A malicious domain feed is a machine-readable list of domains observed in attacks, refreshed on a fixed schedule so security tools can block them. The WhoisFreaks domain threat feeds cover phishing, malware, and spam. Each feed is delivered as one CSV file containing every flagged domain in the database, rebuilt every day.
Features
Three domain feeds, each a separate CSV file rebuilt daily. Subscribe to one, two, or all three. Botnet and C2 indicators ship as IP feeds, covered in the next section.
A daily feed of phishing domains flagged for credential theft, fake login pages, and brand impersonation. Covers lookalike and typosquatted domains built to mimic banks, SaaS platforms, payment providers, and delivery services, plus phishing pages spun up on free hosting and site builders. Every record is surfaced through shared registrant and DNS pivots and scored, so email gateways and DNS filters can block domains before users ever reach them.
A daily feed of malware domains observed distributing payloads, hosting infected downloaders, or serving files for ransomware, stealers, and loaders. Includes drive-by download sites and short-lived disposable domains registered purely for malware delivery. Every record is expanded from verified malware seeds through shared NS, MX, and registrant pivots, and carries a confidence value and risk score for DNS firewall , RPZ, and proxy blocklists.
A daily feed of spam domains caught sending unsolicited bulk email or hosting the landing pages and link networks spam campaigns promote. Covers snowshoe sending infrastructure, spamvertised domains, and mail systems with a history of abuse. Every record is expanded from verified spam seeds through shared MX, NS, and registrant pivots and scored, so secure email gateways and mail filters can reject messages and URLs at scale.
Product
Alongside the domain feeds, these feeds flag malicious and high-risk IP addresses instead of domains. Each IP threat type is a separate feed file, scored and dated, so you can subscribe to one, several, or all five.
A daily feed of IP addresses tied to commercial and public VPN services, built for VPN detection at signup, login, and checkout. Covers paid VPN providers, free VPN apps, and shared VPN exit ranges that users rely on to mask their real location. Every IP carries a confidence value and risk score so fraud, risk, and access teams can flag or step up traffic hiding behind a VPN without blocking legitimate users outright.
A daily feed of open, anonymous, and datacenter proxy IPs used to relay traffic and hide a visitor's true origin. Covers HTTP/HTTPS and SOCKS proxy endpoints along with rotating proxy pools common in scraping and credential-stuffing traffic. Each IP ships with a confidence value and risk score so you can flag or step up proxied traffic without impacting real users.
A daily feed of published Tor exit and relay node IP addresses used to access services anonymously over the Tor network. Updated as the public consensus list changes, so newly listed and retired nodes are reflected quickly. Each entry carries a confidence value and risk score to help you decide whether Tor traffic should be challenged, limited, or blocked.
A daily feed of IP addresses linked to automated bot traffic, including scrapers, credential-stuffing tools, and known headless-browser infrastructure. Covers both declared bots and stealth automation that mimics human browsing. Every IP includes a confidence value and risk score so you can throttle, challenge, or block non-human traffic without disrupting real visitors.
A daily feed of IP addresses observed acting as command-and-control infrastructure for malware and botnets. Sourced from active threat intelligence tracking of beaconing and callback traffic. Each IP carries a confidence value and risk score so security teams can detect, alert on, or block compromised hosts communicating with known C2 servers.
Every domain feed is a daily full dump of domain indicators of compromise (IOCs), and all three use the same schema, so one parser handles every file. The IP feeds use their own schema, keyed on IP address instead of domain.
| Header | Description |
|---|---|
| domain | The flagged domain name. |
| threat_type | One of phishing, malware or spam. |
| confidence | How strongly the evidence supports the classification, from 0 to 1. |
| first_seen | Date the domain first appeared in WhoisFreaks threat data. |
| last_seen | Most recent date the threat activity was observed. |
| no_of_threat_matched_pivots | How many shared infrastructure attributes linked this domain to the threat. Pivots include registrant email, phone, fax, company name, organization, NS, MX, and CNAME. |
Records are plain CSV, so they load into MISP, OpenCTI, and Cisco Umbrella without transformation, and into BIND or Unbound as an RPZ zone. RFC 8484 resolvers can enforce the same list at query time.
Product
Each feed starts from confirmed domains, then expands through the attributes those domains share with the rest of an attacker's infrastructure. To investigate a single indicator yourself, the historical DNS API returns the record trail for any domain in the feed.
Each feed starts with domains confirmed for a specific threat type: phishing, malware, spam, botnet, or C2.
Extracting attributes like registrant email, phone, NS, MX, and CNAME shared across infrastructure.
Pivots are matched across the full database to surface related domains, even before they are reported publicly.
Product
Pull each feed from the WhoisFreaks API. Every pull returns a full dump of every domain in that feed, refreshed daily. Full endpoints, authentication, and the record schema are in the threat feed API documentation.
Each threat type ships as a separate CSV file, retrieved through the WhoisFreaks API and rebuilt daily. Every pull returns a full dump of every domain currently in that feed, including your first. There are no delta files to stitch together and no risk of a missed day leaving a gap in your blocklist.
Use Cases
Splunk, Sentinel, BIND RPZ zones, and secure email gateways all ingest the same scored CSV records.
Ingest feeds into Splunk or Sentinel to match flagged domains against logs. Support retro-hunting with historical date context.
Load malware and botnet feeds into DNS firewalls or RPZ zones to stop connections before payloads are fetched.
Feed spam and phishing lists into mail filters to block malicious messages surfaced through infrastructure pivots.
Detect impersonation domains targeting your brand. Combine it with Newly Registered Domains feed for day-one protection.
Screen signups and transactions against feeds to flag accounts operating from known malicious infrastructure.
Ingest feeds once and enforce across client environments. Scored records allow custom risk tolerance thresholds.
Book a call and we will show you a live feed file, walk through how a record gets its confidence value, and tell you which threat types fit your blocking policy.
Comparison
WhoisFreaks pipeline expands 1M verified indicators into 25M flagged records through shared pivots.
| Capability | Open Community Lists | WhoisFreaks Domain Threat Feeds |
|---|---|---|
| Method | Reports and observations only | Verified seeds expanded through infrastructure pivots |
| Scoring | Mostly binary listed or not listed | Confidence value and risk score per record |
| Record context | Usually the domain or URL alone | Threat type, first and last seen, related pivots |
| First delivery | Varies; often forward-only | Full dump of the feed |
| Licensing | Often restricted or non-commercial terms | Commercial license |
Tell us which threat types you need and how you plan to use them. We will set up your first full dump and daily deliveries.