Check any indicator
Paste an IP, domain, URL, email, phone, wallet, or file hash — same lookup as the homepage, streamed into a full threat report.
Free to try · No credit card · Automate via API
What you get
One paste. Full context.
The report stream layers verdict, enrichment, and evidence as it arrives — built for triage, not a dashboard wall.
Multi-source verdict
Reputation, confidence, and source attribution in one stream.
Infrastructure context
WHOIS, DNS, geo, ASN, and SSL when the indicator supports it.
Hashes & scam vectors
File hashes, emails, phones, and wallets on the same report flow.
Analyst-ready output
HTML report in the browser, or JSON from the API check path.
Learn more
- Firewall Blocklist Automation: Pulling IP and Domain Feeds Without Outages
External dynamic lists can block malware and phishing at the edge — or break payroll, CDN traffic, and vendor portals. This guide covers staged rollout, allowlists, fail-open vs fail-closed, and measuring hit rates for IP and domain blocklists.
- STIX/TAXII Threat Feeds: Operational Guide for OpenCTI, MISP, and SIEM Pipelines
How to wire STIX 2.1 and TAXII 2.1 collections into OpenCTI, MISP, or your SIEM — what to poll, how to handle confidence and aging indicators, and where enrichment APIs fit alongside feed ingestion.
- How to Use an NRD Feed to Catch Phishing Before It Lands in the Inbox
Newly registered domains are where most phishing campaigns start. This guide walks through NRD feed workflows for brand monitoring, mail gateway hygiene, and SOC triage — without treating domain age as a blunt block rule.