Public APIs
AbuseIPDB favicon

AbuseIPDB

Anti-Malware

IP/domain/URL reputation.

AbuseIPDB's website screenshot

About AbuseIPDB

AbuseIPDB provides an API (APIv2) for checking and reporting IP addresses associated with abusive behavior such as hacking attempts, spam, and other malicious activity. The API exposes endpoints to check an IP's abuse history and confidence score, retrieve paginated reports for an IP, report abusive IPs, check IPs against a blacklist, perform bulk reporting, and clear address data. It integrates with Fail2Ban, with a prepackaged configuration for automatically reporting banned IPs.

The CHECK endpoint returns details on a queried IP address including IP version, country code and name, usage type (e.g. Commercial, Data Center/Web Hosting/Transit, Mobile ISP), ISP, domain name, whitelist status, an abuse confidence score, and associated abuse reports with timestamps, comments, categories, and reporter country. Geolocation, usage type, ISP, and domain data are sourced from IPinfo. Requests require an API key, passed as an HTTP header, and responses are returned in JSON.

The service is aimed at developers and system administrators who need programmatic access to IP reputation and abuse-reporting data, such as for automating IP blocking or building security tooling. Access requires signing up for a developer key, and the documentation references daily API rate limits and a paid plan option, though specific limits and pricing are not detailed in this content.

Key features

  • Check IP addresses for abuse reports and confidence score via CHECK endpoint
  • Retrieve paginated abuse reports for an IP via REPORTS endpoint
  • Report abusive IP addresses via REPORT and BULK-REPORT endpoints
  • Query and filter a plaintext IP blacklist with truncation and country filtering
  • Prepackaged Fail2Ban integration for automated abuse reporting
  • Bulk check multiple IPs via CHECK-BLOCK endpoint

Frequently asked questions

What languages have example code in the docs?

The documentation provides examples in cURL, Python, PHP, C#, and VBScript.

How do I authenticate API requests?

You pass your API key via the 'Key' HTTP header (recommended) or as a 'key' query parameter, obtained from your account dashboard.

What data does the CHECK endpoint return?

It returns the IP's abuse confidence score, country, usage type, ISP, domain, whitelist status, and abuse reports when the verbose flag is set.

Does AbuseIPDB integrate with Fail2Ban?

Yes, AbuseIPDB comes prepackaged with a Fail2Ban configuration for automatically reporting abusive IPs.

Is there a rate limit on API usage?

Yes, the API enforces daily rate limits, and higher limits are available by subscribing to a paid plan.

Advertise here

Featured products

  • SerpApi - Search API favicon
  • Screenshot Scout favicon
  • TalorData favicon
  • CoreClaw favicon

Show your product to thousands of developers

· 100k monthly pageviews
· 7k newsletter subscribers

Advertise your product