DNSBL - DNS-basierte Blacklist6 min read3 sections

Reporting API, Tokens & Plesk Plugin

Reporting is open to everyone - no registration required. Use API tokens for higher signal weight. Automate with the Plesk plugin.

01

Open Reporting

Reporting is open to everyone. No registration, no application, no approval process required. Anyone can report a malicious IP via the web interface or the API.

Every report creates a signal that contributes to the IP's score. The scoring model itself prevents abuse - a single report can never cause a hard block.

Without API Token

  • Signal weight: +8 (base)
  • Reporter trust multiplier: ~0.75x (new reporter)
  • Effective weight per report: ~6 points
  • A single report results in "Clean" status (score well below 20)

With API Token (Optional)

  • Signal weight: +15 (trusted reporter)
  • Reporter trust multiplier: ~1.25x (starting), up to 2.0x with proven accuracy
  • Effective weight per report: ~19–30 points
  • Still cannot hard-list on its own (needs 90+ for hard-listing)

API tokens can be created in your account settings after logging in. No application or approval needed - just create and use.

Safety Guarantee

Even a trusted reporter with the maximum multiplier (2.0x) can only produce ~30 points with a single report - that's "Watchlist" at most. Hard-listing always requires multiple independent signals or critical evidence.

02

API Token Usage

Reporting with Token

POST https://provider.tools/api/dnsbl/report
Authorization: Bearer YOUR_API_TOKEN
Content-Type: application/json

{
  "ip": "1.2.3.4",
  "category": "spam",
  "reason": "Detected by SpamAssassin (score: 8.5)",
  "evidence": "X-Spam-Score: 8.5",
  "reporterHost": "mail.example.com",
  "reporterHostIp": "203.0.113.10"
}

Response:
{
  "success": true,
  "reportId": "abc-123",
  "signalId": "sig-456",
  "score": 19,
  "listingState": "clean"
}

Reporting without Token

POST https://provider.tools/api/dnsbl/report
Content-Type: application/json

{
  "ip": "1.2.3.4",
  "category": "spam",
  "reason": "Sending bulk unsolicited emails"
}

Response:
{
  "success": true,
  "reportId": "abc-456",
  "signalId": "sig-789",
  "score": 6,
  "listingState": "clean"
}

Both work. The token just gives more weight. The scoring model handles the rest.

Available Categories

  • spam - Unsolicited bulk email
  • phishing - Phishing campaigns
  • malware - Malware distribution
  • botnet - Botnet membership
  • openrelay - Open relay misconfiguration
  • exploit - Exploit scanning / vulnerability probing
  • abuse - General policy violation
03

Plesk Plugin

Our Plesk plugin automates spam IP reporting from your server. It works with or without an API token.

Installation

# Install
plesk bin extension --install-url https://provider.tools/api/plesk-plugin/latest

# Upgrade
plesk bin extension --upgrade-url https://provider.tools/api/plesk-plugin/latest

Configuration

  • API Token (optional): Enter a token from your account settings for higher signal weight. Without a token, the plugin still works - reports just carry less weight.
  • Spam score threshold: Default 5.0 - only IPs above this score are reported.
  • Whitelist: Exclude your own IPs from reporting.

Requirements

  • Plesk Obsidian 18.0+
  • SpamAssassin or Rspamd enabled