IP reputation feeds
CSV feeds of IPs seen in the last 1, 2, 7 or 15 days, plus a "most detected" list. Each row carries first seen, last seen, category and attack count.
IPSpamList runs honeypots and spam traps that log SSH brute force, mail server scans, Telnet and RDP probes, comment spam and other abuse. Every IP we catch is deduplicated, categorised and exported as a feed you can drop into a firewall, a fraud model or a threat-intel platform.
A blocklist built from real attacks, not from reports. Everything in the feed was observed hitting one of our own machines.
CSV feeds of IPs seen in the last 1, 2, 7 or 15 days, plus a "most detected" list. Each row carries first seen, last seen, category and attack count.
Feeds are regenerated hourly from the live database, so a scanner that showed up this morning is in your blocklist this afternoon.
The same data is one of the sources behind APIVoid's IP Reputation API, where it is queried millions of times a month.
Both families are logged, in separate feeds. IPv6 abuse is still a small fraction of IPv4, but it is there when you need it.
Collected by 300+ honeypots and spam traps across 25+ attack types: SSH, Telnet, RDP, SMTP, IMAP, SMB, MySQL, VNC, SIP and more.
Known-safe addresses are excluded before they can enter the list: search-engine crawlers, public DNS resolvers, uptime monitors and our own allow-list, kept up to date as they change.
Anyone who needs a fast answer to "has this IP been attacking servers recently?"
Enrich indicators with first/last seen dates, attack category and hit counts.
Add a signal to signup, login and checkout risk models. Fraud-prevention platforms integrate the feeds to sharpen their own detection.
Load the CSV into iptables, pfSense, MikroTik, Fortinet or any appliance that accepts an address list.
Reject SMTP, IMAP and POP brute-forcers before they reach the authentication layer.
Stop credential stuffing and automated signups from addresses already caught misbehaving elsewhere.
Years of categorised honeypot data for studying scanner behaviour and botnet churn.
Our decoy SSH, mail, web, database and IoT services accept the connection and log the source address.
The port and protocol decide the category: SSH brute force, Postfix scan, RDP, MS-DS, Mirai and so on.
Known addresses get their last-seen date and attack count bumped; new ones are inserted with a first-seen date.
Every hour the CSV feeds are regenerated. Subscribers fetch them with a key; IPs drop out after 15 days of silence.
Hourly CSV feeds of the IPs attacking our honeypots, ready for firewalls, fraud models and threat-intel platforms.