Angriffsabwehr3 min read4 sections

Check IPs: Live Check & DNS

Check whether an IP is listed: web Live Check or dig against the per-service check zones - with return codes, TXT details and the HTTP export.

01

Web Live Check

The quickest way is the Live Check on the Reporting page: enter an IP and you get the current state (clean / watchlist / soft-listed / hard-listed), score, category, confidence level and anonymized evidence - no account needed.

02

Check with dig

Reverse the IP octets and append the service zone (or the base zone for any attack):

# Is 203.0.113.7 listed for SSH attacks?
dig 7.113.0.203.ssh.attacks.provider.tools

# Any attack at all?
dig 7.113.0.203.attacks.provider.tools

Every supported service has its own zone: <service>.attacks.provider.tools (e.g. ssh., imap., mysql., wordpress., minecraft.).

03

Return codes

AnswerMeaningAction
NXDOMAINClean or watchlist (not publicly listed).Accept.
127.0.0.7Exploit / scanner activity.Block.
127.0.0.8Abuse / policy (brute-force etc.).Block.
127.0.0.6Botnet.Block.

TXT records contain the listing details (category, state, confidence, score, services):

dig 7.113.0.203.ssh.attacks.provider.tools TXT
04

Machine-readable check

GET https://reports.provider.tools/api/v1/abuse/check?ip=203.0.113.7

Returns JSON with listing state, score, category, confidence level and anonymized evidence. The plain-text export is available at /api/v1/abuse/export (all listed IPs, optional ?service= filter).