more about residential proxies on our Knowledge Base.</a
            >
          </p>
        </td>
      </tr>

      <tr>
        <td>provider_name</td>
        <td>string</td>
        <td>
          <p>
            The name of the VPN provider (e.g., <code>nordvpn</code>,
            <code>surfshark</code>) associated with the network.
          </p>
          <p>
            Please note that MaxMind identifies a subset of VPN providers. A
            current list of VPN providers identified in the IP Risk database is
            available on request.
          </p>
        </td>
      </tr>

      <tr>
        <td>anonymizer_confidence</td>
        <td>integer</td>
        <td>
          <p>
            A score ranging from 1 to 99 that is our percent confidence that the
            network is currently part of an actively used VPN service.
          </p>
          <p>
            Currently we will only provide values of 30 and 99, but the number
            of values will increase as we improve our confidence ratings.
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind"
              >Learn more about anonymizer confidence on our Knowledge Base.</a
            >
          </p>
        </td>
      </tr>

      <tr>
        <td>network_last_seen</td>
        <td>string</td>
        <td>
          <p>
            The last day that the network was sighted in our analysis of
            anonymized networks. This is in the ISO 8601 date format
            (YYYY-MM-DD).
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind"
              >Learn more about anonymizer and proxy detection on our Knowledge
              Base.</a
            >
          </p>
        </td>
      </tr>
    </tbody>
  </table>
</div>


### Conversion Utility

We've created a
[small utility program](https://github.com/maxmind/geoip2-csv-converter) to
allow you to convert a GeoIP CSV file's representation of IP addresses to
another format. You can choose between start/end IP addresses, with the
addresses represented as strings or integers.

The program is available from our
[geoip2-csv-converter GitHub project releases tab.](https://github.com/maxmind/geoip2-csv-converter/releases)


## Example Files

We maintain example files in CSV and MMDB format. The files contain dummy data
rather than real GeoIP data.


### CSV Example Files

We maintain examples of the CSV files as they would be downloaded from the account portal:



- [GeoIP2-IP-Risk-CSV_Example.zip](/examples/GeoIP2-IP-Risk-CSV_Example.zip)
  

### MMDB Example Files

We maintain test MMDB files on GitHub:



- [GeoIP2-IP-Risk-Test.mmdb](https://github.com/maxmind/MaxMind-DB/blob/main/test-data/GeoIP2-IP-Risk-Test.mmdb)
  

Alternatively, you can [view all of our MMDB test data on GitHub](https://github.com/maxmind/MaxMind-DB/tree/main/test-data).

## Database Sizes

<!-- prettier-ignore-start -->

MaxMind databases can vary in size from release to release. If you are
working with file size limitations that are concerning, you should build
your integrations to fail gracefully in event of a significant size
change.

From May to August 2026, the database files varied in file size and number of networks as
follows:

| Database | CSV File Size | MMDB File Size | IPv4 Networks | IPv6 Networks |
|----------|---------------|----------------|---------------|---------------|
- databaseName: "GeoIP IP Risk"
  csvSizeRange: "748 MB - 976 MB"
  mmdbSizeRange: "584 MB - 645 MB"
  ipv4Range: "19,530,000 - 24,682,000"
  ipv6Range: "796,000 - 7,370,000"

The listed file sizes are for unpacked databases. Databases are
downloaded in a compressed format.


<!-- prettier-ignore-end -->

## Database Changes

We may add new data fields to the IP Risk database at any time.

New database fields are added as new columns to the right of existing columns in our CSV files,
and as additional data in our MMDB files.

Subscribe to our [GeoIP release notes](/geoip/release-notes) to be notified when new
data is added to our databases.

## [GeoIP IP Risk binary database fields](/geoip/docs/databases/ip-risk/binary/)
<p>The GeoIP IP Risk binary database contains the following fields for each network.</p>


<div class="table">
  <table>
    <tbody>
      <tr>
        <th>Data field name</th>
        <th>Type</th>
        <th>Data field description</th>
      </tr>

      <tr>
        <td>anonymizer_confidence</td>
        <td>uint16</td>
        <td>
          <p>
            A score ranging from 1 to 99 that represents our percent confidence
            that the network is currently part of an actively used VPN service.
          </p>
          <p>
            Currently, we will only provide values of 30 and 99, but the number
            of values will increase as we improve our confidence ratings.
          </p>
          <p>
            <a
              href="https://support.maxmind.com/knowledge-base/articles/anonymizer-and-proxy-data-maxmind"
              >Learn more about anonymizer confidence on our Knowledge Base.</a
            >
          </p>

