Threat Intelligence Feeds

Daily CSV feeds of flagged domains, each record scored, dated, and linked to the infrastructure behind it. Built from verified seed data and pivot analysis across the WhoisFreaks domain database.

pricing backgroundEclipse Top RightEclipse Top Left

Features

What Threat Types Are Covered?

Each threat type is a separate feed file. Subscribe to one, several, or all.

Phishing Domain Feed

A daily feed of phishing domains flagged for credential theft, fake login pages, and brand impersonation. Covers lookalike and typosquatted domains built to mimic banks, SaaS platforms, payment providers, and delivery services, plus phishing pages spun up on free hosting and site builders. Every record is surfaced through shared registrant and DNS pivots and scored, so email gateways and DNS filters can block domains before users ever reach them.

Phishing Domain Feed

Malware Domain Feed

A daily feed of malware domains observed distributing payloads, hosting infected downloaders, or serving files for ransomware, stealers, and loaders. Includes drive-by download sites and short-lived disposable domains registered purely for malware delivery. Every record is expanded from verified malware seeds through shared NS, MX, and registrant pivots, and carries a confidence value and risk score for DNS firewall , RPZ, and proxy blocklists.

Malware Domain Feed

Spam Domain Feed

A daily feed of spam domains caught sending unsolicited bulk email or hosting the landing pages and link networks spam campaigns promote. Covers snowshoe sending infrastructure, spamvertised domains, and mail systems with a history of abuse. Every record is expanded from verified spam seeds through shared MX, NS, and registrant pivots and scored, so secure email gateways and mail filters can reject messages and URLs at scale.

Spam Domain Feed

Product

What IP Threats Are Covered?

Alongside the domain feeds, these feeds flag malicious and high-risk IP addresses instead of domains. Each IP threat type is a separate feed file, scored and dated, so you can subscribe to one, several, or all.

What Each Feed Record Contains

Every feed is a daily stream of domain indicators of compromise (IOCs), and every record across all feeds uses the same schema, so one parser handles every file.

HeaderDescription
domainThe flagged domain name.
threat_typeOne of phishing, malware, spam, botnet, or c2.
confidenceHow strongly the evidence supports the classification, from 0 to 1.
first_seenDate the domain first appeared in WhoisFreaks threat data.
last_seenMost recent date the threat activity was observed.
related_pivotsShared attributes linking the domain to related infrastructure: email, phone, fax, company name, organization, NS, MX, and CNAME.

Product

From Seed Domains to Flagged Infrastructure

Each feed starts from confirmed domains, then expands through the attributes those domains share with the rest of an attacker's infrastructure. To investigate a single indicator yourself, the historical DNS API returns the record trail for any domain in the feed.

  1. Step 1: Seed Data

    Each feed starts with domains confirmed for a specific threat type: phishing, malware, spam, botnet, or C2.

  2. Step 2: Pivot Extraction

    Extracting attributes like registrant email, phone, NS, MX, and CNAME shared across infrastructure.

  3. Step 3: Extrapolation

    Pivots are matched across the full database to surface related domains, even before they are reported publicly.

Product

How Is Each Feed Delivered?

Pull each feed from the WhoisFreaks API: a full dump to start, daily changes after. Full endpoints, authentication, and the record schema are in the threat feed API documentation.

Daily CSV Threat Feeds via API

Each threat type ships as a separate CSV file, retrieved through the WhoisFreaks API and updated daily. Your first pull is a full dump of every domain currently in that feed. Every pull after that is a daily update file with new and changed records.

Daily Incremental UpdatesStay current without reprocessing the full dataset every time.
Delivery SpecificationProduction Ready
FormatCSV (one per type)
DeliveryWhoisFreaks API
Update frequencyDaily
First deliveryFull Dump
Ongoing deliveriesDaily Changes

Use Cases

Who Uses Threat Intelligence Feeds?

From SOC pipelines to mail filters, the same scored records plug into the tools your teams already run.

Feature icon

SOC and Intel Teams

Ingest feeds into Splunk or Sentinel to match flagged domains against logs. Support retro-hunting with historical date context.

