SOC status:Duty analyst on shift

UK Cyber Defence

Tools / Reputation

Is this address, or this domain, known to be bad?

An IP in your firewall log, the sender of an odd email, a domain in a link you are not sure about. Enter it and get what the public threat feeds, mail blocklists, registries and DNS say about it, in one page, with a verdict in plain English.

Threat feeds · Mail blocklists · ASN · RDAP · Reverse DNS · Domain age · LookalikesFree · No sign-up · PDF and JSON

What it checks

Public threat feeds

abuse.ch Feodo Tracker and ThreatFox (botnet C2), Spamhaus DROP, Emerging Threats compromised hosts, CINS Army, blocklist.de, the DShield top networks and the Tor exit list, refreshed daily and matched by range.

Mail blocklists

Spamhaus ZEN, SpamCop, PSBL and UCEPROTECT, with the return codes read for you: a spam source, an infected machine, or just end-user space that should not be sending mail directly.

Who is behind it

The origin AS and prefix from Team Cymru, the holder and abuse contact from the regional registry's RDAP record, reverse DNS and whether it is forward-confirmed.

Threat assessment

When enabled, ipinsights.io adds location, operator, proxy/VPN/Tor and data-centre flags, its own blocklist matches and a threat score with reasons.

Domains: age, name and hosting

Registration date, registrar and status over RDAP; the URLhaus and ThreatFox host lists; lookalike, punycode and bulk-registration patterns in the name; and every address it resolves to, assessed as above.

A report you can act on

Graded A to E, every finding with the evidence and what to do about it, PDF and JSON, and nothing sent to the target.

How to read it

Reputation is a record of what an address or a name has been seen doing, kept by people who watch a lot of traffic. It is a strong signal when it is bad — a botnet controller is a botnet controller — and a weak one when it is clean, because most attacks come from addresses that were clean last week. So use a bad result to decide, and a clean result to look elsewhere: the header analyser for an email, the email security check for a domain’s mail defences, the DNS audit for what its records leak.

For domains, age matters more than any list. Most phishing domains are registered, used and abandoned within weeks; an organisation that has held its name for ten years is a different proposition. The lookup reads the registration date over RDAP, which is the registries’ own protocol, and flags the shapes lookalike domains take: a brand’s name inside a domain the brand does not own, a character swapped for a digit, accented characters that render like Latin ones, and deep sub-domains that push the real name out of sight.

Every feed used here is public and free with attribution, and every listing links to its source. The data is held on our own server and refreshed nightly, so a lookup sends nothing about you to a third party except, when enabled, the address itself to ipinsights.io. Nothing at all is sent to the target.