Threat Feed Checker
Check if a domain is flagged by DNS-based threat feeds (SURBL, Spamhaus DBL, URIBL, SORBS). Catch phishing and malware flags before your users do.
About this check
What does this tool check?
It queries five public DNS-based threat feeds: SURBL, the Spamhaus Domain Block List, URIBL (Spam Eating Monkey), the URIBL malware list, and the SORBS RHSBL. These feeds flag domains observed in phishing campaigns, malware distribution, and spam. Mail servers, web filters and security appliances consult them to decide whether to trust your domain. This tool does not query the Google Safe Browsing API; if you also want that verdict, Google offers its own transparency report lookup.
Why check threat feed status?
If your domain lands on one of these feeds, mail filters start junking your email and web filters may block your site outright. This can destroy deliverability and trust overnight. Regular checks let you catch a listing early, investigate the cause (compromised pages, injected scripts, a spam outbreak from your infrastructure), and request delisting once the issue is resolved.
What if my domain is flagged?
First, identify and remove the malicious content or spam source. Common causes include compromised CMS plugins, injected JavaScript, phishing pages placed in forgotten subdirectories, or a compromised mail account. After cleanup, each feed has its own delisting process: Spamhaus, SURBL and URIBL all take removal requests on their sites and typically process them within days.
FAQ
Operator questions, answered.
Is this threat feed checker free?+
Yes, completely free. No signup or credit card required. Check any public domain instantly.
Which feeds exactly do you query?+
Five DNS blocklists: multi.surbl.org, dbl.spamhaus.org, uribl.spameatingmonkey.net, malware.uribl.com and rhsbl.sorbs.net. Each is queried live over DNS at the moment you run the check; we do not cache or invent results.
Is this the same as Google Safe Browsing?+
No. Google Safe Browsing is a separate service that powers the red warning page in Chrome and other browsers. This tool queries DNS-based blocklists used mainly by mail and web filters. A domain can be clean on one and flagged on the other, so checking both is worthwhile.
Can a false positive occur?+
Yes, legitimate sites are occasionally listed, especially on shared hosting where another tenant misbehaves, or if user-generated content on your site was abused. Each feed accepts delisting requests with evidence that the issue has been resolved.
Threat Feed Checker is one slice of the full scan.
A free CQwerty scan covers TLS, DMARC / SPF / DKIM, DNS, headers, WHOIS, exposed files and spam blocklists in a single 90 second submission.