IP Blacklist Check

Find out whether an IP address appears on public blacklists, which ones, and why.

Free, no signup. Checked against 140+ public blocklists rebuilt every day.

What an IP blacklist is

An IP blacklist (or blocklist) is a published list of addresses that someone observed doing something unwanted: sending spam, brute-forcing SSH, scanning ports, hosting malware, or relaying traffic as an open proxy. Mail servers, firewalls, CDNs and fraud filters consume these lists automatically, so an address that lands on a few of them starts to meet closed doors: bounced mail, captchas, blocked logins, failed API calls.

What this check covers

IPGuardian aggregates more than 140 public lists from FireHOL, Spamhaus DROP, Emerging Threats, DShield, Blocklist.de, AbuseIPDB-derived feeds, StopForumSpam, the Tor Project and others, over 2.1 billion addresses including listed ranges. The result names every matching list, its category and its maintainer, so you know who to talk to.

How to read the result

One list is weak evidence. Addresses are shared behind NAT, reassigned by providers, and sometimes listed as whole ranges because of a neighbour. Several independent lists in the attack and abuse categories is a strong signal: in our own measurement, 78% of hosts that brute-forced our SSH were on ten or more lists at the moment of the attack.

If your own address is listed

  1. Find the cause first. Scan the machine, check outgoing mail and traffic, change credentials. Delisting a still-infected host lasts a day.
  2. Look at the list names in the result. Each maintainer has its own removal procedure; many lists expire entries automatically after days or weeks without new reports.
  3. If the address is dynamic or shared, ask your provider for a different one, or for the range to be cleaned up.

Frequently asked questions

Is the check free?

Yes. There is no signup and no API key, for the web form and for the API alike.

How fresh is the data?

All source lists are downloaded again and rebuilt once a day.

Can I check many addresses at once?

Yes, the API accepts up to 100 addresses per request. See the documentation.

Does a clean result mean the address is safe?

No. Lists lag behind: roughly one attacker in ten is unknown to every list at the moment of a first attack.