Investigate → confirm → block

Investigations against hackers, fraud and abuse

Enter an IP, domain, email, wallet or Telegram channel — BlockSpam queries open sources in parallel, builds a link graph inside the case and tells you who held the address at the moment of the incident and whom to contact next.

Access after the organisation is verified. Every search lives in a case with a legal basis.

#2026-0314 · fraud, remote accessopen
IP
185.xx.xx.17 @ 2026-03-14 10:41:07 CET
  • Block holder: Example Hosting B.V.NL
  • Announced 14 Mar 2026: AS 2xxxx (tenant)at date
  • 47 reports in 30 days · SSH brute forcerisk
  • login-secure-bank.top → this IPphishing
Search targetsdomainIPASNURLemailusernamephoneTelegramBTCETHTRONfile hash.eml message
The cycle

From the first finding to the block

01

Investigate

A case with a legal basis. One identifier → dozens of sources in parallel → findings, a link graph and one-click pivots.

02

Confirm

Claims with a confidence level, a source and the time it was queried. Nothing is listed without two keys.

03

Block

Confirmed indicators go to the blocklists: REST checks, JSON/CSV/STIX 2.1 exports and DNSBL for mail gateways.

Features

Answers to the questions people actually ask

Derived from real law-enforcement requests: what kind of address it is and what it’s used for, who used it at that moment, whether logs are kept, and where to go next.

◎

Who held the IP at time T

Block holder → tenant → the AS announcing the address that day → abuse contact and the next recipient of the request.

⌘

Link graph and pivots

Findings spawn new identifiers: domain → IP → AS → neighbouring domains. A 3D case graph, a new search straight from a node.

▤

Documents sort themselves

Drop a batch of files: request, translation, reply, receipt. Document type, case number, timestamps with time zones and questions are recognised automatically.

✓

Case analytics

Claims C001… graded from HIGH to REJECTED, hypotheses with evidence for and against, a timeline with typed timestamps. No fake-precision percentages.

✈

Telegram as a first-class target

Channel card and public feed, archive and mentions in other channels. A channel deleted from t.me stays on record in the case.

☣

Infostealers and ransomware

Has a domain or address appeared in infostealer logs, has it been claimed as a victim on a leak site. Credentials are never stored.

✉

Email forensics

From / Reply-To / Return-Path and their mismatches, the Received chain with the origin IP, SPF/DKIM/DMARC, deceptive links, attachment hashes.

◉

Monitor what you own

The owner’s networks, domains, channels and wallets: blocklist hits, complaints, lookalike domains, DNS changes — alerts twice a day.

A snapshot in time, not “now”

The block holder almost never knows the end user

So the answer is a chain. A single /24 can pass through several tenants in a year, and BlockSpam shows every link as of the incident date — with its source and strength. A tenant ASN that disagrees with BGP, or no announcement at all, raises a warning instead of silence.

One click turns the result into case claims — with honest limits.

  1. Prefix
    185.xx.xx.0/24
    RDAP · RIR holder
  2. Leasing broker
    IPXO / InterLIR
    owner’s lease register
  3. Tenant
    Example Ltd · AS 2xxxx
    contract, period, contacts
  4. Announcement at date
    AS 2xxxx · 14 Mar 09:41 UTC
    RIPEstat routing history
  5. Next recipient
    abuse@… · NL · MLAT
    whom to contact next
Who it’s for

Both sides of a request on one platform

A request about a resource is matched to its owner by the narrowest verified prefix or domain and lands in the owner’s inbox. If the owner isn’t on the platform — the RDAP abuse contact.

Investigator

Police, prosecutors, CERTs, private investigators

  • ✓Cases by IP and timestamp, wallets, channels
  • ✓“Whom to contact next” and the jurisdiction
  • ✓Send a request to the resource owner from the case
Resource owner

ISPs, hosting providers, companies, channel owners

  • ✓Proof of ownership: RDAP, DNS TXT, a code in the channel
  • ✓Incoming requests with the document and legal basis
  • ✓Subnet lease register — answers as of a date
Abuse desk

Both roles at once

  • ✓Complaints about your networks and about others
  • ✓Blocklists and delisting in one place
  • ✓Recurring tenants and ASes as a risk signal
BlockSpam Feed

Blocklists you can trust

A false positive means an innocent person’s mail gets blocked. That’s why only confirmed entries are listed, every entry expires, and email addresses are exported as SHA-256.

REST check
Anti-fraud, sign-up, payments
JSON · CSV · TXT · STIX 2.1
SIEM, TIP, MISP
DNSBL (RFC 5782)
Postfix, Rspamd, SpamAssassin
STIX and MISP import
Your indicators into the case and the registry

abuse.ch feeds (URLhaus, ThreatFox, Feodo Tracker) are imported daily. Anything removed by a moderator or delisted is never brought back by an import.

Feed API
$ curl -H "X-API-Key: $KEY" \
"https://app.blockspam.io/api/v1/feed/check?type=domain&value=login-secure-bank.top"
{ "query": "login-secure-bank.top", "listed": true,
"matches": [{ "category": "phishing", "confidence": 90, … }] }
DNSBL
$ dig +short 2.0.0.127.ip.dnsbl.blockspam.io
127.0.0.2 ; 2 = spam
$ dig +short TXT 2.0.0.127.ip.dnsbl.blockspam.io
"Listed by BlockSpam (spam): 127.0.0.2. Delist: https://blockspam.io/lookup"
Listed by mistake?
Public lookup and a removal request — no account needed.
Check →
Principles

A tool for investigations, not surveillance

These rules are built into the product and cannot be switched off in settings.

01

Verified customers only

An organisation is verified before it can search. Law-enforcement status requires a separate check.

02

Searches only inside a case

Every case requires a legal basis: incident, complaint, fraud, contract.

03

Full audit trail

Every read, search and change goes into the organisation’s immutable log.

04

Data minimisation

No passwords or hashes from breaches — only the fact and the date. Case data is deleted after the retention period.

05

Public sources only

Public and official APIs. No bypassing logins or CAPTCHAs.

06

Two keys to block

An entry becomes active after a moderator or reports from two independent organisations. Delisting is public.

Sources

A source that doesn’t answer in time doesn’t break the search — the error shows up in the findings
RDAP / WHOISDNScrt.shRIPEstatVirusTotalurlscan.ioShodanAbuseIPDBabuse.ch URLhausMalwareBazaarThreatFoxFeodo TrackerHybrid AnalysisHave I Been PwnedHudson Rockransomware.liveEtherscanTronGridblockstream.infoOFAC SDNGravatarTelegramTGStatTelemetr.io

Onboard your organisation

Sign-up takes a minute. Once the organisation is verified, cases, search and blocklists open up. Law-enforcement agencies get a dedicated status after their official details are confirmed.