IP Blacklist Lookup API

GET

Identify spam sources, botnets, and malware hosts by IP address.

IP Blacklist Lookup checks whether a given IP address appears on known malicious IP blocklists. Identifies both inbound threats (attackers, spammers) and outbound threats (C2 servers, malware hosts).

Try it — live request, no key required

Request
GETapi.apiverve.com/v1/ipblacklistlookup?ip=185.220.101.1
Query parameters
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "ipAddress": "185.220.101.1",
    "isIPBlacklisted": true,
    "inbound": {
      "found": true,
      "description": "IP is known for malicious inbound activity (spam, scanning, brute-force attacks)"
    },
    "outbound": null,
    "threatLevel": "high",
    "isTor": true,
    "ipDetails": {
      "ip": "185.220.101.1",
      "country": "DE",
      "region": "BY",
      "timezone": "Europe/Berlin",
      "city": "Nuremberg",
      "coordinates": [
        49.4478,
        11.0683
      ],
      "countryName": "Germany",
      "regionName": "Bavaria",
      "postalCode": "90403",
      "continent": "EU",
      "continentName": "Europe",
      "accuracyRadius": 20,
      "isEU": true
    },
    "asn": "AS60729",
    "asnName": "TORSERVERS-NET"
  }
}

About the IP Blacklist Lookup API

An IP reputation and threat intelligence API for firewalls, fraud checks and email security. IP Blacklist Lookup checks IPs against comprehensive blocklists that are updated multiple times daily. Inbound lists contain IPs known for spam, scanning, and brute-force attacks. Outbound lists contain known malicious destinations like command-and-control servers and malware hosts.

What people use it for

Firewall Enhancement
Automatically block connections to/from known malicious IPs to strengthen your security posture
Threat Detection
Identify if incoming traffic originates from known malicious sources before processing requests
Outbound Security
Detect if your systems are attempting to connect to known command-and-control or malware servers
Security Auditing
Check historical connection logs against current threat intelligence to identify past compromises

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

How it compares

Side by side with the tools people weigh IP Blacklist Lookup against — what each one is better at, in plain terms.

Other ways to use IP Blacklist Lookup

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the IP Blacklist Lookup API.

Read the docs →
Does this check cover both incoming attacks and outbound malicious traffic?
Yes. The check evaluates incoming threats like spammers, network scanners, and brute-force attackers, as well as outbound risks such as command-and-control servers and malware hosts.
How frequently are the IP blocklists updated?
The underlying blocklists are updated multiple times daily. Each lookup evaluates the address against these freshly refreshed sources to identify newly detected threats.
Do I get threat levels and IP geolocation on the Free plan?
No. The Free plan only reports whether the IP appears on any blocklists. Detailed inbound threat descriptions, outbound risk data, threat severity ratings, and full location coordinates require a paid subscription, starting with Starter.
Which plan fits 10,000 IP lookups a month?
The Starter plan covers that volume with room to spare. At 10 credits per call, 10,000 lookups use 100,000 credits, exactly half of the plan's 200,000 monthly allowance. That works out to about $0.0015 per call, while the Free plan includes 20 lookups each month.
Can I use these blacklist checks inside a commercial firewall or security service?
Yes, commercial use is supported on any paid plan. You can integrate IP Blacklist Lookup directly into your own security tools, firewalls, and audit pipelines, as long as you do not resell or redistribute the raw threat data.

Ready to build with IP Blacklist Lookup? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs