Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About

Passive DNS
Real-Time Feed

Access Spamhaus' Passive DNS database via real-time feed and get immediate visibility into DNS activity worldwide. Gain a continuous stream of actionable DNS infrastructure insight, including CNAMEs, Nameservers, TXT, and MX records.

Trace malicious domains, monitor infrastructure changes, and investigate emerging threats by understanding how DNS records have changed over time — delivered directly to your systems.

Real-time updates

Continuous feed of recursive DNS data, providing immediate awareness of DNS changes and detection of potential threats.

High-quality, global data

A wealth of data from our extensive DNS sensor network provides comprehensive visibility of changes as they happen.

Easy to set up and integrate

Seamless integration into your existing data pipelines, with technical assistance to help get you started.

Spamhaus’ Passive DNS via Real Time Feed

Uncover a rich source of real-time data focussed on DNS infrastructure — the same trusted data used by Spamhaus researchers to support their investigations on a daily basis.

Integrate the live feed directly into your systems to continuously monitor recursive DNS traffic in real time, enhance threat detection, and gain immediate context on domains, IPs and hostnames to enrich ongoing investigations.

Why are there two different names for the data?

Our datasets have been supporting users for a very long time. With new users requesting our support, the dataset names are being updated for clearer understanding. We’re documenting two names, for now, to best support all users.

Datasets Included

Passive DNS

(Passive DNS)

A repository of DNS infrastructure connections, capturing CNAMEs, nameservers, TXT, MX, and other query responses over time. This dataset enables analysts and hunters to pivot, enrich indicators, track malicious infrastructure changes, and uncover related threats—critical for correlation, incident response, and proactive defense.

transition

Use cases for Passive DNS via Real-Time Feed

Deliver reliable, real-time Passive DNS (pDNS) data directly into security platforms and enrichment workflows.

Transition

For Threat Intelligence Enrichment

Built for security vendors, large enterprises, and law enforcement, the pDNS Real-Time Feed provides continuous visibility into live recursive DNS traffic. By ingesting a firehose of DNS resolution data in near real time, organizations gain constant comprehensive coverage.

This always-on data stream is essential for fueling proactive threat intelligence products, enabling automated detections, and tracking emerging malicious domains and cybercriminal infrastructure as they unfold.

Comprehensive coverage

Maintain visibility across global DNS activity to spot threats as they emerge.

Proactive intelligence

Detect new malicious domains and infrastructure early, accelerating response to evolving campaigns.

Automated enrichment

Continuous stream of rich IP and domain context - removing the need for time-consuming manual lookups.

Getting started

  • How to start a free 30-day trial

    Simply complete the form and submit. No credit card or payment details are required for the free trial.

    What happens next?

    Once you’ve completed the form to trial the Passive DNS Real Time Feed, one of our team will be in touch to get you set up with access.

    Need help?

    If you have any questions, please add them to the comments box below. Once you gain access to the data, support is available should you require any.

    Trial duration

    A free trial lasts for 30 days. You’ll receive an email notification before the trial expires. To continue accessing the services, simply log in to the Customer Portal, and click “request quote” to upgrade to a paid subscription.

  • System requirements

    Customers connecting to the Real Time Feed will have to connect utilizing a WireGuard VPN Client and a Kafka Client.

  • Technical documentation

    Full set up details for the Passive DNS via Real Time Feed are available in the customer portal once starting a free trial. Our team will provide support to set up access for all users.

  • Pricing

    Pricing is based on monthly query volume, with final costs provided after the trial based on actual usage. Alternatively please contact our sales team.

Ready to start
your free trial?

Get a free 30-day trial of the Passive DNS via Real Time Feed. No credit card details required.

Sign up

Frequently Asked Questions

  • What is Passive DNS data?

    It is a log of DNS queries and answers over time, recording the mappings between domain names and IP addresses. The data consists of anonymized DNS queries, collected from recursive DNS servers worldwide. It includes a number of different internet records including: IPs, domains, hosts, name servers, and canonical names. Using the Passive DNS Real Time Feed, you can uncover the connections between these records.

    You can learn more about where passive DNS data comes from in "What is Passive DNS? A beginner’s guide".

  • Where does Passive DNS data come from?

    We collect feeds from both our own systems and trusted partners, and we also perform targeted lookups. Every entry in our database represents an actual result from a live DNS server.

  • Who can use Passive DNS via Real-Time Feed?

    There are many ways to use this data, including but not limited to: Security research: to investigate suspicious domains and identify associated and related malicious infrastructure.

    • Network monitoring: find out what domain names point to your IP space.
    • Malware research: to trace malicious domains, and minimize the need for complex reverse engineering malware.
    • Incident response: understand the extent of a security incident by identifying affected domains and related infrastructure.
    • Brand protection: to monitor for infringement of copyright and brands by detecting spoofed domains.

Data Access

abuse.ch Real-Time Feeds

Real-time stream of enriched indicators to enhance threat detection, triage, hunting, and enrichment workflows. Gain immediate access to fresh IOCs and dataset changes to proactively identify threats before they cause damage.

Learn More

Data Access

Intelligence API

Integrate context-rich metadata relating to IP and domain reputation to enhance existing data feeds, or consume as an independent data source. Gain additional intelligence to monitor, assess and remediate as required.

Learn More

Data Access

Passive DNS API

A simple API supporting a variety of query types to discover historical, and up-to-the-moment, DNS infrastructure connections from Spamhaus’ Passive DNS database with up to one year of historical data.

Learn More