Free tools

Is This IP Malicious?

That address hammering your auth.log - known attacker or random noise? Check it against three live threat feeds and get a plain-English verdict. No signup.

What the three feeds tell you

Spamhaus DROP lists entire netblocks that are hijacked or leased directly to criminal operations - an address inside one has no legitimate reason to touch your server. IPsum aggregates roughly thirty public blocklists and counts how many list each IP - the population is dominated by SSH brute-forcers and scanners, so it's the feed your auth.log visitors usually show up in. URLhaus tracks live malware-distribution URLs - an IP here is actively serving payloads. These are the same three feeds AlertKick ships as default threat intelligence, checked against your hosts' real connections.

"Not listed" does not mean "safe"

Public feeds catch the loud, reused infrastructure - botnets, scanners, bulletproof hosting. A targeted attacker on fresh infrastructure won't be on any list, which is why a clean lookup is a data point rather than a verdict. The durable answer is watching what addresses actually do on your servers: which ones log in, what runs afterwards, and what changes. If you're triaging a suspicious address right now, that runbook is the next step.

Stop looking IPs up by hand

AlertKick's agent checks every real connection to your servers against these feeds automatically - and tells you when a listed address connects, logs in, or your host starts talking back to one. Included with every monitored host.

Watch my servers - free

Data: Spamhaus DROP, IPsum, and URLhaus (abuse.ch), refreshed daily. Also useful: SSL checker and domain expiry checker.