Investigate → confirm → block
Investigations against hackers, fraud and abuse
Enter an IP, domain, email, wallet or Telegram channel — BlockSpam queries open sources in parallel, builds a link graph inside the case and tells you who held the address at the moment of the incident and whom to contact next.
Access after the organisation is verified. Every search lives in a case with a legal basis.
- rdap_ipBlock holder: Example Hosting B.V.NL
- ripestat_ipAnnounced 14 Mar 2026: AS 2xxxx (tenant)at date
- abuseipdb47 reports in 30 days · SSH brute forcerisk
- urlhauslogin-secure-bank.top → this IPphishing
From the first finding to the block
Investigate
A case with a legal basis. One identifier → dozens of sources in parallel → findings, a link graph and one-click pivots.
Confirm
Claims with a confidence level, a source and the time it was queried. Nothing is listed without two keys.
Block
Confirmed indicators go to the blocklists: REST checks, JSON/CSV/STIX 2.1 exports and DNSBL for mail gateways.
Answers to the questions people actually ask
Derived from real law-enforcement requests: what kind of address it is and what it’s used for, who used it at that moment, whether logs are kept, and where to go next.
Who held the IP at time T
Block holder → tenant → the AS announcing the address that day → abuse contact and the next recipient of the request.
Link graph and pivots
Findings spawn new identifiers: domain → IP → AS → neighbouring domains. A 3D case graph, a new search straight from a node.
Documents sort themselves
Drop a batch of files: request, translation, reply, receipt. Document type, case number, timestamps with time zones and questions are recognised automatically.
Case analytics
Claims C001… graded from HIGH to REJECTED, hypotheses with evidence for and against, a timeline with typed timestamps. No fake-precision percentages.
Telegram as a first-class target
Channel card and public feed, archive and mentions in other channels. A channel deleted from t.me stays on record in the case.
Infostealers and ransomware
Has a domain or address appeared in infostealer logs, has it been claimed as a victim on a leak site. Credentials are never stored.
Email forensics
From / Reply-To / Return-Path and their mismatches, the Received chain with the origin IP, SPF/DKIM/DMARC, deceptive links, attachment hashes.
Monitor what you own
The owner’s networks, domains, channels and wallets: blocklist hits, complaints, lookalike domains, DNS changes — alerts twice a day.
The block holder almost never knows the end user
So the answer is a chain. A single /24 can pass through several tenants in a year, and BlockSpam shows every link as of the incident date — with its source and strength. A tenant ASN that disagrees with BGP, or no announcement at all, raises a warning instead of silence.
One click turns the result into case claims — with honest limits.
- Prefix185.xx.xx.0/24RDAP · RIR holder
- Leasing brokerIPXO / InterLIRowner’s lease register
- TenantExample Ltd · AS 2xxxxcontract, period, contacts
- Announcement at dateAS 2xxxx · 14 Mar 09:41 UTCRIPEstat routing history
- Next recipientabuse@… · NL · MLATwhom to contact next
Both sides of a request on one platform
A request about a resource is matched to its owner by the narrowest verified prefix or domain and lands in the owner’s inbox. If the owner isn’t on the platform — the RDAP abuse contact.
Police, prosecutors, CERTs, private investigators
- ✓Cases by IP and timestamp, wallets, channels
- ✓“Whom to contact next” and the jurisdiction
- ✓Send a request to the resource owner from the case
ISPs, hosting providers, companies, channel owners
- ✓Proof of ownership: RDAP, DNS TXT, a code in the channel
- ✓Incoming requests with the document and legal basis
- ✓Subnet lease register — answers as of a date
Both roles at once
- ✓Complaints about your networks and about others
- ✓Blocklists and delisting in one place
- ✓Recurring tenants and ASes as a risk signal
Blocklists you can trust
A false positive means an innocent person’s mail gets blocked. That’s why only confirmed entries are listed, every entry expires, and email addresses are exported as SHA-256.
- REST check
- Anti-fraud, sign-up, payments
- JSON · CSV · TXT · STIX 2.1
- SIEM, TIP, MISP
- DNSBL (RFC 5782)
- Postfix, Rspamd, SpamAssassin
- STIX and MISP import
- Your indicators into the case and the registry
abuse.ch feeds (URLhaus, ThreatFox, Feodo Tracker) are imported daily. Anything removed by a moderator or delisted is never brought back by an import.
$ curl -H "X-API-Key: $KEY" \"https://app.blockspam.io/api/v1/feed/check?type=domain&value=login-secure-bank.top"{ "query": "login-secure-bank.top", "listed": true,"matches": [{ "category": "phishing", "confidence": 90, … }] }
$ dig +short 2.0.0.127.ip.dnsbl.blockspam.io127.0.0.2 ; 2 = spam$ dig +short TXT 2.0.0.127.ip.dnsbl.blockspam.io"Listed by BlockSpam (spam): 127.0.0.2. Delist: https://blockspam.io/lookup"
A tool for investigations, not surveillance
These rules are built into the product and cannot be switched off in settings.
Verified customers only
An organisation is verified before it can search. Law-enforcement status requires a separate check.
Searches only inside a case
Every case requires a legal basis: incident, complaint, fraud, contract.
Full audit trail
Every read, search and change goes into the organisation’s immutable log.
Data minimisation
No passwords or hashes from breaches — only the fact and the date. Case data is deleted after the retention period.
Public sources only
Public and official APIs. No bypassing logins or CAPTCHAs.
Two keys to block
An entry becomes active after a moderator or reports from two independent organisations. Delisting is public.
Sources
A source that doesn’t answer in time doesn’t break the search — the error shows up in the findingsOnboard your organisation
Sign-up takes a minute. Once the organisation is verified, cases, search and blocklists open up. Law-enforcement agencies get a dedicated status after their official details are confirmed.