Check an IP address

Enter an IPv4 or IPv6 address to see whether our honeypots have logged it, when it was first and last seen, what it was doing and how many times it hit us. Want to automate the check? Try the IP Reputation API by APIVoid.

IP lookup

Results will be shown here
  • First seen

    The first time the address hit one of our honeypots.

  • Last seen

    The most recent detection. An IP leaves the feeds 15 days after this date if it stays quiet.

  • Category

    The service it attacked: SSH, Postfix, IMAP, RDP, MS-DS, Telnet and so on.

  • Attacks logged

    How many separate days the address was seen.

Most detected

The addresses with the highest number of attack days on record, refreshed hourly.

#IP addressCategoryFirst seenLast seenActive forAttack days
1 66.240.205.34 Unclassified 2017-05-03 2026-10-08 3,445 days 3,065
2 93.174.95.106 Socks Scan 2017-04-04 2026-10-08 3,473 days 2,991
3 71.6.146.185 Imap 2017-01-20 2026-10-08 3,548 days 2,872
4 71.6.146.186 Imap 2016-11-23 2026-10-08 3,606 days 2,825
5 94.102.49.193 Imap 2016-10-17 2026-10-08 3,643 days 2,809
6 66.240.192.138 Postfix 2016-11-04 2026-10-08 3,624 days 2,675
7 66.240.219.146 Imap 2016-12-17 2026-10-08 3,581 days 2,630
8 71.6.167.142 Imap 2016-10-17 2026-10-08 3,643 days 2,581
9 80.82.77.139 FTP 2017-03-27 2026-12-31 3,566 days 2,579
10 66.240.236.119 Postfix 2017-03-22 2026-12-31 3,571 days 2,577

Questions

My IP is listed. How do I get it removed?

Removal is automatic. Stop the abusive traffic and the address drops out of the feeds after 15 days without new detections. See the IP removal page for a cleanup checklist.

Can I query this page from a script?

No. The lookup is protected by a captcha on purpose. If you need bulk or automated checks, subscribe to the feeds or use APIVoid's IP Reputation API, which includes this data.

Why is my server's IP listed when I never attacked anyone?

Usually because a compromised process on the machine is scanning the internet, or the address was recently reassigned from someone who did. Check for malware, unexpected outbound connections and unknown cron jobs.

Do you list IPv6 addresses?

Yes. IPv6 detections are stored separately and are far fewer than IPv4, but the lookup checks both families.

Put the blocklist to work

Hourly CSV feeds of the IPs attacking our honeypots, ready for firewalls, fraud models and threat-intel platforms.