Threat Intelligence Feeds

A malicious domain feed is a machine-readable list of domains observed in attacks, refreshed on a fixed schedule so security tools can block them. The WhoisFreaks domain threat feeds cover phishing, malware, and spam. Each feed is delivered as one CSV file containing every flagged domain in the database, rebuilt every day.

pricing backgroundEclipse Top RightEclipse Top Left

Features

What Threat Types Are Covered?

Three domain feeds, each a separate CSV file rebuilt daily. Subscribe to one, two, or all three. Botnet and C2 indicators ship as IP feeds, covered in the next section.

Phishing Domain Feed

A daily feed of phishing domains flagged for credential theft, fake login pages, and brand impersonation. Covers lookalike and typosquatted domains built to mimic banks, SaaS platforms, payment providers, and delivery services, plus phishing pages spun up on free hosting and site builders. Every record is surfaced through shared registrant and DNS pivots and scored, so email gateways and DNS filters can block domains before users ever reach them.

Phishing Domain Feed

Malware Domain Feed

A daily feed of malware domains observed distributing payloads, hosting infected downloaders, or serving files for ransomware, stealers, and loaders. Includes drive-by download sites and short-lived disposable domains registered purely for malware delivery. Every record is expanded from verified malware seeds through shared NS, MX, and registrant pivots, and carries a confidence value and risk score for DNS firewall , RPZ, and proxy blocklists.

Malware Domain Feed

Spam Domain Feed

A daily feed of spam domains caught sending unsolicited bulk email or hosting the landing pages and link networks spam campaigns promote. Covers snowshoe sending infrastructure, spamvertised domains, and mail systems with a history of abuse. Every record is expanded from verified spam seeds through shared MX, NS, and registrant pivots and scored, so secure email gateways and mail filters can reject messages and URLs at scale.

Spam Domain Feed

Product

What IP Threats Are Covered?

Alongside the domain feeds, these feeds flag malicious and high-risk IP addresses instead of domains. Each IP threat type is a separate feed file, scored and dated, so you can subscribe to one, several, or all five.

What Each Feed Record Contains

Every domain feed is a daily full dump of domain indicators of compromise (IOCs), and all three use the same schema, so one parser handles every file. The IP feeds use their own schema, keyed on IP address instead of domain.

HeaderDescription
domainThe flagged domain name.
threat_typeOne of phishing, malware or spam.
confidenceHow strongly the evidence supports the classification, from 0 to 1.
first_seenDate the domain first appeared in WhoisFreaks threat data.
last_seenMost recent date the threat activity was observed.
no_of_threat_matched_pivotsHow many shared infrastructure attributes linked this domain to the threat. Pivots include registrant email, phone, fax, company name, organization, NS, MX, and CNAME.

Records are plain CSV, so they load into MISP, OpenCTI, and Cisco Umbrella without transformation, and into BIND or Unbound as an RPZ zone. RFC 8484 resolvers can enforce the same list at query time.

Product

From Seed Domains to Flagged Infrastructure

Each feed starts from confirmed domains, then expands through the attributes those domains share with the rest of an attacker's infrastructure. To investigate a single indicator yourself, the historical DNS API returns the record trail for any domain in the feed.

  1. Step 1: Seed Data

    Each feed starts with domains confirmed for a specific threat type: phishing, malware, spam, botnet, or C2.

  2. Step 2: Pivot Extraction

    Extracting attributes like registrant email, phone, NS, MX, and CNAME shared across infrastructure.

  3. Step 3: Extrapolation

    Pivots are matched across the full database to surface related domains, even before they are reported publicly.

Product

How Is Each Feed Delivered?

Pull each feed from the WhoisFreaks API. Every pull returns a full dump of every domain in that feed, refreshed daily. Full endpoints, authentication, and the record schema are in the threat feed API documentation.

Daily CSV Threat Feeds via API

Each threat type ships as a separate CSV file, retrieved through the WhoisFreaks API and rebuilt daily. Every pull returns a full dump of every domain currently in that feed, including your first. There are no delta files to stitch together and no risk of a missed day leaving a gap in your blocklist.

Daily Full Dump DeliveryEach file is the whole feed, so there is no delta to reconcile.
Delivery SpecificationGzip-compressed CSV
FormatCSV (one per type)
DeliveryWhoisFreaks API
Update frequencyDaily
Every deliveryFull dump of the feed, daily
Ongoing deliveriesDaily Changes

Use Cases

Who Uses Threat Intelligence Feeds?

Splunk, Sentinel, BIND RPZ zones, and secure email gateways all ingest the same scored CSV records.

