Skip to main content
The Complete AntiProxies Dataset

22 data categories. One annual price. Local lookups.

22 categories of curated cybersecurity data - from IP intelligence and bot fingerprints to WAF rules and email blacklists. Self-hosted, so your users' data stays yours.

Six pillars of protection

From IP-level blocking to network fingerprinting - the data you need to identify and reduce fraud, bots, and abuse across your application.

IP Intelligence

Datacenter, VPN, proxy, CDN, serverless, and Tor IP ranges for identifying non-human traffic.

  • 75 datacenter providers (AWS, Azure, GCP, Hetzner, etc.)
  • 1,000+ VPN providers (NordVPN, ExpressVPN, Mullvad, etc.)
  • 10 residential proxy networks (BrightData, Oxylabs, etc.)
  • 12 CDN networks, 10 serverless platforms
  • Open proxies (HTTP, HTTPS, SOCKS4, SOCKS5)
  • Tor exit nodes, relay nodes & proxy list

Threat Intelligence

10 categories of known threat IPs: botnets, brute force, phishing, spam, bulletproof hosting, and more.

  • Active attack source IPs
  • Botnet C2 command servers
  • Brute force attackers (RDP, SSH, SMTP)
  • Bulletproof hosting providers
  • Compromised hosts & phishing IPs
  • Spamhaus DROP list integration

Bot & Crawler Detection

Search engine bots, AI crawlers, user agents, and internet scanners - know exactly what visits your site.

  • 10 search engine bots (Google, Bing, Apple, etc.)
  • 8 AI crawlers (GPTBot, ClaudeBot, Perplexity, etc.)
  • Bad bots, fake browsers & scraper user agents
  • Vulnerability scanner signatures
  • 5 internet scanners (Shodan, Censys, etc.)
  • Good bot vs bad bot classification

Email & Domain Security

Disposable email domains, spam sources, phishing TLDs, bad referrers, and SMTP blacklists.

  • Disposable/temporary email domains
  • Spam email domains
  • University email domains (US & UK)
  • SMTP blacklists (open relays, spam, phishing)
  • Suspicious newly registered domains (NRD)
  • URL shorteners & dynamic DNS domains

TLS/HTTP Fingerprinting

JA3, JA4, and HTTP/2 fingerprints to identify bots by their network signature, not just IP.

  • JA3 bot fingerprints (known bot hashes)
  • JA3 legitimate browser fingerprints
  • JA4 next-gen fingerprints
  • HTTP/2 connection fingerprints
  • HTTP header order analysis (bots vs browsers)
  • Client identification by TLS handshake

WAF Rules & Geo-Blocking

Ready-made WAF regex patterns and country IP ranges for comprehensive application protection.

  • SQL Injection patterns (UNION SELECT, OR 1=1, etc.)
  • XSS patterns (<script>, onerror=, etc.)
  • RCE & LFI/RFI detection patterns
  • Scanner signature patterns
  • Protocol anomaly detection
  • 22 country IP ranges for geo-blocking

All 22 data categories, one price

No feature gating, no tiers. IP intelligence, threat feeds, WAF rules, fingerprints, email blacklists, and more - all included in a single plan.

Datacenters

75 providers

IP ranges of datacenter providers (AWS, Azure, GCP, Hetzner, DigitalOcean, OVH, and 69 more)

CDN

12 providers

IP ranges of CDN networks (CloudFront, Cloudflare, Fastly, Akamai, and more)

VPN Providers

1,000+ providers

IP addresses of VPN servers (NordVPN, ExpressVPN, Surfshark, ProtonVPN, Mullvad, and more)

DNS Providers

8 providers

IP addresses of public DNS resolvers (Google DNS, Cloudflare DNS, Quad9, and more)

DNS-over-HTTPS

2 lists

DoH domains and endpoints for identifying encrypted DNS traffic

Search Engine Crawlers

10 bots

IPs of legitimate search engine bots (GoogleBot, Bingbot, Applebot, and more)

AI Crawlers

8 bots

IPs of AI training bots (GPTBot, ClaudeBot, Perplexitybot, ByteSpider, and more)

