IP Report

185.220.101.25

Stiftung Erneuerbare Freiheit · AS60729 · Berlin, Germany

85/100
High risk
0–1920–4950–7980–100

Score 85 of 100, in the high risk band. Bands run 0 to 19 minimal, 20 to 49 low, 50 to 79 medium, 80 to 100 high.

Its risk score of 85/100 is high: multiple strong signals stack up here, and most sites that screen traffic would challenge or block requests from this address.

Detection signals

Anonymity signals— act on these
Tor exit node
Active Tor exit node
0.99
Verified
VPN infrastructure
Commercial VPN provider's published ranges
0.85
High
Infrastructure facts— context, not accusations
Datacenter
Listed in a published datacenter range feed
0.95
Verified
Hosting network
ASN classification

Not detected: Proxy, Crawler

Summary

185.220.101.25 is a Tor exit node — traffic leaving the Tor anonymity network reaches the open internet from this address, which means the person or program behind a request cannot be identified from the IP alone.

The address is announced by Stiftung Erneuerbare Freiheit (AS60729) and geolocates to Berlin, State of Berlin, Germany.

Why this address scores 85

It is a listed Tor exit node — the strongest single signal we score, because Tor exits are shared by everyone using the network, including its worst actors.

It falls within IP ranges operated by VPN providers, so the address conceals where its traffic really originates.

It sits in datacenter address space, where automated traffic vastly outnumbers human visitors.

Together these produce the score of 85/100 shown above.

Observation history

This address has been looked up through Predax once, on August 31, 2026.

Network & location

ASN
AS60729
Country
Germany (DE)
Provider
Stiftung Erneuerbare Freiheit
Region
State of Berlin
CIDR
185.220.101.0/23
City
Berlin
Network type
hosting
PTR
berlin01.tor-exit.artikel10.org
First seen
8/31/2026, 2:30:54 PM
Last seen
8/31/2026, 2:30:54 PM
Times seen
1

What to do with this

If you run a site and this address showed up

Tor exits carry both abuse and legitimate privacy-conscious visitors, and you cannot tell which from the address alone.

Blocking this address at checkout, login, or signup is a defensible default. For ordinary content pages, a challenge (CAPTCHA) keeps the privacy-conscious readers you may want while stopping automation.

Applying that default does not require touching a block list: the Predax Security plugin for WordPress can block or challenge Tor exits at login and signup automatically, and the WooCommerce fraud plugin does the same at checkout.

If you found this address in your logs

A request from this address tells you nothing reliable about the client’s location or identity — that is what Tor is for.

Per-IP rate limits and geo checks are unreliable here: every Tor user sharing this exit looks identical. Key abuse decisions on the account or session instead of the IP.

Loading map...

Detection sources

  • DatacenterVerified · 95%

    Listed in a published datacenter range feed. Hosted in a cloud / datacenter range. Typical of automation, scrapers, and bots — not consumer browsers.

  • VPNHigh · 85%

    Commercial VPN provider's published ranges. Traffic from a VPN exit. Could be a privacy-conscious user, or an adversary using a VPN to evade rate limits — context matters.

  • TorVerified · 99%

    Active Tor exit node. Tor exit node. Anonymous traffic used by privacy advocates and adversaries alike.

Check Another IP