Find out whether an IP address appears on public blacklists, which ones, and why.
Free, no signup. Checked against 140+ public blocklists rebuilt every day.
An IP blacklist (or blocklist) is a published list of addresses that someone observed doing something unwanted: sending spam, brute-forcing SSH, scanning ports, hosting malware, or relaying traffic as an open proxy. Mail servers, firewalls, CDNs and fraud filters consume these lists automatically, so an address that lands on a few of them starts to meet closed doors: bounced mail, captchas, blocked logins, failed API calls.
IPGuardian aggregates more than 140 public lists from FireHOL, Spamhaus DROP, Emerging Threats, DShield, Blocklist.de, AbuseIPDB-derived feeds, StopForumSpam, the Tor Project and others, over 2.1 billion addresses including listed ranges. The result names every matching list, its category and its maintainer, so you know who to talk to.
One list is weak evidence. Addresses are shared behind NAT, reassigned by providers, and sometimes listed as whole ranges because of a neighbour. Several independent lists in the attack and abuse categories is a strong signal: in our own measurement, 78% of hosts that brute-forced our SSH were on ten or more lists at the moment of the attack.
Yes. There is no signup and no API key, for the web form and for the API alike.
All source lists are downloaded again and rebuilt once a day.
Yes, the API accepts up to 100 addresses per request. See the documentation.
No. Lists lag behind: roughly one attacker in ten is unknown to every list at the moment of a first attack.