Domain Threat Intelligence Feeds

Five daily CSV feeds of flagged domains, each record scored, dated, and linked to the infrastructure behind it. Built from verified seed data and pivot analysis across the WhoisFreaks domain database.

DomainThreat typeConfidenceFirst seenLast seenNo of threat matched pivots
00000001gogoli.infomalware12026-06-25T13:45:40.258478+00:...2026-07-16T10:58:55.129258+00:...N/A
000009594.xyzmalware12026-06-25T13:45:40.258478+00:...2026-07-16T10:58:55.129258+00:...N/A
00000.hikvision-cctv.sumalware12026-06-25T13:45:00.511284+00:...2026-07-20T00:15:10.839177+00:...N/A
00000l.nvms9000.sumalware12026-06-25T13:45:00.511284+00:...2026-07-20T00:15:10.839177+00:...N/A
0000262a0.shopmalware12026-06-25T13:45:40.258478+00:...2026-07-16T10:58:55.129258+00:...N/A
0000336fanjx3.sbsmalware12026-06-25T13:45:40.258478+00:...2026-07-16T10:58:55.129258+00:...N/A
000049998.xyzmalware12026-06-25T13:45:40.258478+00:...2026-07-16T10:58:55.129258+00:...N/A
0000550xtz2.shopmalware12026-06-25T13:45:40.258478+00:...2026-07-16T10:58:55.129258+00:...N/A
pricing backgroundEclipse Top RightEclipse Top Left

Features

What Threat Types Are Covered?

Each threat type is a separate feed file. Subscribe to one, several, or all five.

Phishing Domain Feed

A daily feed of phishing domains flagged for credential theft, fake login pages, and brand impersonation. Covers lookalike and typosquatted domains built to mimic banks, SaaS platforms, payment providers, and delivery services, plus phishing pages spun up on free hosting and site builders. Every record is surfaced through shared registrant and DNS pivots and scored, so email gateways and DNS filters can block domains before users ever reach them.

Phishing Domain Feed

Malware Domain Feed

A daily feed of malware domains observed distributing payloads, hosting infected downloaders, or serving files for ransomware, stealers, and loaders. Includes drive-by download sites and short-lived disposable domains registered purely for malware delivery. Every record is expanded from verified malware seeds through shared NS, MX, and registrant pivots, and carries a confidence value and risk score for DNS firewall, RPZ, and proxy blocklists.

Malware Domain Feed

Spam Domain Feed

A daily feed of spam domains caught sending unsolicited bulk email or hosting the landing pages and link networks spam campaigns promote. Covers snowshoe sending infrastructure, spamvertised domains, and mail systems with a history of abuse. Every record is expanded from verified spam seeds through shared MX, NS, and registrant pivots and scored, so secure email gateways and mail filters can reject messages and URLs at scale.

Spam Domain Feed

What Each Feed Record Contains

Every record in every feed follows the same schema, ensuring a single parser can handle all five files seamlessly.

HeaderDescription
domainThe flagged domain name.
threat_typeOne of phishing, malware, spam, botnet, or c2.
confidenceHow strongly the evidence supports the classification, from 0 to 1.
first_seenDate the domain first appeared in WhoisFreaks threat data.
last_seenMost recent date the threat activity was observed.
related_pivotsShared attributes linking the domain to related infrastructure: email, phone, fax, company name, organization, NS, MX, and CNAME.

Product

Global Registry Integration

Our multi-stage pipeline turns verified threat data into a comprehensive intelligence map using infrastructure-level analysis.

  1. Step 1: Seed Data

    Each feed starts with domains confirmed for a specific threat type: phishing, malware, spam, botnet, or C2.

  2. Step 2: Pivot Extraction

    Extracting attributes like registrant email, phone, NS, MX, and CNAME shared across infrastructure.

  3. Step 3: Extrapolation

    Pivots are matched across the full database to surface related domains, even before they are reported publicly.

Product

How Is Each Feed Delivered?

