Skip to main contentSkip to footer

Blacklist

The ReportedIP blacklist is a community-driven list of malicious IP addresses, generated automatically from real-world attack reports and available via API and GitHub. Use it to block known malicious IPs in your firewall, web server, or application — it refreshes daily without manual review.

How the blacklist is generated

Every IP in the blacklist comes from community reports that hit our reputation engine. An IP is included only when:

  • Its confidence score is ≥ 75 % (computed from report frequency, source diversity, severity, and recency)
  • Its most recent report is at least 48 hours old (false-positive cool-down — entries only enter the export once the score has had time to recalibrate)
  • It is not on the whitelist (search engines, CDN providers, known-good infrastructure are excluded)

The blacklist refreshes automatically — there is no manual editorial review. The whole pipeline is open and transparent: you can verify any entry via GET /reportedip/v2/check?ip=<ip>&verbose=true to see the exact score breakdown.

GitHub Repository

The full blacklist is published as a public GitHub repository, pushed daily from the live API data. The exported data itself is delayed by 48 hours (the false-positive cool-down described above). You can clone it, use it in CI/CD pipelines, or integrate it into your infrastructure.

github.com/reportedip/reportedip-blacklist

Repository Structure

text
reportedip-blacklist/
├── blacklist-all.txt       # All IPs, one per line
├── blacklist-all.json      # All IPs with metadata
├── blacklist-all.csv       # All IPs, CSV format
├── metadata.json           # Export metadata (version, counts, timestamps)
├── lists/                  # Thematic sub-lists
│   ├── spam.txt
│   ├── brute-force.txt
│   ├── cms-login.txt
│   ├── web-attacks.txt
│   ├── malware.txt
│   ├── ddos.txt
│   ├── fraud.txt
│   ├── infrastructure.txt
│   └── apt.txt
└── formats/                # Ready-to-include firewall snippets
    ├── nginx-deny.conf
    ├── apache-htaccess.txt
    └── iptables.sh

File Formats

TXT Format

Plain text, one IP address per line. Lines starting with # are comments containing metadata such as generation time and total count.

text
# ReportedIP Blacklist - All IPs
# https://reportedip.com
#
# Copyright (c) 2026 ReportedIP / Patrick Schlesinger
# Licensed under CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/
#
# IMPORTANT: Data is delayed by 48 hours.
# For real-time threat intelligence via API, contact: 1@reportedip.com
#
# Generated: 2026-07-22
# Total IPs: 12847
#
1.2.3.4
5.6.7.8
9.10.11.12

JSON Format

A meta block (export version, counts, generation timestamp) followed by an entries array. categories are numeric threat-category IDs — resolve them against the threat-category catalogue or GET /categories.

json
{
  "meta": {
    "version": "2026-07-22",
    "generatedAt": "2026-07-22T00:00:00Z",
    "totalCount": 12847
  },
  "entries": [
    {
      "ip": "1.2.3.4",
      "confidence": 95,
      "categories": [18, 21],
      "source": "dynamic"
    },
    {
      "ip": "5.6.7.8",
      "confidence": 82,
      "categories": [14],
      "source": "dynamic"
    }
  ]
}

CSV Format

Comma-separated values with a header row. Easy to import into spreadsheets, databases, or SIEM tools. categories holds semicolon-separated numeric category IDs.

csv
ip,confidence,categories,last_reported
1.2.3.4,95,"18;21","2026-07-19 14:22:00"
5.6.7.8,82,"14","2026-07-18 09:15:00"
9.10.11.12,78,"21","2026-07-17 20:45:00"

Firewall Integration

Use the blacklist files to block malicious IPs at the firewall or web server level. Below are integration examples for common tools.

Nginx

Generate a blocklist config and include it in your Nginx server block:

bash
# Generate Nginx blocklist from TXT file
awk '{print "deny " $1 ";"}' blacklist-all.txt > /etc/nginx/blocklist.conf
nginx
# /etc/nginx/sites-enabled/default
server {
    include /etc/nginx/blocklist.conf;

    # ... rest of your config
}

Apache (.htaccess)

apache
# .htaccess — Block reported IPs
<RequireAll>
    Require all granted
    Require not ip 1.2.3.4
    Require not ip 5.6.7.8
    Require not ip 9.10.11.12
</RequireAll>

iptables

bash
# Block all IPs from the blacklist
while read ip; do
    iptables -A INPUT -s "$ip" -j DROP
done < blacklist-all.txt

fail2ban

Create a custom jail that bans IPs from the ReportedIP blacklist:

ini
# /etc/fail2ban/jail.d/reportedip.conf
[reportedip-blacklist]
enabled  = true
banaction = iptables-allports
bantime  = 86400
filter   = reportedip-blacklist
logpath  = /var/log/reportedip-blacklist.log
maxretry = 1

fail2ban also works in the other direction: a ready-made action reports every ban on your server to the community via POST /report. See the fail2ban integration guide for the action config and the jail-to-category mapping.

