IP Address Lookup & Reputation Database

See the truth behind every IP address. We combine WHOIS, ASN, geolocation, abuse history and 42 open threat-intelligence feeds into a single lookup. Protect your servers, network and users from malicious IPs.

No account required Sources are open and listed Refreshed every 30 minutes Free API tier
Your IP address: 18.97.14.85 View full report →
Sample report Live record from the pool
CountryUnited States · Irvine
ASNAS7018 · AT&T Enterprises, LLC
Blacklist MatchesListed by 1 sources
Abuse.ch ThreatFox Botnet C2
377.364 Malicious IPs/Networks Tracked
42 Open Threat-Intel Sources
10.000 Free API Checks / Day
Works with the tools you already run

Complete IP intelligence in one place

From ownership records to network reputation — every signal you need to make a decision.

WHOIS & RDAP

Query network owner, allocation record and contact details live via the standard RDAP protocol.

Geolocation & ASN

Resolve country, city and autonomous system number in milliseconds from locally hosted databases.

Blacklist Pool

Cross-reference against open threat data aggregated daily from Spamhaus, abuse.ch, FireHOL and more.

Live DNSBL Checks

Real-time queries against major DNS blocklists like Spamhaus ZEN, SpamCop, Barracuda and SORBS.

Community Reports

Abuse incidents reported by our users keep the confidence score continuously up to date.

Developer API

Simple REST endpoints, an API key and transparent daily limits — integrate into your app in minutes.

Recently Reported IP Addresses

Malicious source activity arriving from the community and the automated feeds, as it lands.

IP Address Category / Threat Country ASN Risk Score Time
43.229.114.114 Botnet C2 Server United States AS138415 90/100 27 minutes ago
64.89.163.224 Attack Source Germany AS401626 90/100 27 minutes ago
188.43.28.193 Attack Source Russia AS20485 90/100 27 minutes ago
222.116.28.126 Mail Abuse South Korea AS4766 90/100 27 minutes ago
216.221.8.156 Mail Abuse United States AS12087 90/100 27 minutes ago
38.194.230.10 Mail Abuse Mexico AS28458 90/100 27 minutes ago
152.52.197.130 Mail Abuse India AS9498 90/100 27 minutes ago
70.169.11.218 Mail Abuse United States AS22773 90/100 27 minutes ago
Process

How it works

1

Enter an IP address

Paste any IPv4 or IPv6 address, or check your own IP with one click.

2

We scan every source

RDAP, geo database, live DNSBLs, daily threat feeds and community reports are queried simultaneously.

3

Decide instantly

A 0–100 confidence score and a readable report let you assess the threat in seconds.

Frequently Asked Questions

The questions we get most often about IP reputation data, blacklists, and how this database works.

An IP reputation database is a record of whether an IP address has been involved in malicious behaviour. IP-DB combines 42 open threat-intelligence feeds, community abuse reports and live DNSBL queries into a single 0-100 confidence score for each address. The higher the score, the more independent evidence there is that the address has been used for brute-force attacks, port scanning, spam or botnet traffic.
Type the address into the search box at the top of this page. The result page shows its confidence score, which blocklists it appears on, DNSBL matches, the WHOIS/RDAP owner, its ASN, country and any community reports. No account is needed. You can run the same check on up to 100 addresses at once with the bulk tool, or from your own code through the REST API.
From three places: 42 open threat-intelligence feeds pulled every half hour, live DNSBL checks run at query time (Spamhaus ZEN, SpamCop, Barracuda, SORBS), and abuse reports filed by users. Every feed is listed individually on the Data Sources page with its coverage, licence and the weight it carries in the score.
Lookups through the web interface are free and need no account at all. The REST API has a free tier of 1,000 checks a day — create an account, generate a key, and you are done. Higher volumes are listed on the Pricing page.
First fix what caused the listing: close the vulnerability on the server, clean up compromised accounts, shut any open relay or proxy. Our record updates automatically once the upstream feed drops the address. If you believe the listing is wrong, write to us through the contact form with the details — a review usually takes one business day.
Yes. The Integrations page carries copy-and-run configurations for FortiGate threat feeds, Palo Alto External Dynamic Lists, pfSense, Wazuh, fail2ban and nftables. If you are writing your own automation, the REST API returns JSON and can check hundreds of addresses per call.

IP Security Guides · IP Blacklist by Country · Malicious IP Networks by ASN · What Is My IP · IP Threat Intelligence Feeds