Serverless Platforms

10 platforms

IP ranges of serverless services (AWS Lambda, Cloudflare Workers, Vercel, and more)

Residential Proxies

10 providers

IPs of residential proxy networks (BrightData, Oxylabs, SmartProxy, and more)

Open Proxies

6 types

Open proxy lists by type: HTTP, HTTPS, SOCKS4, SOCKS5, anonymous, and transparent

Tor Network

3 lists

Tor exit nodes, relay nodes, and combined proxy list

Threats

10 categories

Known threat IPs: attack sources, botnets, brute force, phishing, spam, and more

Countries

22 countries

IP ranges by country for geo-blocking (US, DE, GB, FR, RU, CN, BG, and 15 more)

Domains

7 lists

Suspicious domains: phishing TLDs, bad referrers, dynamic DNS, URL shorteners, NRD monitoring

User Agents

4 lists

Bot user agents: bad bots, fake browsers, scrapers & automation tools, vulnerability scanners

Internet Scanners

5 services

IPs of internet scanning services (Shodan, Censys, BinaryEdge, ShadowServer)

Email Lists

5 lists

Disposable email domains, spam domains, and university email domains (US & UK)

SMTP Blacklists

6 lists

Mail server protection: open relays, spam relays, compromised servers, phishing senders

ASN Data

6 categories

ASN numbers linked to VPNs, residential proxies, bulletproof hosting, cloud abuse, and spam

TLS/HTTP Fingerprints

6 lists

JA3/JA4 hashes and HTTP/2 fingerprints for bot identification by network signature

WAF Rules

6 categories

Regex patterns for SQLi, XSS, RCE, LFI/RFI, scanner signatures, and protocol anomalies

Website DDoS IPs

1 list

IP addresses that have participated in DDoS attacks against websites

22
Data Categories
200+
Tracked Services
150,000+
Email Domains
10,000+
ISP Profiles

Why teams add AntiProxies to their stack

AntiProxies isn't meant to replace your WAF, reCAPTCHA, or firewall - it's the threat intelligence layer underneath them. Other API solutions charge per query, gate features behind tiers, and route your user data through their servers. We don't.

Feature AntiProxies IPQualityScore Fingerprint SEON ProxyCheck
VPN Detection

Database covering 1,000+ commercial VPN providers with monthly updates. Identify users hiding behind VPN services in real time.

1,000+ VPN providers tracked
Learn more
Proxy Detection

Covers datacenter and residential proxies alike. Our lists include open proxies, SOCKS proxies, and HTTP/HTTPS proxies worldwide.

Datacenter + residential coverage
Learn more
Tor Detection

Maintained list of Tor exit nodes and bridge relays, published with each monthly release.

Exit node data, updated monthly
Learn more
Residential Proxy Detection

Residential proxies are the hardest threat to detect because they use real ISP IPs. Our database identifies known residential proxy networks.

Hardest threat vector covered
Learn more
Disposable Email Detection

Flag signups from known throwaway email services, including mainstream and obscure providers.

150,000+ disposable domains tracked
Learn more
Bot Detection

Identify automated traffic using datacenter IP ranges and known bot signatures. Distinguish good crawlers from malicious scrapers.

Bot fingerprinting via IP intelligence
Learn more
Device Fingerprinting

Not our approach. Device fingerprinting requires client-side JavaScript that collects user data - we believe in privacy-first detection.

Privacy-first: no client-side tracking
Social Media Lookup

Not our approach. Social media lookups expose user identities to third parties - incompatible with a privacy-first architecture.

Privacy-first: no identity lookups
Privacy-First Option

Runtime lookups happen inside your environment, so the IP address or email being checked is not sent to AntiProxies. Your wider compliance obligations still depend on how you use and retain that data.

No AntiProxies lookup API
Learn more
No Per-Query Fees

One flat price for unlimited local queries. No metered billing, no surprise invoices, no throttling - just €99/year for everything.

Flat €99/year, unlimited queries
Learn more
No Feature Gating

All categories are included in every plan. No tiers, no add-ons, no upsells - IP intelligence, threats, WAF rules, fingerprints, email security, and more.

