Removing an IP address

Delisting is automatic and cannot be requested by email. An address is removed from every feed, and from the services that consume them, once our honeypots have not seen it for 15 days.

How delisting works

There is no form and no manual review, because the list only reflects what the honeypots observe. Stop the traffic and the clock starts.

  1. Confirm the address is listed

    Use the IP lookup to see the category and last-seen date, or run a broader check on APIVoid's IP Reputation Checker, which queries many blocklists at once.

  2. Find and stop the source

    The category tells you what to look for: "SSH Brute Force" means something on your side is scanning port 22, "Postfix" or "Imap" points at a mail scanner, "MS-DS Attack" at SMB probing on port 445.

  3. Wait 15 days

    If the address is not logged again, it drops out of the feeds automatically. Any new detection resets the counter, so make sure the traffic has really stopped.

  4. Verify

    Look the address up again. A "not listed" result means the removal has propagated to every feed and to services built on them.

Cleanup checklist

Most listed servers are not run by attackers. They are compromised, misconfigured or freshly assigned an address with a bad history.

Look for malware and rogue processes

Check running processes, cron jobs, systemd units and recently modified binaries. Web shells inside CMS upload folders are a common source of outbound scanning.

Watch outbound connections

Run ss -tunp or netstat and look for connections to ports 22, 23, 25, 445, 3389 on many different hosts. A legitimate server rarely opens hundreds of these.

Block outbound ports you do not use

Deny outgoing TCP and UDP to ports that are commonly scanned (445, 23, 2323, 1433, 3389, 5060) unless the machine genuinely needs them.

Rotate credentials

If you found a compromise, change SSH keys, database and mail passwords, and API tokens stored on the host. Reinstalling is often faster than cleaning.

Check mail and web forms

Open relays, contact forms without rate limits and comment sections without anti-spam get abused for spam runs that trip our traps.

Shared or dynamic address?

On carrier-grade NAT, VPN exits or cloud ranges, another tenant may be the cause. Ask your provider for a different address or a dedicated one.

Questions

Can you delist my IP right now?

No. We do not delist manually; the data would be inconsistent with what the honeypots see. Stop the traffic and the address is gone in 15 days.

My IP was listed years ago. Is it still on the list?

Only if it kept attacking. The feeds only contain addresses seen in the last 15 days; older records stay in our history but are not distributed.

I stopped the traffic but the last-seen date keeps moving.

Something is still reaching us. Double-check for a second compromised host behind the same NAT, a scheduled task, or a container you forgot about.

Which services will still block me after delisting?

Any service that fetches the feed hourly, including APIVoid, will drop the address at its next refresh. Services that cache older copies may take longer.

Is your IP on the list?

Look up any IPv4 or IPv6 address to see whether our honeypots have logged it, what it was doing and when it was last seen.