Feature icon

DNS Filtering

Load malware and botnet feeds into DNS firewalls or RPZ zones to stop connections before payloads are fetched.

Feature icon

Email Security

Feed spam and phishing lists into mail filters to block malicious messages surfaced through infrastructure pivots.

Feature icon

Brand Protection

Detect impersonation domains targeting your brand. Combine it with Newly Registered Domains feed for day-one protection.

Feature icon

Fraud and Risk

Screen signups and transactions against feeds to flag accounts operating from known malicious infrastructure.

Feature icon

MSSP Providers

Ingest feeds once and enforce across client environments. Scored records allow custom risk tolerance thresholds.

Request demo background

Walk through the feeds with our team, see how records are scored and delivered, and pick the threat types you need for blocking and investigation.

Comparison

How Do These Feeds Compare?

WhoisFreaks pipeline expands 896K verified indicators into 14M flagged records through shared pivots.

CapabilityOpen Community ListsWhoisFreaks Domain Threat Feeds
MethodReports and observations only
Verified seeds expanded through infrastructure pivots
ScoringMostly binary listed or not listed
Confidence value and risk score per record
Record contextUsually the domain or URL alone
Threat type, first and last seen, related pivots
First deliveryVaries; often forward-only
Full dump of the feed
LicensingOften restricted or non-commercial terms
Commercial license

Related Products

Newly Registered Domains

Newly Registered Domains

A daily feed of newly registered domains, so you can catch phishing before the sites go live.

NRD feed
Domain Reputation API

Domain Reputation API

Score any domain in real time from WHOIS, DNS, and hosting signals, and act on the risk score returned.

Domain Reputation API
Reverse WHOIS API

Reverse WHOIS API

Find every domain tied to a name, email, or organization and map the attacker infrastructure behind it.

Reverse WHOIS API

FAQs

Get quick answers to your questions about Domain Threat Intelligence.

What is a threat intelligence feed?

A threat intelligence feed is a regularly updated, machine-readable list of indicators (domains & IPs) observed in malicious activity. Security teams load feeds into SIEMs, DNS firewalls, and email gateways to block or investigate flagged domains. WhoisFreaks delivers feeds as daily CSV files, one per threat type: phishing, malware, spam, botnet, and C2.

What threat types do the feeds cover?

Whoisfreaks Threat Intelligence feed covers phishing, malware, spam, botnet, and command and control (C2). You can subscribe to a single feed or any combination.

How often are the feeds updated?

Every feed is updated daily. Each daily file contains new and changed records since the previous delivery.

How does a domain end up in a feed?

Each feed starts from verified seed domains for that threat type. WhoisFreaks extracts the pivots those seeds share, such as registrant email, organization, NS, MX, and CNAME records, then matches the pivots across its domain database to surface related domains. Every surfaced domain is assigned a confidence value and risk score before it is published.
The shared attributes that link the flagged domain to the rest of the campaign it belongs to: registrant email, phone, fax, company name, and organization, plus NS, MX, and CNAME records. Analysts use it to expand an investigation from one flagged domain to the surrounding infrastructure without running separate lookups.

Do I get historical data?

Yes. Your first delivery is a full dump of every domain currently in the feed, including records that entered the feed before your subscription started. Daily update files follow from that point.

How do I get access?

Contact the WhoisFreaks team through the contact form. There is no self-serve signup for the threat feeds at launch; access, feed selection, and pricing are handled directly.

How are these feeds different from free or open-source threat feeds?

Free and open-source threat intelligence feeds list domains from reports and observations, usually without scoring or context. WhoisFreaks starts from verified seed domains, expands them through shared registrant and DNS pivots, and assigns a confidence value and risk score to every record, so you get related infrastructure and a threshold you control.

What should you look for in a threat intelligence feed provider?

Look for verified sourcing over scraped lists, a confidence value or risk score on every record so you can set your own blocking threshold, related infrastructure pivots for investigation, daily updates, and clean CSV or API delivery. Many providers publish raw domain lists, WhoisFreaks scores each record and links it to the wider campaign.
Get the Domain Threat Feeds!

Tell us which threat types you need and how you plan to use them. We will set up your first full dump and daily deliveries.