All 22 categories included
Learn more
Detection Feed

Last 24 hours

24h
VPN detected NordVPN · DE
2m ago
Proxy blocked Datacenter · US
14m ago
Disposable email user@trashmail.com
31m ago
Tor exit node 185.220.101.xx
1h ago
Bot fingerprinted Scraper · Residential
2h ago
VPN detected ExpressVPN · NL
3h ago
Disposable email test@guerrillamail.com
5h ago
Proxy blocked SOCKS5 · SG
7h ago
Bot fingerprinted Credential Stuffer · DC
10h ago
Tor exit node 104.244.76.xx
14h ago
VPN detected Surfshark · JP
19h ago
Disposable email anon@tempmail.ninja
23h ago
VPN detected NordVPN · DE
2m ago
Proxy blocked Datacenter · US
14m ago
Disposable email user@trashmail.com
31m ago
Tor exit node 185.220.101.xx
1h ago
Bot fingerprinted Scraper · Residential
2h ago
VPN detected ExpressVPN · NL
3h ago
Disposable email test@guerrillamail.com
5h ago
Proxy blocked SOCKS5 · SG
7h ago
Bot fingerprinted Credential Stuffer · DC
10h ago
Tor exit node 104.244.76.xx
14h ago
VPN detected Surfshark · JP
19h ago
Disposable email anon@tempmail.ninja
23h ago
Simulated from real threat patterns

Last updated: February 2026. Something wrong? Let us know.

200+ services tracked across 22 categories - all for €99/year. Runtime lookups stay in your environment, with no per-query charge and no dependency on an AntiProxies API.

Compare Pricing

Why teams choose AntiProxies

No surprises on your invoice

€99/year gets you all 22 categories. No tiers, no add-ons, no hidden fees.

Privacy-first architecture

Every lookup runs in your environment. The IP address or email being checked is not sent to AntiProxies.

Updated monthly, not last quarter

We publish a new database release each month so you can replace older snapshots on a predictable schedule.

Tested before every release

Every database is verified against known threats before it ships. No silent regressions, no untested drops - just clean, accurate data on a predictable schedule.

Choose the format that fits your stack

Use ready-made formats for Nginx, Apache, HAProxy, Caddy, Traefik, iptables, and Cloudflare, or import CSV and JSON into your own datastore. Custom formats are available on request.

€99/year - all included

One price for every database, unlimited servers, and a full year of monthly updates. No per-query fees.

What AntiProxies does not replace

AntiProxies is a network-intelligence layer. It tells your systems what an incoming IP address is likely to be-such as a VPN, proxy, Tor exit, datacenter range, or disposable-email domain - before your application makes a high-impact decision.

That boundary is intentional. Lookups run on your infrastructure, so we do not receive transaction history, browser events, message content, or other user data. This keeps the service privacy-first, while letting your existing controls use a reliable network-risk signal.

Where it fits in your stack

Use AntiProxies to enrich a request with network context, then let the system that owns the relevant data decide what to do: allow it, slow it down, request verification, flag it for review, or block it. This layered approach is more accurate than relying on one signal alone.

Application-level fraud rules

Only your application knows whether an order is unusual, a coupon has been reused, or an account has changed its payout details. AntiProxies can flag a high-risk connection; your fraud rules combine that signal with transaction and account context.

Behavioral bot scoring

Mouse movement, navigation patterns, browser automation signals, and session timing are visible to your frontend or bot-management tool. We classify the network behind the session, giving those tools another signal rather than attempting to replace them.

DDoS mitigation

Volumetric attacks require traffic absorption and edge-level rate controls from a WAF, CDN, or specialist DDoS provider. Network intelligence can help inform their rules, but it cannot absorb attack traffic on its own.

Email-content spam filtering

We identify throwaway and disposable email domains at signup. Filtering the content, attachments, reputation, and delivery of messages is a separate job for an email-security or anti-spam system.

Ready to strengthen your defenses?

All 22 categories. €99/year. 30-day money-back guarantee. Ready-made formats for any stack - web servers, firewalls, databases, and more.