Skip to content

Latest commit

 

History

History
128 lines (91 loc) · 8.12 KB

File metadata and controls

128 lines (91 loc) · 8.12 KB

Exact-Host Security Blocklists

Generated: 2026-06-07 06:36:22 UTC

Audience: Security-focused / higher churn

False-Positive Risk: Elevated

Security-focused host blocking for phishing, malware, scam, dynamic DNS, and badware hoster feeds. These lists preserve exact hostnames so URL-derived feeds stay precise instead of collapsing to broad registrable roots.

Output Tiers

Quick Start

Use these lists when you want stronger protection against exact phishing or malware hosts and you are comfortable with faster list churn.

Recommended Entry Points

Use these starter bundles if you want a fast, opinionated default instead of picking categories one by one.

Bundle Best For Entries Includes File Raw URL
Security People who want stronger phishing and malware coverage 635,263 Badware Hosters, Dynamic DNS, Malware & Threats, Phishing & Scam Sites, Scam & Fraud security.txt Raw

Why Trust This Layer

  • Public Suffix List-aware domain normalization prevents bad roots like co.uk from leaking into generated outputs
  • Repo-local source policies remove noisy shared infrastructure and known false-positive patterns before lists are written
  • Validation reports are published at quality_report.json and check syntax, exclusions, and count drift
  • Standard, exact-host, and RPZ outputs are generated from the same source graph so the repo stays internally consistent

Aggregated Categories

Exact-host category bundles built from higher-sensitivity security feeds.

Category Entries Sources File Raw URL
🗄️ Badware Hosters 903 1 badware_hoster.txt Raw
🌐 Dynamic DNS 1,031 1 dynamic_dns.txt Raw
🦠 Malware & Threats 5,149 3 malware.txt Raw
🎣 Phishing & Scam Sites 415,433 3 phishing.txt Raw
💸 Scam & Fraud 212,854 3 scam.txt Raw

Individual Sources

Each source is also available separately if you want tighter source attribution or to tune false-positive handling.

Badware Hosters

Source Entries File Raw URL
HaGeZi Badware Hoster 903 hagezi_hoster.txt Raw

Dynamic DNS

Source Entries File Raw URL
HaGeZi Dynamic DNS 1,031 hagezi_dyndns.txt Raw

Malware & Threats

Source Entries File Raw URL
Block List Project Ransomware 1,904 blp_ransomware.txt Raw
ThreatFox 287 threatfox.txt Raw
URLhaus 3,108 urlhaus.txt Raw

Phishing & Scam Sites

Source Entries File Raw URL
OpenPhish 257 openphish.txt Raw
PhishTank 31,834 phishtank.txt Raw
Phishing Army 385,351 phishing_army.txt Raw

Scam & Fraud

Source Entries File Raw URL
Block List Project Fraud 195,904 blp_fraud.txt Raw
Block List Project Scam 1,274 blp_scam.txt Raw
HaGeZi Fake 15,749 hagezi_fake.txt Raw

Usage

Pi-hole / AdGuard Home

  1. Import the Raw URL of the exact-host list you want
  2. Start with the aggregated categories before stacking individual feeds
  3. Watch query logs closely after enabling them

When to use this layer

  1. You want stronger phishing and malware coverage
  2. You are comfortable whitelisting exact hosts when needed
  3. You prefer precision over broad domain collapsing

Format Details

  • Hosts file format - 0.0.0.0 hostname
  • Exact hostnames preserved - designed for URL-derived security feeds
  • Higher churn - entries can appear and disappear faster than the standard layer
  • Best paired with logging and allowlisting when you run it broadly

Data Sources

Notes

  • Start with the recommended bundles if you want the fewest decisions
  • Move to aggregated categories when you want control without going fully source-by-source
  • Whitelist when needed and watch your resolver logs after major changes
  • Exact-host security and RPZ layers are more aggressive than the standard services layer
  • Source feeds change over time, so entry counts will drift