AbuseIPDB Checker
Abuse reports against the domain's hosting IP address.
This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain.
Based on: AbuseIPDB API Documentation
About this validation
Abuse reports against a domain's hosting IP address.
- Vendor documentation:
- Rules reviewed:
- Sep 6, 2026
SEOTechTests methodology: Data source: a live AbuseIPDB API query for the domain's resolved IP address. FAIL/WARNING scaled by AbuseIPDB's own confidence score; UNKNOWN when the API key isn't configured, DNS resolution fails, or the request errors.
Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.
FAQ
What does the AbuseIPDB check test?
It resolves the domain to an IP address and queries AbuseIPDB's community-reported abuse confidence score for that specific IP -- things like spam, brute-force, or attack reports filed by other users.
Why check the hosting IP instead of only the domain name?
Abuse activity (spam sending, brute-force scanning, botnet participation) is often reported against the IP actually doing it, which can be shared infrastructure -- this is a signal about the server's neighborhood, not necessarily this domain's own content.
Does a high AbuseIPDB score mean this domain is malicious?
Not necessarily -- on shared hosting, a bad score can reflect a different site or a past tenant on the same IP. It's one contextual infrastructure signal, weighed alongside the domain-specific checks.
Why can this check return UNKNOWN?
It needs a configured AbuseIPDB API key and a resolvable IP address. Missing either, or a failed/timed-out request, produces UNKNOWN rather than an assumed-clean PASS.