Blacklist
The ReportedIP blacklist is a community-driven list of malicious IP addresses, generated automatically from real-world attack reports and available via API and GitHub. Use it to block known malicious IPs in your firewall, web server, or application — it refreshes daily without manual review.
How the blacklist is generated
Every IP in the blacklist comes from community reports that hit our reputation engine. An IP is included only when:
- Its confidence score is ≥ 75 % (computed from report frequency, source diversity, severity, and recency)
- Its most recent report is at least 48 hours old (false-positive cool-down — entries only enter the export once the score has had time to recalibrate)
- It is not on the whitelist (search engines, CDN providers, known-good infrastructure are excluded)
The blacklist refreshes automatically — there is no manual editorial review. The whole pipeline
is open and transparent: you can verify any entry via
GET /reportedip/v2/check?ip=<ip>&verbose=true
to see the exact score breakdown.
GitHub Repository
The full blacklist is published as a public GitHub repository, pushed daily from the live API data. The exported data itself is delayed by 48 hours (the false-positive cool-down described above). You can clone it, use it in CI/CD pipelines, or integrate it into your infrastructure.
github.com/reportedip/reportedip-blacklist
Repository Structure
reportedip-blacklist/
├── blacklist-all.txt # All IPs, one per line
├── blacklist-all.json # All IPs with metadata
├── blacklist-all.csv # All IPs, CSV format
├── metadata.json # Export metadata (version, counts, timestamps)
├── lists/ # Thematic sub-lists
│ ├── spam.txt
│ ├── brute-force.txt
│ ├── cms-login.txt
│ ├── web-attacks.txt
│ ├── malware.txt
│ ├── ddos.txt
│ ├── fraud.txt
│ ├── infrastructure.txt
│ └── apt.txt
└── formats/ # Ready-to-include firewall snippets
├── nginx-deny.conf
├── apache-htaccess.txt
└── iptables.sh
File Formats
TXT Format
Plain text, one IP address per line. Lines starting with # are comments
containing metadata such as generation time and total count.
# ReportedIP Blacklist - All IPs
# https://reportedip.com
#
# Copyright (c) 2026 ReportedIP / Patrick Schlesinger
# Licensed under CC BY 4.0 - https://creativecommons.org/licenses/by/4.0/
#
# IMPORTANT: Data is delayed by 48 hours.
# For real-time threat intelligence via API, contact: 1@reportedip.com
#
# Generated: 2026-07-22
# Total IPs: 12847
#
1.2.3.4
5.6.7.8
9.10.11.12
JSON Format
A meta block (export version, counts, generation timestamp) followed by an
entries array. categories are numeric threat-category IDs — resolve
them against the threat-category catalogue
or GET /categories.
{
"meta": {
"version": "2026-07-22",
"generatedAt": "2026-07-22T00:00:00Z",
"totalCount": 12847
},
"entries": [
{
"ip": "1.2.3.4",
"confidence": 95,
"categories": [18, 21],
"source": "dynamic"
},
{
"ip": "5.6.7.8",
"confidence": 82,
"categories": [14],
"source": "dynamic"
}
]
}
CSV Format
Comma-separated values with a header row. Easy to import into spreadsheets, databases, or SIEM tools.
categories holds semicolon-separated numeric category IDs.
ip,confidence,categories,last_reported
1.2.3.4,95,"18;21","2026-07-19 14:22:00"
5.6.7.8,82,"14","2026-07-18 09:15:00"
9.10.11.12,78,"21","2026-07-17 20:45:00"
Firewall Integration
Use the blacklist files to block malicious IPs at the firewall or web server level. Below are integration examples for common tools.
Nginx
Generate a blocklist config and include it in your Nginx server block:
# Generate Nginx blocklist from TXT file
awk '{print "deny " $1 ";"}' blacklist-all.txt > /etc/nginx/blocklist.conf
# /etc/nginx/sites-enabled/default
server {
include /etc/nginx/blocklist.conf;
# ... rest of your config
}
Apache (.htaccess)
# .htaccess — Block reported IPs
<RequireAll>
Require all granted
Require not ip 1.2.3.4
Require not ip 5.6.7.8
Require not ip 9.10.11.12
</RequireAll>
iptables
# Block all IPs from the blacklist
while read ip; do
iptables -A INPUT -s "$ip" -j DROP
done < blacklist-all.txt
fail2ban
Create a custom jail that bans IPs from the ReportedIP blacklist:
# /etc/fail2ban/jail.d/reportedip.conf
[reportedip-blacklist]
enabled = true
banaction = iptables-allports
bantime = 86400
filter = reportedip-blacklist
logpath = /var/log/reportedip-blacklist.log
maxretry = 1
fail2ban also works in the other direction: a ready-made action reports every ban on your server
to the community via POST /report. See the
fail2ban integration guide for the
action config and the jail-to-category mapping.
