Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About

DNS Blocklists
via HTTPS

Query a wide range of real-time DNS Blocklists (DNSBLs) covering IPs, domains, and hashes (including malware files, cryptowallets, email addresses and URLs). Use for protection or get a quick, binary indication on whether an internet identifier is positive or negative in reputation.

Fast response

Low latency, high efficacy data to understand Internet identifier reputation with speed.

Immediate & trusted signals

Real-time updates with low-false positive rates.

No additional costs

Easily integrated into your existing infrastructure.

DNS Blocklist data via HTTPS

Query DNSBLs in real-time with Spamhaus’ Web Query Service (WQS). Easily integrate email threat data into your infrastructure to prevent malicious activity. This data provides a quick, cost-effective way to understand reputation, giving a strong signal for where to focus your research, hunt or investigate.

Why are there two different names for the data?

Our datasets have been supporting users for a very long time. With new users requesting our support, the dataset names are being updated for clearer understanding. We’re documenting two names, for now, to best support all users.

Datasets Included

Botnet C2 IPs

(Botnet Controller List - BCL)

Botnet command and controller (C2) servers. The status of these single IPv4 addresses is re-evaluated several times a day to identify active botnet controllers only. Utilize for protection or threat intelligence requirements.

Bruteforce IPs

(Authentication Blocklist - AuthBL)

Compromised IPs

(Exploits Blocklist - XBL)

Email Spam IPs

(Combined Spam Sources - CSS)

Highly Malicious Networks

(Don't Route Or Peer - DROP)

Low Reputation Domains

(Domain Blocklist - DBL)

Low Reputation Resources

(Hash Blocklist - HBL)

Malicious network ranges

(Spamhaus Blocklist - SBL)

Non-mail emitting IPs

(Policy Blocklist - PBL)

Zero reputation domains

(Zero Reputation Domains - ZRD)

transition

Use cases for DNS Blocklist data via HTTPS

This real-time data has several applications, including protecting your email infrastructure, wider network, and users from email-borne threats, in addition to enrichment for threat intelligence tools and workflows.

Please note: This service provides real-time data and does not make available historic data. If you require this information, please trial via API here.

Threat Intelligence Enrichment
Email Compliance
Threat Intelligence Enrichment
Transition

Blocklist data via HTTPS for Threat Intelligence Enrichment

Simply, this service provides a binary yes/no, listed/not listed response. Using HTTPS in JSON format, this data is very flexible. One common CTI use case, to keep query volumes down and reduce low-impact alerts, is a quick response on internet identifiers that might be of most concern, e.g. botnet C2 IPs.

On understanding whether the identifier is listed, you gain a clear indicator that further research should be conducted to get the full picture, and what the means for your company/clients. This keeps data costs low and the ability to pivot fast.

Proactive signals

Our Domain datasets and Non-mail emitting IPs (Policy Blocklist) can protect against threats before they are seen in the wild.

Flexible data

Supported across most programming languages, CTI platforms, and threat feeds. Quickly plug into your SIEM, detection systems, or custom pipelines.

Real-Time Retrieval

To support live threat hunting or continuous threat monitoring, where data ingestion can be automated.

Getting started

  • How do I start a free 30 day trial?

    Simply complete the form and submit. No credit card or payment details are required for the free trial.

    What happens next?

    You’ll receive an email asking you to verify your address. If you haven’t already, you’ll be prompted to create an account.

    Once verified, log in to the Customer portal to view your access key and follow the setup instructions provided in the manual.

    Need help?

    If you have any questions, please add them to the comments box below. Once you gain access to the data, technical support is available via our Customer Portal.

  • Technical documentation

    Our documentation page provides full setup details for accessing Blocklist Data with HTTPS Access via the Web Query Service.

  • Pricing and purchase

    During your free trial, you can request a quote in the Customer Portal to get the subscription cost based on your setup. You can also enable trials of additional datasets via the Customer Portal.

Ready to start
your free trial?

Get a free 30 day trial to query Spamhaus’ real-time DNSBLs via the Web Query Service (WQS). No credit card details required.

Sign up

Frequently Asked Questions

  • Who can use the Web Query Service?

    • Threat Intelligence Enrichment - this service is relevant for Security Engineers, Product Managers, and IR Specialists.

    • Email Protection and Compliance - Email administrators and email engineers running their own mail transfer agent (MTA) or email infrastructure.

Explore more

Data Access

Intelligence API

Integrate context-rich metadata relating to IP and domain reputation to enhance existing data feeds, or consume as an independent data source. Gain additional intelligence to monitor, assess and remediate as required.

Learn More

Data Access

Spamhaus Consultancy

Data-driven consultancy to help networks prevent and resolve email-related challenges. By utilizing our unique internal databases against specific behavior patterns, we provide tailored, data-driven reports and actionable 1:1 advice.

Learn More

Data Access

Rsync

Incremental synchronization of binary and contextual datasets to local servers, including access to our entire binary DNS blocklist data. Efficiently transfer data by only copying changes between the source and destination.

Learn More