SOC and Intel Teams

SOC and Intel Teams

Ingest feeds into Splunk or Sentinel to match flagged domains against logs. Support retro-hunting with historical date context.

DNS Filtering

DNS Filtering

Load malware and botnet feeds into DNS firewalls or RPZ zones to stop connections before payloads are fetched.

Email Security

Email Security

Feed spam and phishing lists into mail filters to block malicious messages surfaced through infrastructure pivots.

Brand Protection

Brand Protection

Detect impersonation domains targeting your brand. Combine it with Newly Registered Domains feed for day-one protection.

Fraud and Risk

Fraud and Risk

Screen signups and transactions against feeds to flag accounts operating from known malicious infrastructure.

MSSPs

MSSPs

Ingest feeds once and enforce across client environments. Scored records allow custom risk tolerance thresholds.

Request demo background

Book a call and we will show you a live feed file, walk through how a record gets its confidence value, and tell you which threat types fit your blocking policy.

Comparison

How Do These Feeds Compare?

WhoisFreaks pipeline expands 1M verified indicators into 25M flagged records through shared pivots.

CapabilityOpen Community ListsWhoisFreaks Domain Threat Feeds
MethodReports and observations only
Verified seeds expanded through infrastructure pivots
ScoringMostly binary listed or not listed
Confidence value and risk score per record
Record contextUsually the domain or URL alone
Threat type, first and last seen, related pivots
First deliveryVaries; often forward-only
Full dump of the feed
LicensingOften restricted or non-commercial terms
Commercial license
Newly Registered Domains

Newly Registered Domains

A daily feed of newly registered domains, so you can catch phishing before the sites go live.

NRD feed
Domain Reputation API

Domain Reputation API

Score any domain in real time from WHOIS, DNS, and hosting signals, and act on the risk score returned.

Domain Reputation API
Reverse WHOIS API

Reverse WHOIS API

Find every domain tied to a name, email, or organization and map the attacker infrastructure behind it.

Reverse WHOIS API

FAQs

Get quick answers to your questions about Domain Threat Intelligence.

What is a threat intelligence feed?

A threat intelligence feed is a regularly updated, machine-readable list of indicators (domains and IPs) observed in malicious activity. Security teams load feeds into SIEMs, DNS firewalls, and email gateways to block or investigate flagged indicators. WhoisFreaks delivers three domain feeds (phishing, malware, spam) and five IP feeds (VPN, proxy, Tor, bot, C2), each as one CSV file rebuilt daily.

What threat types do the feeds cover?

The domain feeds cover phishing, malware, and spam. The IP feeds cover VPN, proxy, Tor, bot, and command and control (C2) addresses. You can subscribe to a single feed or any combination.

How often are the feeds updated?

Every feed is rebuilt once a day. Each daily file is a full dump containing every indicator currently in that feed, not just the records that changed. The rolling window is 1 day: each file replaces the previous one.

How does a domain end up in a feed?

Each feed starts from verified seed domains for that threat type. WhoisFreaks extracts the pivots those seeds share, such as registrant email, organization, NS, MX, and CNAME records, then matches the pivots across its domain database to surface related domains. Every surfaced domain is assigned a confidence value and risk score before it is published.
The shared attributes that link the flagged domain to the rest of the campaign it belongs to: registrant email, phone, fax, company name, and organization, plus NS, MX, and CNAME records. Analysts use it to expand an investigation from one flagged domain to the surrounding infrastructure without running separate lookups.

Do I get historical data?

Every daily file contains every domain currently in the feed, including domains flagged long before your subscription started, so you get the full backlog on day one and on every day after. Each record's first_seen value tells you when it entered WhoisFreaks threat data. The feed does not serve archived copies of previous days' files, so retain the daily dumps you need for your own history.

How do I get access?

Contact the WhoisFreaks team through the contact form. There is no self-serve signup for the threat feeds; access, feed selection, and pricing are handled directly. A sample malware domain feed file is available to download without an account.

How are these feeds different from free or open-source threat feeds?

Free and open-source threat intelligence feeds list domains from reports and observations, usually without scoring or context. WhoisFreaks starts from verified seed domains, expands them through shared registrant and DNS pivots, and assigns a confidence value and risk score to every record, so you get related infrastructure and a threshold you control.

What should you look for in a threat intelligence feed provider?

Look for verified sourcing over scraped lists, a confidence value or risk score on every record so you can set your own blocking threshold, related infrastructure pivots for investigation, daily updates, and clean CSV or API delivery. Many providers publish raw domain lists, WhoisFreaks scores each record and links it to the wider campaign.
Get the Domain Threat Feeds!

Tell us which threat types you need and how you plan to use them. We will set up your first full dump and daily deliveries.