Five daily CSV feeds of flagged domains, each record scored, dated, and linked to the infrastructure behind it. Built from verified seed data and pivot analysis across the WhoisFreaks domain database.
Features
Each threat type is a separate feed file. Subscribe to one, several, or all five.
A daily feed of phishing domains flagged for credential theft, fake login pages, and brand impersonation. Covers lookalike and typosquatted domains built to mimic banks, SaaS platforms, payment providers, and delivery services, plus phishing pages spun up on free hosting and site builders. Every record is surfaced through shared registrant and DNS pivots and scored, so email gateways and DNS filters can block domains before users ever reach them.
A daily feed of malware domains observed distributing payloads, hosting infected downloaders, or serving files for ransomware, stealers, and loaders. Includes drive-by download sites and short-lived disposable domains registered purely for malware delivery. Every record is expanded from verified malware seeds through shared NS, MX, and registrant pivots, and carries a confidence value and risk score for DNS firewall, RPZ, and proxy blocklists.
A daily feed of spam domains caught sending unsolicited bulk email or hosting the landing pages and link networks spam campaigns promote. Covers snowshoe sending infrastructure, spamvertised domains, and mail systems with a history of abuse. Every record is expanded from verified spam seeds through shared MX, NS, and registrant pivots and scored, so secure email gateways and mail filters can reject messages and URLs at scale.
Every record in every feed follows the same schema, ensuring a single parser can handle all five files seamlessly.
| Header | Description |
|---|---|
| domain | The flagged domain name. |
| threat_type | One of phishing, malware, spam, botnet, or c2. |
| confidence | How strongly the evidence supports the classification, from 0 to 1. |
| first_seen | Date the domain first appeared in WhoisFreaks threat data. |
| last_seen | Most recent date the threat activity was observed. |
| related_pivots | Shared attributes linking the domain to related infrastructure: email, phone, fax, company name, organization, NS, MX, and CNAME. |
Product
Our multi-stage pipeline turns verified threat data into a comprehensive intelligence map using infrastructure-level analysis.
Each feed starts with domains confirmed for a specific threat type: phishing, malware, spam, botnet, or C2.
Extracting attributes like registrant email, phone, NS, MX, and CNAME shared across infrastructure.
Pivots are matched across the full database to surface related domains, even before they are reported publicly.
Product
Pull each feed from the WhoisFreaks API: a full dump to start, daily changes after.
Each threat type ships as a separate CSV file, retrieved through the WhoisFreaks API and updated daily. Your first pull is a full dump of every domain currently in that feed. Every pull after that is a daily update file with new and changed records.
Use Cases
From SOC pipelines to mail filters, the same scored records plug into the tools your teams already run.
Ingest feeds into Splunk or Sentinel to match flagged domains against logs. Support retro-hunting with historical date context.
Load malware and botnet feeds into DNS firewalls or RPZ zones to stop connections before payloads are fetched.
Feed spam and phishing lists into mail filters to block malicious messages surfaced through infrastructure pivots.
Catch impersonation domains targeting your brand. Pairs with Newly Registered Domains feed for day-one coverage.
Screen signups and transactions against feeds to flag accounts operating from known malicious infrastructure.
Ingest feeds once and enforce across client environments. Scored records allow custom risk tolerance thresholds.
Walk through the feeds with our team, see how records are scored and delivered, and pick the threat types you need for blocking and investigation.
Comparison
WhoisFreaks pipeline expands 862K verified indicators into 14M flagged records through shared pivots.
| Capability | Open Community Lists | WhoisFreaks Domain Threat Feeds |
|---|---|---|
| Method | Reports and observations only | Verified seeds expanded through infrastructure pivots |
| Scoring | Mostly binary listed or not listed | Confidence value and risk score per record |
| Record context | Usually the domain or URL alone | Threat type, first and last seen, related pivots |
| First delivery | Varies; often forward-only | Full dump of the feed |
| Licensing | Often restricted or non-commercial terms | Commercial license |
Tell us which threat types you need and how you plan to use them. We will set up your first full dump and daily deliveries.