A domain threat feed

10s of 1000s of domains
Zero false positives
Enriched with unique data

Updated daily, human reviewed, and built for people who need threat intelligence without having to second-guess it.

Threat data, backed by signals

The figures below come from the latest DNS telemetry snapshot. They are refreshed as the telemetry rollups are generated.

12,345,678DNS queries blocked in the last 7 days
1,234,567DNS queries blocked in the last 24 hours
98,765queried subdomains observed in the last 7 days
42malware families tracked

Placeholder figures — live telemetry will replace them when available.

Malware activity, not just malware names.

See which families are driving activity, which domains are associated with them, and where infections are being observed.

  • No activity snapshot is available yet.

Indicators, with the details that make them useful.

Each domain is more than a line in a text file. It is reviewed and enriched before it reaches the feed.

Who uses it?

Linked malware families, labels, tags, source evidence, and a clear history of where the indicator came from.

What does it do?

Infection volume from DNS blocks, observed IP record sets, and the passive-DNS context around the domain.

Where is it?

Geolocation for infected hosts and for the domain’s location, when the available evidence supports it.

Use the format that fits.

We can provide the feed as plain text, CSV, JSON, or STIX. Need a portal, an API, or RPZ? We support those too.

Plain textCSVJSONSTIXRPZ

Interested?

Get in touch and we will talk through the feed, the data behind it, and the delivery option that suits your setup.

Contact us