suribs.org: free keyless RHSBL suribs.net: licensed API and keyed RHSBL suribs.com: this site, accounts and dashboard

Hostname and domain reputation, checked before it's trusted.

SURIBS tracks confirmed and unconfirmed bad hosts at the hostname level: phishing, malware distribution, and brand-impersonation infrastructure. It publishes this three ways: a free public RHSBL, a licensed API with a keyed RHSBL, and this self-service dashboard.

Check a hostname

Free, keyless lookup against the same confirmed-bad-only view suribs.org serves over DNS. Exact hostname match only: a result for one host says nothing about a sibling on the same domain.

Free, keyless

suribs.org

RHSBL over DNS: evil.com.suribs.org. A single fixed policy, confirmed-bad only, rate-limited by source IP.

Licensed

suribs.net

HTTPS API (lookup and submission) and a keyed RHSBL. Per-account policy: confirmed-vs-unconfirmed threshold, category filters, and your own allowlist.

This site

suribs.com

Sign up for a suribs.net account, issue API keys, build policies, and manage your allowlist. Sign up or log in.

Published for MISUIC

Part of the same ecosystem

SURIBS is the published, publicly-interactive half of the MISUIC product, within misullivan.com's wider spam elimination ecosystem: outside sightings, licensed consumer submissions, and public threat intelligence all flow in here, and confirmed listings flow back out to the products that act on them, at mail time and at click time alike.

MISUIC

The URI intent classifier judges what a link is actually for, so it can give a verdict on a link no blocklist has seen yet. SURIBS supplies the reputation history, confirmed bad, or already earning trust, that MISUIC weighs alongside that intent.

Click-time URL protection

Links are rewritten as a message passes through the mail proxy and adjudicated again at the moment a recipient opens them, catching a site that was clean at delivery and weaponised since. SURIBS is one of the reputation sources checked at that moment.

How a listing happens

  1. A sighting is submitted: from URIs found in our own mail flow (spam and legitimate mail alike), a licensed consumer's API submission, or corroborated public threat intelligence.
  2. A single sighting at high confidence confirms immediately; otherwise two independent sightings are required before a host is listed as confirmed rather than unconfirmed.
  3. DNS listings are exact-hostname, never widened to a parent or child domain: a shared-hosting tenant's bad actor never lists the whole host.
  4. Licensed suribs.net consumers can query domain, host, path (subdirectory), and target information, for cases where only one tenant on a shared host is compromised.
  5. Reaching the highest trust tier works the other way round: it is never automatic, and always goes through a human review queue.