blocklist.de
Attack-source lists. What blocklist.de is, on what terms it is used, which fields of the IP answer it feeds, how big it is today and when it was last synced.
| Kind | Attack-source lists |
|---|---|
| Publisher | https://www.blocklist.de/en/export.html |
| Terms | "A free and voluntary service"; export files "as they are, and to be used at your own risk"; no licence text published. |
| Refresh | hourly |
| Size today | 27,811 IPv4 ranges and 398 IPv6 ranges compiled from the feed. |
| Last synced | 2026-09-13 |
| Answers | is_attack_source, attack_source |
What it is
The combined export of blocklist.de, a reporting service where server operators submit the addresses that attacked them (SSH, mail, web, FTP and more), regenerated every thirty minutes. Tens of thousands of hosts seen in the last days, weighed at 50.
What it answers
In the IP response this source feeds is_attack_source, attack_source. Every answer names the datasets it read in its sources block with the date each was synced, so the figure on this page and the one in an answer are the same figure.
curl https://spaw.co/api/v1/ip \
-H "Authorization: Bearer $SPAW_KEY" \
-H "Content-Type: application/json" \
-d '{"ip": "203.0.113.9"}'How to read this page
A source names a network or an operator, never a person. An address inside one of these ranges tells you what the connection is — a cloud instance, a VPN exit, a gateway, a listed host — and nothing about who is behind it.
More sources in attack-source lists
counts and dates read from the installed feed · checked 2026-09-13
More free tools
All free toolsNeed this at scale?
The Spaw API runs the same checks plus mailbox-level SMTP verification, batch and bulk endpoints, and list monitoring — 10 free lookups a month, no card required.