Is this IP blacklisted?
Paste any IPv4 or IPv6 address. We tell you whether it is listed in our abuse database, what it was caught doing, how much of its surrounding network is dirty, and whether the activity is recent or historical.
Result
185.220.101.34
Brandenburg, Germany · TORSERVERS-NET · Data Center
Pre-filled with a known Tor exit node so you can see a listed result. Type any address to check your own.
Behind every check
19.8 million
IP addresses profiled
2.4 million
malicious domains tracked
208,000
disposable email domains
1.9 million
networks scored
Counts read live from the engine, not written into the page. The full dataset is published on GitHub under the MIT license and rebuilt every 30 minutes.
What this checks
Every address is scored against the full ffraud dataset, not a single feed. A listing has to survive independent confirmation before it appears, which is why a result here means something more than an appearance on one noisy list.
Confirmed abuse history
Whether the address has been observed attacking, and what category it fell into: command and control, botnet traffic, brute force, credential stuffing, web attacks, port scanning, phishing, or spam.
Recency
An address listed three years ago and an address listed this morning are very different risks. We show first seen and last seen so you can tell them apart instead of guessing.
Neighborhood reputation
The share of the surrounding /24 that is flagged. A clean address inside a block where most neighbors are abusive is a very different proposition to a clean address in a clean block.
Infrastructure type
Whether the address is a VPN endpoint, an open proxy, a Tor exit node, a residential proxy, a datacenter host, or an ordinary consumer connection.
Network ownership
The operator, the autonomous system it belongs to, the reverse DNS name, and the WHOIS abuse contact, so you know who to complain to.
What this is not
This is an abuse and fraud blacklist, not a mail-delivery blacklist. If your mail is bouncing and you need to know whether your sending IP sits on a DNSBL such as Spamhaus, Barracuda, or SORBS, this page will not tell you, and no honest answer here can substitute for a delisting request filed with the list that actually blocked you. Check us for whether an address has an abuse history worth acting on, and go to the specific DNSBL for mail delisting. The two questions look identical in a search box and are answered by completely different data.
What to do with the answer
If your own address is listed
Look at the category and the last-seen date. A live listing usually means something on your network is compromised or a previous tenant of that address was abusive. Cloud and hosting addresses get recycled constantly, so an address you rented last week can carry someone else's history.
If a visitor's address is listed
Score it, do not reflexively hard-block it. Carrier-grade NAT and shared connections put thousands of innocent users behind one address. Challenge rather than ban, and reserve hard blocks for the top of the range.
If you want it in code
The same verdict is available from a free API endpoint with no key, and the underlying list is published in full on GitHub for you to download and use offline.
Five addresses, five different answers.
Live verdicts, fetched as this page loaded. They are chosen to show the range: a listing is not simply on or off.
185.220.101.34
100/100 · critical
tor-exit-34.for-privacy.net · Tor, VPN, proxy, datacenter
A Tor exit node, and it says so in its own reverse DNS. Listed, and correctly so: the operator is not hiding, but traffic arriving from here is anonymous by design.
45.148.10.121
100/100 · critical
no PTR record · Tor, datacenter
Also confirmed abusive, with no reverse DNS at all. Absence of a hostname is not innocence, and it is not guilt either. It is just missing.
1.1.1.1
5/100 · none
one.one.one.one · VPN, datacenter
Flagged as a VPN and as datacenter space, and still scored near zero. Flags describe what a connection is, not whether it has done anything wrong.
8.8.8.8
5/100 · none
dns.google · datacenter
A public DNS resolver in datacenter space. Clean. This is what a well-run piece of infrastructure looks like in our data.
52.95.110.1
10/100 · none
no PTR record · datacenter
Cloud space with no abuse history and no reverse DNS. Most of the internet looks like this: unremarkable, and correctly left alone.
Every verdict above was fetched from the engine when this page loaded. Nothing here is a screenshot or a stored example, so if a number looks surprising, that is what our data actually says right now.
How this differs from a DNSBL lookup
Most people searching for an IP blacklist check land on a tool that queries mail-delivery blacklists. That is a different question from the one this page answers, and knowing which one you need saves a lot of wasted time.
| ffraud | DNSBL lookup tools | |
|---|---|---|
| The question answered | Has this address been confirmed attacking, and what was it doing | Should a mail server accept mail from this address |
| Where the data comes from | Honeypot sensors we run, community reports, and independent threat feeds that must agree | The policies of each individual blacklist operator |
| Use it when | You are scoring traffic, signups, or payments | Your outbound mail is bouncing |
| Delisting | Fix the cause and contact us; every listing carries its evidence | File with the specific list that blocked you; nobody else can delist you |
| Getting the raw data | The whole list published on GitHub under MIT | Generally queried per lookup, not distributed in bulk |
If your mail is bouncing, a DNSBL tool is genuinely the right one and this page will not help you. We are the right tool when the question is whether to trust traffic.
Reading the result
0 to 29
No meaningful abuse signal. Let it through under normal handling.
30 to 69
Weaker or older signals, or a bad neighborhood. Challenge it, add friction, do not hard-block on this alone.
70 to 100
Confirmed abusive infrastructure. Blocking or a hard challenge is reasonable.
Questions people ask
How do I check if an IP address is blacklisted?
Paste the address into the box at the top of this page. You get an immediate verdict: whether it is listed in our abuse database, the score behind that verdict, what the address was caught doing, and when it was last seen doing it. There is no signup, no key, and no limit on how many you check.
Why is my IP address blacklisted?
Almost always one of three reasons. Something on your network is compromised and is sending attack traffic without your knowledge. Or the address was reassigned to you and carries the history of whoever held it before, which is extremely common on cloud and hosting providers. Or the address belongs to shared infrastructure such as a VPN, a proxy, or carrier-grade NAT, where your traffic is mixed with everyone else's. The result page shows the category and the dates, which is usually enough to tell which of the three you are looking at.
Does this check Spamhaus and other DNSBLs?
No. This checks the ffraud abuse database, which is built from honeypot sensors, community reports, and independent threat feeds. It answers whether an address has a confirmed history of attacking. It does not mirror the mail-delivery blacklists, so if your mail is bouncing you still need to query the specific DNSBL that blocked you and file a delisting request with them.
How do I get my IP removed from the blacklist?
First fix the cause, because a listing that gets re-confirmed will simply come back. Then contact us with the address and what you fixed. Every listing carries its evidence, so we can tell you exactly what we saw and when. Listings also age: an address that stops being seen in attack traffic loses its recent-abuse status on its own.
Is this IP blacklist check really free?
Yes, permanently, and without an account. The web lookup is free, the API endpoint behind it is free and needs no key, and the whole underlying list is published on GitHub under the MIT license for you to download and run offline.
Other free tools
IP reputation
A 0 to 100 fraud score for any IP address, with every signal that produced it shown in the open.
Proxy and VPN detection
Test whether an address is seen as a VPN, proxy, Tor node, or datacenter host, and what to do about it.
What is my IP
Your public address, plus the risk score, VPN classification, and network reputation that sites see with it.
Do it in code.
The same answer from a free API endpoint, or download the whole database and never call an API at all. No card, no quota, no expiry.