Transparency

BIND is the source of truth for live listings • meta.json records observation and delisting history

Transparency snapshot

Back to DNSBL
Active listings
2,649
Live from BIND zone (A + AAAA)
Threat activity (7 days)
13
Unique suspicious public IPs • 706 matched events • 1,698 requests evaluated
Repeat offenders
120
Threatmail: 71 • Apache security: 49
Lifecycle
Active
Pending review: 0 • Expiring ≤7d: 31 • Expired last run: 2
Delisted records
4
1 in the last 7 days • unique IPs with a recorded delist
Mail feeds
Active
Threatmail: active
User reports: not enabled • last 2026-06-25 06:35 BST
History coverage
70.1%
1,858 of 2,649 live listings have metadata
Last zone update
2026-06-25 06:17 BST
Authoritative BIND zone last modified
Live status, return code and TXT reason are reconciled directly against the BIND zone. An address is marked DELISTED only when a real delist timestamp, counter or audit event exists; otherwise a non-live historical address is OBSERVED. Repeat-offender totals are grouped by the latest sanitised attack source; complete event history is available only through the per-IP JSON feed and delist information. Apache activity cache updated 2026-06-25 06:35 BST.
BIND records: IPv4 A = 2,649 • IPv6 AAAA = 0 • TXT = 2,649 • SOA serial 2026062508.

Listings history

Live BIND entries plus observation and delisting history. Times use UK local GMT/BST.

Clear

Showing 1,801–1,900 of 2,822 matching records.

IP Status Code Reason Last activity Sources Lists / Delists Details
20.65.193.78 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 34 threatmail 1 / 0
20.14.73.54 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 19 threatmail 1 / 0
35.207.161.191 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
64.62.156.162 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
205.210.31.104 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
13.219.1.233 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 14 threatmail 5 / 0
157.230.167.26 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 208 threatmail 1 / 0
40.124.184.27 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 51 threatmail 1 / 0
198.235.24.67 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
193.163.125.152 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
176.65.139.219 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
198.235.24.43 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
205.210.31.142 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
205.210.31.44 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
66.132.186.159 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
205.185.118.149 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 284 threatmail 1 / 0
113.23.52.131 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 2 / 0
202.183.141.109 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 283 threatmail 2 / 0
216.202.205.235 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
147.185.132.201 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 195 threatmail 1 / 0
20.64.106.71 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 29 threatmail 1 / 0
103.123.226.10 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 143 threatmail 6 / 0
178.214.76.172 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 249 threatmail 1 / 0
64.62.156.91 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
198.235.24.79 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
147.185.132.9 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 198 threatmail 1 / 0
176.65.139.229 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 2 / 0
216.180.246.157 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
64.62.197.62 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
121.202.144.103 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 169 threatmail 1 / 0
79.72.3.119 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 1 / 0
64.62.197.64 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
172.234.218.87 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 243 threatmail 1 / 0
205.210.31.81 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 3 / 0
152.32.132.28 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET COMPROMISED Known Compromised or Hostile Host Traffic group 4 threatmail 1 / 0
217.144.154.164 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 2 / 0
45.198.224.4 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
20.28.136.213 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 2 / 0
66.132.195.146 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
176.65.139.214 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 5 / 0
66.240.192.82 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 113 threatmail 1 / 0
165.154.163.10 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 226 threatmail 1 / 0
20.65.195.19 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 32 threatmail 1 / 0
72.144.115.5 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 2,107 / 0
217.216.92.40 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 2 / 0
149.19.168.168 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 1 / 0
193.163.125.151 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 3 / 0
71.6.134.235 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 119 threatmail 1 / 0
45.136.119.164 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 59 / 0
103.226.155.185 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 65 / 0
120.89.68.68 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 29 / 0
81.19.159.98 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 39 / 0
89.41.38.65 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 45 / 0
193.163.125.107 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
112.203.55.29 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 2 / 0
185.7.120.88 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 71 / 0
70.153.161.2 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 37 / 0
193.163.125.227 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
154.89.156.32 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 80 / 0
109.224.242.41 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 2 / 0
122.52.248.193 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 2 / 0
5.226.140.62 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 3 threatmail 1 / 0
2.58.172.169 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 2 threatmail 1 / 0
198.163.207.24 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 3 / 0
64.62.156.86 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 threatmail 1 / 0
162.214.80.167 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 27 / 0
145.79.210.25 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 24 / 0
159.65.91.36 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 4 / 0
192.185.87.172 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 106 / 0
102.164.251.70 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 3 / 0
50.28.37.166 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 66 / 0
144.31.152.113 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SERVER /bin/sh In URI Possible Shell Command Execution Attempt threatmail 3 / 0
64.227.82.174 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT Cisco ASA/Firepower Unauthenticated File Read (CVE-2020-3452) M2 threatmail 3 / 0
172.64.244.69 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 2 / 0
118.148.168.74 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 3 / 0
160.119.76.24 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET CINS Active Threat Intelligence Poor Reputation IP group 213 threatmail 2 / 0
89.42.218.114 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 10 / 0
31.11.36.5 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 8 / 0
183.90.187.210 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 221 / 0
66.132.186.177 LISTED 127.0.0.4 Threat Prevention: Misc Attack / ET DROP Dshield Block Listed Source group 1 web:post 3 / 0
217.21.90.112 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 19 / 0
70.153.161.0 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 42 / 0
176.67.58.47 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 3 / 0
46.43.65.3 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 9 / 0
84.242.53.32 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
176.119.251.25 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
20.113.29.118 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 574 / 0
24.22.88.55 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 4 / 0
38.6.37.154 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 69 / 0
150.228.187.129 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT D-Link DSL-2750B - OS Command Injection threatmail 3 / 0
117.55.228.142 LISTED 127.0.0.4 Threat Prevention: Potentially Bad Traffic / ET DOS DNS Amplification Attack Inbound threatmail 1 / 0
110.137.34.157 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
114.10.41.136 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
157.85.209.118 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
153.117.33.35 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
180.190.241.9 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
103.188.169.147 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
181.228.242.123 LISTED 127.0.0.4 Threat Prevention: Attempted User Privilege Gain / ET EXPLOIT D-Link DSL-2750B - OS Command Injection threatmail 6 / 0
138.84.114.53 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0
202.51.197.33 LISTED 127.0.0.4 Threat Prevention: Web Application Attack / ET WEB_SPECIFIC_APPS MVPower CCTV DVR /shell JAWS Webserver Unauthenticated Remote Command Execution (CVE-2016-20016) threatmail 6 / 0

Lists / Delists shows list_count and delist_count. OBSERVED means the IP exists in history but is not currently in BIND and has no recorded delist event. Trusted addresses in /etc/scotnet/dnsbl-public-hide.txt are omitted from this public history table.