Generated: 2026-06-07 06:36:22 UTC
Audience: Security-focused / higher churn
False-Positive Risk: Elevated
Security-focused host blocking for phishing, malware, scam, dynamic DNS, and badware hoster feeds. These lists preserve exact hostnames so URL-derived feeds stay precise instead of collapsing to broad registrable roots.
- services - home-safe, registrable-domain blocklists
- security - exact-host security blocklists
- rpz - Unbound-friendly RPZ policies
- hardening - DNSTwist-derived brand impersonation blocklists
- active impersonation review - scored live-lookalike review reports
Use these lists when you want stronger protection against exact phishing or malware hosts and you are comfortable with faster list churn.
Use these starter bundles if you want a fast, opinionated default instead of picking categories one by one.
| Bundle | Best For | Entries | Includes | File | Raw URL |
|---|---|---|---|---|---|
| Security | People who want stronger phishing and malware coverage | 635,263 | Badware Hosters, Dynamic DNS, Malware & Threats, Phishing & Scam Sites, Scam & Fraud | security.txt | Raw |
- Public Suffix List-aware domain normalization prevents bad roots like
co.ukfrom leaking into generated outputs - Repo-local source policies remove noisy shared infrastructure and known false-positive patterns before lists are written
- Validation reports are published at quality_report.json and check syntax, exclusions, and count drift
- Standard, exact-host, and RPZ outputs are generated from the same source graph so the repo stays internally consistent
Exact-host category bundles built from higher-sensitivity security feeds.
| Category | Entries | Sources | File | Raw URL |
|---|---|---|---|---|
| 🗄️ Badware Hosters | 903 | 1 | badware_hoster.txt | Raw |
| 🌐 Dynamic DNS | 1,031 | 1 | dynamic_dns.txt | Raw |
| 🦠 Malware & Threats | 5,149 | 3 | malware.txt | Raw |
| 🎣 Phishing & Scam Sites | 415,433 | 3 | phishing.txt | Raw |
| 💸 Scam & Fraud | 212,854 | 3 | scam.txt | Raw |
Each source is also available separately if you want tighter source attribution or to tune false-positive handling.
| Source | Entries | File | Raw URL |
|---|---|---|---|
| HaGeZi Badware Hoster | 903 | hagezi_hoster.txt | Raw |
| Source | Entries | File | Raw URL |
|---|---|---|---|
| HaGeZi Dynamic DNS | 1,031 | hagezi_dyndns.txt | Raw |
| Source | Entries | File | Raw URL |
|---|---|---|---|
| Block List Project Ransomware | 1,904 | blp_ransomware.txt | Raw |
| ThreatFox | 287 | threatfox.txt | Raw |
| URLhaus | 3,108 | urlhaus.txt | Raw |
| Source | Entries | File | Raw URL |
|---|---|---|---|
| OpenPhish | 257 | openphish.txt | Raw |
| PhishTank | 31,834 | phishtank.txt | Raw |
| Phishing Army | 385,351 | phishing_army.txt | Raw |
| Source | Entries | File | Raw URL |
|---|---|---|---|
| Block List Project Fraud | 195,904 | blp_fraud.txt | Raw |
| Block List Project Scam | 1,274 | blp_scam.txt | Raw |
| HaGeZi Fake | 15,749 | hagezi_fake.txt | Raw |
- Import the Raw URL of the exact-host list you want
- Start with the aggregated categories before stacking individual feeds
- Watch query logs closely after enabling them
- You want stronger phishing and malware coverage
- You are comfortable whitelisting exact hosts when needed
- You prefer precision over broad domain collapsing
- Hosts file format -
0.0.0.0 hostname - Exact hostnames preserved - designed for URL-derived security feeds
- Higher churn - entries can appear and disappear faster than the standard layer
- Best paired with logging and allowlisting when you run it broadly
- AdGuard - service blocklists for social media, gaming, streaming, and more
- Phishing Army - active phishing domains
- OpenPhish - phishing URLs converted to exact hosts
- PhishTank - verified phishing URLs converted to exact hosts
- ThreatFox - malware indicators from abuse.ch
- URLhaus - malware distribution URLs converted to exact hosts
- The Block List Project - curated category feeds for abuse, crypto, drugs, piracy, redirects, smart TV, torrent, tracking, vaping, and more
- HaGeZi DNS Blocklists - dynamic DNS, badware hoster, fake-domain, DNS-bypass, and URL-shortener feeds
- UKLANS cache-domains - gaming CDN/cache hostnames
- StevenBlack and Chad Mayfield - adult-content feeds
- Start with the recommended bundles if you want the fewest decisions
- Move to aggregated categories when you want control without going fully source-by-source
- Whitelist when needed and watch your resolver logs after major changes
- Exact-host security and RPZ layers are more aggressive than the standard services layer
- Source feeds change over time, so entry counts will drift