API Access

The /blacklist endpoint provides real-time access to the full blacklist with filtering options. An API key with the threat-feed feature (Contributor tier and up) is required. The endpoint is feature-gated and does not count against your daily check or report quota — poll it as often as your caching strategy needs. See Authentication & Rate Limits for tiers and keys.

Parameter Type Description
format string Response format: json (default), txt, csv
source string Blacklist source: dynamic (default) — the community-driven, automatically scored blacklist. Other values are reserved for internal use
confidence integer Minimum confidence score (0–100). Default: 75. Alias: confidenceMinimum. Recommended for automated blocking: 90
category string One or more threat category IDs, comma-separated (e.g. 22,18 for SSH plus generic brute-force). Full catalogue on the Threat Categories page or via GET /categories
limit integer Maximum number of IPs to return. Default: 10000 — keep the default; smaller values truncate the list
curl
curl -H "X-Key: YOUR_API_KEY" \
     "https://reportedip.com/wp-json/reportedip/v2/blacklist?format=txt&confidence=90&limit=10000"

See the API Reference for full endpoint documentation, response format, and additional parameters.

Service-specific blacklists

Combine the category filter with confidence=90 to build one block list per exposed service. Each list only contains IPs that were reported for the matching attack type, so you can apply it port-scoped — an IP on the web list never locks anyone out of SSH.

List category value Categories included Apply to
SSH 22,18 SSH Brute-Force, generic Brute-Force sshd — port 22
Mail 11,7,17,18 Email Spam, Phishing, Spoofing, Brute-Force (SMTP-AUTH/IMAP/POP3) Postfix/Exim, Dovecot — ports 25, 465, 587, 110, 143, 993, 995
Web 21,16,10,19,12 Web App Attack, SQL Injection, Web Spam, Bad Web Bot, Blog Spam — covers WordPress login/XML-RPC/REST brute force, plugin and core exploits, comment spam and scanning, which are reported under these IDs nginx/Apache incl. WordPress hosting — ports 80, 443
FTP 5,18 FTP Brute-Force, generic Brute-Force vsftpd/proftpd — port 21
Edge 4,14,20 DDoS Attack, Port Scan, Exploited Host entire network edge, all ports
curl
# SSH attackers only, plain text for ipset/nftables
curl -H "X-Key: YOUR_API_KEY" \
     "https://reportedip.com/wp-json/reportedip/v2/blacklist?confidence=90&format=txt&limit=10000&category=22,18"

Lists are regenerated server-side every 15 minutes. Hourly polling per list is plenty; send the stored ETag back as If-None-Match and unchanged lists answer with 304 Not Modified. All valid category IDs are in the range 1–30 — see the Threat Categories catalogue.

Auto-Update Script

Set up a cron job to automatically download the latest blacklist and update your firewall rules.

Cron Schedule

bash
# /etc/cron.d/reportedip-blacklist
0 */6 * * * root /usr/local/bin/update-reportedip-blocklist.sh

Update Script

bash
#!/bin/bash
# /usr/local/bin/update-reportedip-blocklist.sh
# Downloads the latest ReportedIP blacklist and updates Nginx blocklist

API_KEY="your-api-key-here"
API_URL="https://reportedip.com/wp-json/reportedip/v2/blacklist"
BLOCKLIST="/etc/nginx/blocklist.conf"
TMPFILE=$(mktemp)

# Download latest blacklist in TXT format
curl -sf -H "X-Key: $API_KEY" \
     "$API_URL?format=txt&confidence=90&limit=10000" \
     -o "$TMPFILE"

if [ $? -eq 0 ] && [ -s "$TMPFILE" ]; then
    # Convert to Nginx deny directives
    grep -v "^#" "$TMPFILE" | grep -v "^$" | \
        awk '{print "deny " $1 ";"}' > "$BLOCKLIST"

    # Reload Nginx
    nginx -t && systemctl reload nginx

    echo "$(date): Blocklist updated with $(wc -l < "$BLOCKLIST") entries"
else
    echo "$(date): Failed to download blacklist" >&2
fi

rm -f "$TMPFILE"

Real-time vs. GitHub

Important: The GitHub repository is pushed daily, but the exported data carries a 48-hour false-positive cool-down. For real-time blocking with the most current data, use the API directly — it reflects changes immediately as new reports come in, while the GitHub files lag behind by up to two days. Mail servers can also consume the blacklist as a DNSBL / RBL zone without downloading files at all.
Method Latency Auth Required Best For
API Real-time Yes (API key) Automated blocking, dynamic firewall rules, SIEM integration
GitHub Up to 48 hours No Static firewall rules, CI/CD pipelines, offline analysis

Last updated: · Maintained by the ReportedIP team

Security Focused
GDPR Compliant
Made in Germany
Back to Docs