Pull each feed from the WhoisFreaks API: a full dump to start, daily changes after.

Daily CSV Threat Feeds via API

Each threat type ships as a separate CSV file, retrieved through the WhoisFreaks API and updated daily. Your first pull is a full dump of every domain currently in that feed. Every pull after that is a daily update file with new and changed records.

Daily Incremental UpdatesStay current without reprocessing the full dataset every time.
Delivery SpecificationProduction Ready
FormatCSV (one per type)
DeliveryWhoisFreaks API
Update frequencyDaily
First deliveryFull Dump
Ongoing deliveriesDaily Changes

Use Cases

Who Uses Domain Threat Feeds?

From SOC pipelines to mail filters, the same scored records plug into the tools your teams already run.

Feature icon

SOC and Intel Teams

Ingest feeds into Splunk or Sentinel to match flagged domains against logs. Support retro-hunting with historical date context.

Feature icon

DNS Filtering

Load malware and botnet feeds into DNS firewalls or RPZ zones to stop connections before payloads are fetched.

Feature icon

Email Security

Feed spam and phishing lists into mail filters to block malicious messages surfaced through infrastructure pivots.

Feature icon

Brand Protection

Catch impersonation domains targeting your brand. Pairs with Newly Registered Domains feed for day-one coverage.

Feature icon

Fraud and Risk

Screen signups and transactions against feeds to flag accounts operating from known malicious infrastructure.

Feature icon

MSSP Providers

Ingest feeds once and enforce across client environments. Scored records allow custom risk tolerance thresholds.

Request demo background

Walk through the feeds with our team, see how records are scored and delivered, and pick the threat types you need for blocking and investigation.

Comparison

How Do These Feeds Compare?

WhoisFreaks pipeline expands 862K verified indicators into 14M flagged records through shared pivots.

CapabilityOpen Community ListsWhoisFreaks Domain Threat Feeds
MethodReports and observations only
Verified seeds expanded through infrastructure pivots
ScoringMostly binary listed or not listed
Confidence value and risk score per record
Record contextUsually the domain or URL alone
Threat type, first and last seen, related pivots
First deliveryVaries; often forward-only
Full dump of the feed
LicensingOften restricted or non-commercial terms
Commercial license

FAQs

Get quick answers to your questions about Domain Threat Intelligence.

What is a domain threat intelligence feed?

A domain threat intelligence feed is a regularly updated list of domains observed in malicious activity, delivered in a machine-readable format. Security teams load feeds into SIEMs, DNS firewalls, and email gateways to block or investigate flagged domains. WhoisFreaks delivers five feeds as daily CSV files, one per threat type.

What threat types do the feeds cover?

Five types, each as a separate feed file: phishing, malware, spam, botnet, and command and control (C2). You can subscribe to a single feed or any combination.

How often are the feeds updated?

Every feed is updated daily. Each daily file contains new and changed records since the previous delivery.

How does a domain end up in a feed?

Each feed starts from verified seed domains for that threat type. WhoisFreaks extracts the pivots those seeds share, such as registrant email, organization, NS, MX, and CNAME records, then matches the pivots across its domain database to surface related domains. Every surfaced domain is assigned a confidence value and risk score before it is published.

What does the related_pivots field contain?

The shared attributes that link the flagged domain to the rest of the campaign it belongs to: registrant email, phone, fax, company name, and organization, plus NS, MX, and CNAME records. Analysts use it to expand an investigation from one flagged domain to the surrounding infrastructure without running separate lookups.

Do I get historical data?

Yes. Your first delivery is a full dump of every domain currently in the feed, including records that entered the feed before your subscription started. Daily update files follow from that point.

How do I get access?

Contact the WhoisFreaks team through the contact form. There is no self-serve signup for the threat feeds at launch; access, feed selection, and pricing are handled directly.
Get the Domain Threat Feeds!

Tell us which threat types you need and how you plan to use them. We will set up your first full dump and daily deliveries.