Hostname and domain reputation, checked before it's trusted.
SURIBS tracks confirmed and unconfirmed bad hosts at the hostname level: phishing, malware distribution, and brand-impersonation infrastructure. It publishes this three ways: a free public RHSBL, a licensed API with a keyed RHSBL, and this self-service dashboard.
Check a hostname
Free, keyless lookup against the same confirmed-bad-only view suribs.org serves over DNS. Exact hostname match only: a result for one host says nothing about a sibling on the same domain.
suribs.org
RHSBL over DNS: evil.com.suribs.org. A single fixed policy,
confirmed-bad only, rate-limited by source IP.
suribs.net
HTTPS API (lookup and submission) and a keyed RHSBL. Per-account policy: confirmed-vs-unconfirmed threshold, category filters, and your own allowlist.
Part of the same ecosystem
SURIBS is the published, publicly-interactive half of the MISUIC product, within misullivan.com's wider spam elimination ecosystem: outside sightings, licensed consumer submissions, and public threat intelligence all flow in here, and confirmed listings flow back out to the products that act on them, at mail time and at click time alike.
MISUIC
The URI intent classifier judges what a link is actually for, so it can give a verdict on a link no blocklist has seen yet. SURIBS supplies the reputation history, confirmed bad, or already earning trust, that MISUIC weighs alongside that intent.
Click-time URL protection
Links are rewritten as a message passes through the mail proxy and adjudicated again at the moment a recipient opens them, catching a site that was clean at delivery and weaponised since. SURIBS is one of the reputation sources checked at that moment.
How a listing happens
- A sighting is submitted: from URIs found in our own mail flow (spam and legitimate mail alike), a licensed consumer's API submission, or corroborated public threat intelligence.
- A single sighting at high confidence confirms immediately; otherwise
two independent sightings are required before a host is listed as
confirmedrather thanunconfirmed. - DNS listings are exact-hostname, never widened to a parent or child domain: a shared-hosting tenant's bad actor never lists the whole host.
- Licensed suribs.net consumers can query domain, host, path (subdirectory), and target information, for cases where only one tenant on a shared host is compromised.
- Reaching the highest trust tier works the other way round: it is never automatic, and always goes through a human review queue.