Public REST API · Free Tier
Public API
The reputation engine behind everything. Query individual IPs, submit reports, pull the community blacklist, run bulk operations from any language or system — fail2ban, SIEM, custom firewalls, hosting panels.
- 1,000 free checks per day, 50 reports per day
- 30 threat categories, decay-weighted scoring
- Bulk operations & analytics on Pro+
Community Blacklist · Free Tier
Blacklist Feed
Community-driven blacklist, automatically scored from real-time reports. Plain text, JSON, and CSV — ready to drop into fail2ban, iptables, nginx, Postfix, or any blocklist consumer.
- Confidence ≥ 75 % threshold, 48 h false-positive cool-down
- TXT, JSON, CSV — plus 9 thematic lists (spam, brute-force, …)
- Git mirror, daily refresh, diff-friendly commit history
DNS Blocklist (RBL) · Paid add-on
DNS / RBL Zone
Query the community blacklist as a DNSBL straight from your mail server or firewall. A private, token-authenticated zone (bl.reportedip.de) answers reverse-IP lookups with 127.0.0.x codes — no API client, no integration code.
- RFC 5782 compliant — IPv4 and IPv6, Postfix / Rspamd / BIND RPZ
- 100,000 queries/day per token, answers cached for 30 minutes
- Category sub-zones (spam, brute-force, web-attacks, …)
WordPress Plugin · Two Editions
ReportedIP Hive
Real-time WordPress security from the hive. Pick the Full Edition (GitHub) for sixteen sensors incl. a Web Application Firewall, four-method 2FA and multisite, or grab the Light Edition from WordPress.org for focused brute-force protection. Free and open source either way.
- Full: 16 attack sensors + WAF + four-method 2FA + multisite
- Light: brute-force login protection, zero-config, on wp.org
- Both: progressive block ladder, community threat lookup, Local Shield mode
DNS Diagnostics · Free
DNS Checker
Domain health diagnostics from 76 DNS servers across 6 continents. Validate SPF, DKIM, DMARC, and DNSSEC, run DNSBL lookups, and track DNS propagation during migrations.
- Global propagation check from 76 resolvers
- SPF / DKIM / DMARC / DNSSEC validation
- DNSBL lookup against 60+ blocklists
Standalone PHP App · Free
Honeypot Server
A standalone PHP application that pretends to be WordPress, Drupal, or Joomla. 36 built-in threat analyzers detect SQLi, XSS, brute force, credential stuffing, plugin exploits, and feed clean data back into the network.
- Docker Compose ready, PHP 8.2 + SQLite
- 36 threat analyzers, severity-scored
- Reports auto-batched to ReportedIP API