What this data means — and what it does not.
The Observatory shows third-party and public observations of malicious internet infrastructure. It is an evidence surface — a lens on open data — not an authoritative blocklist and not a verdict on any network operator.
Read this first
- Intelligence is sourced from third-party and public providers, each with its own definitions, collection methods and licence terms.
- Indicators become stale. A record shows first seen, last seen and ingested at.
- An indicator can be malicious in one context and benign later; a domain may be compromised, then cleaned.
- Geolocation refers to observed hosting infrastructure. It does not identify an attacker or a victim.
- No single provider should be treated as absolute truth.
- Absence of a record is not evidence of safety. We never label anything “clean”.
- DNS Daddy preserves provenance so you can always inspect why something appears, who reported it, and whether the value may be republished.
Ingest
Public abuse dumps from abuse.ch Feodo Tracker and URLhaus are pulled server-side on a five minute cache window. No credentials, no user data, no outbound telemetry.
Normalise
Heterogeneous CSV and JSON records collapse into a single indicator shape: type, classification, host, port, ASN, country, malware family, first and last seen.
Score
Severity is derived from classification, upstream status and malware family. Live botnet command-and-control scores critical; unresolved or aged records decay downward.
Interpret
Attribution is registry-level, not owner-level. A hot country or ASN reflects where infrastructure is hosted — not who operates it, and not who is responsible.
Known limits
- Coverage is partial. Only what the upstream feeds publish is visible. Absence of an indicator is not evidence of safety.
- Geography is hosting, not origin. Country is resolved from network registration, so operators using foreign hosting appear there.
- Timestamps are upstream. "Last seen" reflects the reporting feed's observation, not a live probe from this application.
About this project
DNS Daddy Threat Observatory is a student-built open-source cybersecurity project exploring threat intelligence, DNS infrastructure and explainable security analysis.
Google Public DNS, Safe Browsing, Map Tiles, Gemini with Google Search grounding, the threat-intelligence feeds and the hosting behind them all carry ongoing costs. AI-assisted analysis uses paid API resources. Community support contributes toward API, hosting and development costs — every feature stays free and unpaywalled either way.
Support DNS Daddy Threat Observatory
DNS Daddy Threat Observatory is a student-built open-source cybersecurity project exploring threat intelligence, DNS infrastructure and explainable security analysis. Help cover API usage, hosting and ongoing development. Entirely optional — nothing here is paywalled.
Support DNS Daddy