Start here
FFraud API
Free IP and email fraud intelligence. No key needed to start, no usage caps, and the confirmed-attacker list is published as MIT open data on GitHub.
FFraud tells you whether an IP or email is dangerous: fraud score, VPN/proxy/Tor/datacenter detection, abuse history, geolocation, and network ownership. One request, sub-millisecond, free for everyone.
You can call the public endpoint right now with no signup. A free API key adds batch lookups, usage stats, and the community reporting API.
#Your first call
No key, no headers. This works from your shell, an edge worker, or a browser:
curl https://api.ffraud.com/public/ip/80.82.77.33{
"success": true,
"ip": "80.82.77.33",
"fraud_score": 95,
"risk": "critical",
"reason": "Active command & control (C2) server. Confirmed by our honeypot sensors and repeated community reports.",
"vpn": false,
"proxy": true,
"tor": false,
"hosting": true,
"is_abuser": true,
"recent_abuse": true,
"connection_type": "Data Center",
"ASN": 9009,
"organization": "M247 Europe SRL",
"threat_tags": ["c2_server", "malware_distribution"],
"confidence": "high",
"geo": { "country": "NL", "city": "Amsterdam" }
}Optional fields are omitted when we have no data, so there is no null soup to guard against. Check for a key's presence, not for null.
The API knows more than the download. The open data lists the addresses we confirmed as attackers. The API answers for every address, with the VPN and proxy verdict, recency, the written reason, the network around it and the owner, and it already weighs signals we never publish. What each one answers.
#In your language
curl https://api.ffraud.com/public/ip/80.82.77.33