API Access
The /blacklist endpoint provides real-time access to the full blacklist with
filtering options. An API key with the threat-feed feature (Contributor tier and up) is required.
The endpoint is feature-gated and does not count against your daily check or
report quota — poll it as often as your caching strategy needs. See
Authentication & Rate Limits
for tiers and keys.
| Parameter | Type | Description |
|---|---|---|
format |
string | Response format: json (default), txt, csv |
source |
string | Blacklist source: dynamic (default) — the community-driven, automatically scored blacklist. Other values are reserved for internal use |
confidence |
integer | Minimum confidence score (0–100). Default: 75. Alias: confidenceMinimum. Recommended for automated blocking: 90 |
category |
string | One or more threat category IDs, comma-separated (e.g. 22,18 for SSH plus generic brute-force). Full catalogue on the Threat Categories page or via GET /categories |
limit |
integer | Maximum number of IPs to return. Default: 10000 — keep the default; smaller values truncate the list |
curl -H "X-Key: YOUR_API_KEY" \
"https://reportedip.com/wp-json/reportedip/v2/blacklist?format=txt&confidence=90&limit=10000"
See the API Reference for full endpoint documentation, response format, and additional parameters.
Service-specific blacklists
Combine the category filter with confidence=90 to build one block list per
exposed service. Each list only contains IPs that were reported for the matching attack type, so you
can apply it port-scoped — an IP on the web list never locks anyone out of SSH.
| List | category value |
Categories included | Apply to |
|---|---|---|---|
| SSH | 22,18 |
SSH Brute-Force, generic Brute-Force | sshd — port 22 |
11,7,17,18 |
Email Spam, Phishing, Spoofing, Brute-Force (SMTP-AUTH/IMAP/POP3) | Postfix/Exim, Dovecot — ports 25, 465, 587, 110, 143, 993, 995 | |
| Web | 21,16,10,19,12 |
Web App Attack, SQL Injection, Web Spam, Bad Web Bot, Blog Spam — covers WordPress login/XML-RPC/REST brute force, plugin and core exploits, comment spam and scanning, which are reported under these IDs | nginx/Apache incl. WordPress hosting — ports 80, 443 |
| FTP | 5,18 |
FTP Brute-Force, generic Brute-Force | vsftpd/proftpd — port 21 |
| Edge | 4,14,20 |
DDoS Attack, Port Scan, Exploited Host | entire network edge, all ports |
# SSH attackers only, plain text for ipset/nftables
curl -H "X-Key: YOUR_API_KEY" \
"https://reportedip.com/wp-json/reportedip/v2/blacklist?confidence=90&format=txt&limit=10000&category=22,18"
Lists are regenerated server-side every 15 minutes. Hourly polling per list is plenty; send the
stored ETag back as If-None-Match and unchanged lists answer with
304 Not Modified. All valid category IDs are in the range 1–30 — see the
Threat Categories catalogue.
Auto-Update Script
Set up a cron job to automatically download the latest blacklist and update your firewall rules.
Cron Schedule
# /etc/cron.d/reportedip-blacklist
0 */6 * * * root /usr/local/bin/update-reportedip-blocklist.sh
Update Script
#!/bin/bash
# /usr/local/bin/update-reportedip-blocklist.sh
# Downloads the latest ReportedIP blacklist and updates Nginx blocklist
API_KEY="your-api-key-here"
API_URL="https://reportedip.com/wp-json/reportedip/v2/blacklist"
BLOCKLIST="/etc/nginx/blocklist.conf"
TMPFILE=$(mktemp)
# Download latest blacklist in TXT format
curl -sf -H "X-Key: $API_KEY" \
"$API_URL?format=txt&confidence=90&limit=10000" \
-o "$TMPFILE"
if [ $? -eq 0 ] && [ -s "$TMPFILE" ]; then
# Convert to Nginx deny directives
grep -v "^#" "$TMPFILE" | grep -v "^$" | \
awk '{print "deny " $1 ";"}' > "$BLOCKLIST"
# Reload Nginx
nginx -t && systemctl reload nginx
echo "$(date): Blocklist updated with $(wc -l < "$BLOCKLIST") entries"
else
echo "$(date): Failed to download blacklist" >&2
fi
rm -f "$TMPFILE"
Real-time vs. GitHub
| Method | Latency | Auth Required | Best For |
|---|---|---|---|
| API | Real-time | Yes (API key) | Automated blocking, dynamic firewall rules, SIEM integration |
| GitHub | Up to 48 hours | No | Static firewall rules, CI/CD pipelines, offline analysis |
Last updated: · Maintained by the ReportedIP team