Web Live Check
The quickest way is the Live Check on the Reporting page: enter an IP and you get the current state (clean / watchlist / soft-listed / hard-listed), score, category, confidence level and anonymized evidence - no account needed.
Check with dig
Reverse the IP octets and append the service zone (or the base zone for any attack):
# Is 203.0.113.7 listed for SSH attacks?
dig 7.113.0.203.ssh.attacks.provider.tools
# Any attack at all?
dig 7.113.0.203.attacks.provider.tools
Every supported service has its own zone: <service>.attacks.provider.tools (e.g. ssh., imap., mysql., wordpress., minecraft.).
Return codes
| Answer | Meaning | Action |
|---|---|---|
NXDOMAIN | Clean or watchlist (not publicly listed). | Accept. |
127.0.0.7 | Exploit / scanner activity. | Block. |
127.0.0.8 | Abuse / policy (brute-force etc.). | Block. |
127.0.0.6 | Botnet. | Block. |
TXT records contain the listing details (category, state, confidence, score, services):
dig 7.113.0.203.ssh.attacks.provider.tools TXT
Machine-readable check
GET https://reports.provider.tools/api/v1/abuse/check?ip=203.0.113.7
Returns JSON with listing state, score, category, confidence level and anonymized evidence. The plain-text export is available at /api/v1/abuse/export (all listed IPs, optional ?service= filter).
Related articles
Attack Defense - What it is & how it works
The product explained from zero: report attacks from your servers to a global list - and automatically block reported attackers on your own systems. Free, anonymous, GDPR compliant.
ReadIn your firewall: block reported attackers
Block the Attack Defense list directly on routers and border firewalls without fail2ban - iptables, nftables, ufw, pf (BSD) and Windows Firewall, synced every 5 minutes.
ReadOn your server: fail2ban (reporting & auto-blocking)
One command installs reporting AND automatic blocking of reported attackers on your server - with block consumer, 5-minute sync, whitelist and per-service filtering.
Read