Feeds refreshed every hour

The IP addresses attacking our honeypots, delivered to you hourly.

IPSpamList runs honeypots and spam traps that log SSH brute force, mail server scans, Telnet and RDP probes, comment spam and other abuse. Every IP we catch is deduplicated, categorised and exported as a feed you can drop into a firewall, a fraud model or a threat-intel platform.

  • 300+ active honeypots

What you get

A blocklist built from real attacks, not from reports. Everything in the feed was observed hitting one of our own machines.

IP reputation feeds

CSV feeds of IPs seen in the last 1, 2, 7 or 15 days, plus a "most detected" list. Each row carries first seen, last seen, category and attack count.

Refreshed every hour

Feeds are regenerated hourly from the live database, so a scanner that showed up this morning is in your blocklist this afternoon.

Used in production at APIVoid

The same data is one of the sources behind APIVoid's IP Reputation API, where it is queried millions of times a month.

IPv4 and IPv6

Both families are logged, in separate feeds. IPv6 abuse is still a small fraction of IPv4, but it is there when you need it.

20–30K unique IPs a day

Collected by 300+ honeypots and spam traps across 25+ attack types: SSH, Telnet, RDP, SMTP, IMAP, SMB, MySQL, VNC, SIP and more.

History back to 2016

Tens of millions of unique IPs with first-seen dates going back years, useful for spotting long-lived scanners and recycled address space.

Who uses the feeds

Anyone who needs a fast answer to "has this IP been attacking servers recently?"

Threat intelligence platforms

Enrich indicators with first/last seen dates, attack category and hit counts.

Fraud and risk scoring

Add a signal to signup, login and checkout risk models. Fraud-prevention platforms integrate the feeds to sharpen their own detection.

Company firewalls and routers

Load the CSV into iptables, pfSense, MikroTik, Fortinet or any appliance that accepts an address list.

Mail and hosting providers

Reject SMTP, IMAP and POP brute-forcers before they reach the authentication layer.

SaaS blocking abusive users

Stop credential stuffing and automated signups from addresses already caught misbehaving elsewhere.

Security research

Years of categorised honeypot data for studying scanner behaviour and botnet churn.

How an IP ends up in the feed

  1. A honeypot gets hit

    Our decoy SSH, mail, web, database and IoT services accept the connection and log the source address.

  2. The attack is classified

    The port and protocol decide the category: SSH brute force, Postfix scan, RDP, MS-DS, Mirai and so on.

  3. The IP is deduplicated

    Known addresses get their last-seen date and attack count bumped; new ones are inserted with a first-seen date.

  4. Feeds are exported

    Every hour the CSV feeds are regenerated. Subscribers fetch them with a key; IPs drop out after 15 days of silence.

Put the blocklist to work.

Hourly CSV feeds of the IPs attacking our honeypots, ready for firewalls, fraud models and threat-intel platforms.