Skip to content
RequestGuard Documentation
Pricing
Blocklists Updated Sep 8, 2026

Blocklists API

Understand RequestGuard IP and domain blocklist signals and related lookup endpoints.

Blocklist signals appear in IP intelligence, domain intelligence, fraud assessments, and rules. They are treated as one signal among others, not as the only decision source.

An active workspace API key and any Suite or Lookups plan are required. Each request consumes one shared lookup unit. See Authorization for limits and errors.

IP Blocklist Signals

Use the IP intelligence docs for DNSBL and abuse-list checks:

GET /ip/{ip}
GET /ip/{ip}/reputation

IP responses can include individual blocklist results, a blacklistCount, and risk factors such as ip_blocklist_match. RequestGuard separates listed, not_listed, and unavailable states. Resolver errors and timeouts do not count as a clean result.

The stateless probe service queries maintained DNSBLs through its local resolver. It also matches IPs against read-only VPS mirrors for X4B VPN and datacenter ranges, Tor exits, Team Cymru IPv4 and IPv6 fullbogons, Spamhaus DROP IPv4 and IPv6, and Feodo Tracker C2 addresses.

See IP Intelligence.

Domain Blocklist Signals

Use domain intelligence for a resolver-policy matrix and domain reputation evidence:

GET /domain/{domain}

The matrix compares Quad9 Threat Blocking, Cloudflare Security, CleanBrowsing Security, AdGuard Default, and Cloudflare Family against ordinary Cloudflare DNS. A domain is only marked blocked when the neutral reference resolves and the filtered resolver returns an explicit blocking response. Timeouts and resolver failures are reported as unavailable.

Threat-only resolver matches can affect security scoring. Ad/tracking and family-policy results remain evidence only because those policies cannot establish that a domain is malicious. NextDNS is not included because every profile can have different lists and settings; use the NextDNS log for the exact matching rule.

RequestGuard does not query restricted hosted domain URI blocklist services directly from the public domain intelligence endpoint.

See Domain Intelligence.

Bulk Check

POST /blocklists/check
{
  "targets": ["8.8.8.8", "example.com"]
}

A single target costs one lookup unit. More than one target requires Suite Business, Suite Agency or Lookups Growth; the full target count is reserved atomically before any checks.

Bulk blocklist checks accept a single target or up to 20 targets. Results include available and unavailable source counts. Domain results also include freshness, summary, and resolver checks alongside the existing listed, hits, and checked fields.

Rule Conditions

Rules can use IP allow/block lists, email domains, domains, countries, ASNs, hosting network flags, and risk score thresholds.

See Rules.