Skip to main contentSkip to footer
Announcements

ReportedIP Blacklist Repository Now Cleans Itself Daily

Updated Patrick Schlesinger
ReportedIP blacklist repository card: 6,995 addresses in the September 28 snapshot, 30-day score half-life after 14 quiet days, and live data from Hive, the Agent and the API

The public ReportedIP blacklist repository now drops addresses that have stopped attacking, so every daily snapshot lists only IPs with recent, confirmed activity. The build of September 28, 2026 held 6,995 addresses at a confidence score of 75 or higher, and the regular daily build of September 29 held 7,180.

If you need current data rather than a daily file, ReportedIP Hive and the ReportedIP Agent take it straight from the network.

What changed in the ReportedIP blacklist repository?

  • Addresses age out on their own. Two weeks after the last report, an address’s score starts to halve every 30 days. Once it falls below 75, the address is missing from the next snapshot.
  • New reports keep an address listed. Every report restarts the two-week grace period, so an address that keeps attacking keeps its score.
  • The README was rewritten. It now opens with what the repository is, a daily snapshot, and which live source fits which setup. The format section describes the files exactly as they are generated.
  • Every list file says where live data comes from. The comment header of each .txt list points to Hive, the Agent and the API.

Everything else stays as it was: the repository keeps its location, the free CC BY 4.0 licence, the file names, the nine thematic lists and the ready-made firewall formats. Where to download the files and how they are structured is described in the blacklist documentation.

How does an address leave the blacklist?

The confidence score already weighs every report by its age. Since September 28, 2026, the whole score also decays once an address goes quiet. The factor depends only on the time since the newest report:

Days since the last reportShare of the score that remains
0 to 14100%
4450%
7425%
10412.5%

An address scored 90 drops below the listing threshold of 75 within about three weeks without a new report. The same decay applies to the live list and the DNSBL zone, as recorded in the API changelog. The full calculation, including reporter diversity and honeypot evidence, is documented under Confidence score. If an address is listed in error, the delisting request removes it without waiting for the decay.

Why is a daily blacklist snapshot not live protection?

The repository is rebuilt once a day, around 04:20 UTC. An address enters the files 48 hours after its first report, so an attacker that showed up today is not in them yet, however high its score. It then stays as long as its score is 75 or higher, even while it keeps attacking. On September 29, 2026, the live list at confidence 75 held 12,545 addresses, while the snapshot of the same day held 7,180. Until then an address had to wait until its most recent report was 48 hours old, which left out attackers that were still active. From the export of September 30, 2026, the first report counts: a dry run on September 29 returned 12,514 IPs with the new filter instead of 6,934 with the old one.

That makes the snapshot a good fit for research, a lab, a one-off import or a firewall without API access, and a weak fit for anything that should block today’s traffic. How the list grew past 30,000 entries and why it is smaller today is covered in the 30,000 IP report.

Which live sources replace the daily snapshot?

You protectUseWhat you get beyond the snapshot
A WordPress siteReportedIP Hive, freeReal-time reputation lookups, 16 detection sensors, a web application firewall and four 2FA methods
A Linux serverReportedIP AgentThe community list in ipset or nftables every 15 minutes, plus detection in your own logs
Your own firewall or scriptReportedIP APIA real-time check per address and the current list with ETag support

Hive checks every visitor against the network

Hive runs inside WordPress. With a free reportedip.com account, its Community Network mode looks up visiting addresses in real time instead of waiting for tomorrow’s file, and its 16 sensors report the attacks your site sees back to the network. The plugin is free and GPL-2.0.

The Agent keeps the kernel sets current

The Agent is one static binary for hosts running web, mail, FTP and DNS. From the Professional plan up, it refreshes the list every 15 minutes, loads it into five sets by service (ssh, mail, web, ftp and edge) and swaps them atomically. It also watches your own logs and bans what nobody has reported yet. One server is included from the Professional plan; setup is covered in the Agent documentation.

The API serves both single checks and lists

GET /check answers for one address in real time and is free up to 1,000 checks a day. GET /blacklist returns the current list from the Contributor plan, without the 48-hour delay, and a conditional request with ETag costs nothing when the list has not changed. A hand-built firewall setup against the API is described in Network-level blocking.

Frequently asked questions

Why is an address no longer in the blacklist repository?

Its confidence score fell below 75, usually because nobody has reported it for several weeks. Two weeks after the most recent report, the score starts to halve every 30 days. If new reports lift it back to 75, it returns with the next daily snapshot. The 48-hour wait only applies to its first report.

How often is the blacklist repository updated?

The repository is rebuilt once a day, around 04:20 UTC, so pulling it more often gains nothing. Each build contains only addresses whose first report is at least 48 hours old. For data that is minutes old, use ReportedIP Hive on WordPress, the ReportedIP Agent on Linux servers or the API.

Is the blacklist repository still free to use?

The files remain free for private and commercial use under the CC BY 4.0 licence, as long as ReportedIP is credited. Live single checks through the API are free up to 1,000 a day, and the current list without the 48-hour delay is available from the Contributor plan.

Where to go next

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.
You need to agree with the terms to proceed