Spamhaus DROP Blocklist Scraper
Pricing
from $1.00 / 1,000 results
Spamhaus DROP Blocklist Scraper
Pull the Spamhaus DROP and EDROP blocklists of hijacked and criminal netblocks. Each row carries the CIDR prefix, the Spamhaus SBL reference, the allocating regional internet registry, and IP version. Filter by registry across IPv4 and IPv6 for firewall and routing defense.
Pricing
from $1.00 / 1,000 results
Rating
0.0
(0)
Developer
ParseForge
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
a day ago
Last modified
Categories
Share

π‘οΈ Spamhaus DROP Blocklist Scraper
π Pull the live Spamhaus DROP and EDROP blocklists in one run. Get every hijacked or criminal netblock as a clean row with its CIDR, Spamhaus SBL reference, and regional internet registry, ready for firewall and routing blocklists.
Spamhaus DROP (Don't Route Or Peer) and EDROP are public, free blocklists published by The Spamhaus Project. They list IP netblocks that are directly allocated to, or hijacked by, spammers and cyber criminals. This Actor fetches the official Spamhaus DROP feeds and returns one clean row per netblock so network and security teams can ingest fresh indicators without parsing raw feed lines by hand.
This is a defensive, public-data threat-intelligence tool. Every record comes straight from the Spamhaus DROP download feed. Use it to feed firewall and BGP null-route blocklists, enrich alerts in a SOC, confirm whether a prefix is on the DROP list, or back research into criminal hosting patterns.
| π― Target Audience | π‘ Primary Use Cases |
|---|---|
| Network and security engineers | Block hijacked netblocks at the edge |
| SOC and blue-team analysts | Enrich alerts with DROP context |
| Threat intelligence teams | Track criminal netblock allocations |
| ISPs and hosting providers | Null-route DROP prefixes via BGP |
| Security researchers | Study RIR and netblock abuse trends |
π What the Spamhaus DROP Blocklist Scraper does
- Fetches the official Spamhaus DROP feeds for IPv4 (
drop_v4), IPv6 (drop_v6), or both. - Returns one row per netblock with the CIDR, Spamhaus SBL reference, and regional internet registry.
- Builds a direct link to the matching Spamhaus SBL record for each entry.
- Filters by regional internet registry (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC).
- Caps the number of rows returned so you can pull a quick sample or the whole list.
- Uses only the public download feed, no login, no API key, no images.
π Data fields
Each record includes: cidr, ipVersion, results, rir, sblid, sblUrl, scrapedAt. These field names come straight from the actor's dataset schema, so what you see here is what lands in your dataset.
π How to use
- Sign in or create a free Apify account using this sign-up link.
- Open the Spamhaus DROP Blocklist Scraper and pick the
v4,v6, orbothlist. - Optionally set a regional internet registry filter.
- Set
maxItemsand click Start. - When the run finishes, browse the dataset or pull it through the API into your tools.
π Recommended Actors
- Feodo Tracker C2 Scraper. Pull the abuse.ch Feodo Tracker botnet C2 IP blocklist.
- crt.sh Certificate Transparency Scraper. Search certificate transparency logs by domain.
- Have I Been Pwned Breaches Scraper. Browse the catalog of known data breaches.
- EPA FRS Facility Registry Scraper. Query the EPA Facility Registry Service.
- deps.dev Package Insights Scraper. Pull open source package security and dependency data.
π‘ Pro Tip: browse the complete ParseForge collection.
β οΈ Disclaimer: This is an independent tool and is not affiliated with The Spamhaus Project. Only publicly available data is collected, and it is provided for defensive security and research purposes.
π Need Help?
If you hit a bug, have questions about setup, or need a scraper we haven't built yet, open our contact form or write to parseforge@protonmail.com. We also take on paid custom data projects.
For faster answers, join our Discord. It's the best place to get support and suggest new actors.


