What we store
What we store
- The reported IP address, its score, category, confidence and listing state (needed for the blacklist function).
- Aggregate metadata: service type, hour of the signal, source type (anonymous / token / honeypot).
- Optional: the reporter's self-created token ID (to show personal statistics).
What we do NOT store
- Reporter IP addresses or hostnames (anonymous reports carry no reporter identity).
- Raw log lines, usernames, passwords or any evidence content.
- Exact timestamps (signals are displayed rounded to the hour).
Retention & deletion
Scores decay exponentially (half-life 3-30 days depending on signal type). Entries without new activity auto-delist and become inactive. The responsible abuse desk receives at most one anonymized notification per IP per 7 days.
Abuse notifications
When an IP is listed, we resolve the responsible provider via RDAP/whois and send one anonymized notification in X-ARF format (max. once per IP per 7 days). Notifications never contain reporter identities.
- Tor exit nodes are flagged but never reported to abuse desks (shared infrastructure).
- Mail servers on the dnswl.org whitelist get reduced weight for mail services - a whitelisted server can still be compromised, so we soften but do not silence.
Related articles
Attack Defense - What it is & how it works
The product explained from zero: report attacks from your servers to a global list - and automatically block reported attackers on your own systems. Free, anonymous, GDPR compliant.
ReadCheck IPs: Live Check & DNS
Check whether an IP is listed: web Live Check or dig against the per-service check zones - with return codes, TXT details and the HTTP export.
Read