Skip to main content
100 free entries per database

Free threat intelligence samples

Last updated: December 2025

Evaluate every AntiProxies database before you buy. Below you'll find 100 real entries from each of our five core databases - the same data our customers use in production.

500
Free entries total
5
Database categories
CSV / JSON
Standard formats

Why we publish free samples

Most threat intelligence vendors hide their data behind paywalls and NDAs. We think that's backwards. If your business depends on accurate VPN detection, disposable email filtering, or bot mitigation, you should be able to verify data quality before spending a cent.

That's why we publish 100 genuine entries from each of our five databases. Use them to test your integration logic, benchmark against your current provider, or simply learn what structured threat intelligence looks like. Every record below is pulled from the same datasets that power fraud prevention for e-commerce platforms, SaaS applications, financial services, and gaming companies worldwide.

The full databases contain orders of magnitude more data - 1,000+ VPN providers, 148,484 disposable email domains, 471 ISP profiles - and are updated monthly. When you're ready, a single €99/year license gives you everything with no per-query fees and no data leaving your infrastructure.

Database 1 of 5

Disposable email domains

Disposable (or throwaway) email services let anyone create a temporary inbox in seconds. They're the number-one tool for fake signups, trial abuse, and spam. Our database tracks 148,484 domains - below are 100 of the most commonly seen.

# Domain
1 guerrillamail.com
2 tempmail.com
3 throwaway.email
4 mailinator.com
5 10minutemail.com
6 guerrillamailblock.com
7 grr.la
8 dispostable.com
9 yopmail.com
10 sharklasers.com
11 guerrillamail.info
12 guerrillamail.de
13 trashmail.com
14 trashmail.me
15 trashmail.net
16 despammed.com
17 tempail.com
18 binkmail.com
19 safetymail.info
20 filzmail.com
21 mailnesia.com
22 tempr.email
23 discard.email
24 discardmail.com
25 discardmail.de
26 emailondeck.com
27 getairmail.com
28 harakirimail.com
29 mailcatch.com
30 mailexpire.com
31 mailmoat.com
32 mailnull.com
33 mailsac.com
34 mailscrap.com
35 mailshell.com
36 mailzilla.com
37 maildrop.cc
38 mintemail.com
39 mohmal.com
40 mt2015.com
41 mytemp.email
42 nomail.xl.cx
43 nospam.ze.tc
44 owlpic.com
45 proxymail.eu
46 rcpt.at
47 reallymymail.com
48 rtrtr.com
49 spambox.us
50 spamcero.com
51 spamfree24.org
52 tempomail.fr
53 temporaryemail.net
54 temporaryforwarding.com
55 thankdog.com
56 trashymail.com
57 trashymail.net
58 twinmail.de
59 uggsrock.com
60 wegwerfmail.de
61 wegwerfmail.net
62 wh4f.org
63 yopmail.fr
64 zehnminuten.de
65 tempinbox.com
66 temp-mail.org
67 fake-box.com
68 emailfake.com
69 crazymailing.com
70 mailtemp.info
71 inboxbear.com
72 tempmailo.com
73 emailnax.com
74 burnermail.io
75 anonbox.net
76 getnada.com
77 dropmail.me
78 spamgourmet.com
79 meltmail.com
80 jetable.org
81 deadaddress.com
82 emailigo.de
83 spaml.de
84 trashmail.org
85 imstations.com
86 mobi.web.id
87 receiveee.com
88 tmpmail.net
89 tmpmail.org
90 boun.cr
91 mailpick.biz
92 disbox.net
93 disbox.org
94 e4ward.com
95 gishpuppy.com
96 mailblocks.com
97 mailimate.com
98 mailquack.com
99 mytrashmail.com
100 shieldedmail.com
101 sogetthis.com
102 soodonims.com
103 spamherelots.com
104 thisisnotmyrealemail.com
105 tradermail.info

How disposable email detection works

Disposable email services - also known as temporary email, throwaway email, or burner email - provide users with short-lived inboxes that expire after minutes or hours. Services like Guerrilla Mail, Mailinator, and YOPmail are among the most well-known, but new providers appear every week. Our database is continuously curated to catch both established and emerging disposable email domains.

When a user enters an email address during registration, checkout, or form submission, your application can perform a simple domain lookup against this list. If the domain matches, you can reject the submission, flag the account for review, or require a verified email from a legitimate provider. This single check dramatically reduces fake signups, coupon abuse, and spam form submissions.

Unlike API-based email verification services that charge per query, the AntiProxies disposable email list is a static file you host locally. Lookups are instant (a simple hash or set check), cost nothing per query, and - crucially - no user data leaves your servers. This makes the database ideal for GDPR-conscious businesses that need to validate email addresses without sending personal data to third parties.

Database 2 of 5

VPN & proxy IP ranges

Detect commercial VPN connections, residential proxies, and open proxies. Our database covers 1,000+ providers with CIDR ranges, provider attribution, and proxy type classification.

# CIDR Range Provider Type
1 103.86.96.0/22 NordVPN Commercial VPN
2 185.93.182.0/24 NordVPN Commercial VPN
3 146.70.0.0/16 Mullvad VPN Commercial VPN
4 198.54.128.0/24 ExpressVPN Commercial VPN
5 169.150.196.0/23 ExpressVPN Commercial VPN
6 193.148.18.0/24 Surfshark Commercial VPN
7 185.65.134.0/24 Surfshark Commercial VPN
8 37.120.198.0/24 CyberGhost Commercial VPN
9 89.46.62.0/24 CyberGhost Commercial VPN
10 185.159.156.0/22 Private Internet Access Commercial VPN
11 194.59.249.0/24 Private Internet Access Commercial VPN
12 91.207.174.0/24 ProtonVPN Commercial VPN
13 185.177.124.0/22 ProtonVPN Commercial VPN
14 37.19.200.0/22 IPVanish Commercial VPN
15 198.16.66.0/24 IPVanish Commercial VPN
16 82.102.16.0/22 Windscribe Commercial VPN
17 104.254.90.0/24 Windscribe Commercial VPN
18 185.213.152.0/22 TunnelBear Commercial VPN
19 45.87.212.0/22 HideMyAss Commercial VPN
20 103.75.118.0/24 HideMyAss Commercial VPN
21 185.242.4.0/22 VyprVPN Commercial VPN
22 73.3.72.0/24 VyprVPN Commercial VPN
23 176.10.104.0/24 AirVPN Commercial VPN
24 185.236.200.0/22 AirVPN Commercial VPN
25 87.249.133.0/24 IVPN Commercial VPN
26 91.234.36.0/24 Astrill VPN Commercial VPN
27 203.32.120.0/24 Astrill VPN Commercial VPN
28 185.45.72.0/22 Trust.Zone Commercial VPN
29 185.94.111.0/24 ZenMate Commercial VPN
30 185.220.70.0/24 Hotspot Shield Commercial VPN
31 172.98.67.0/24 TorGuard Commercial VPN
32 192.145.127.0/24 TorGuard Commercial VPN
33 45.133.172.0/22 AtlasVPN Commercial VPN
34 45.8.146.0/24 AtlasVPN Commercial VPN
35 154.47.20.0/24 PureVPN Commercial VPN
36 196.240.57.0/24 PureVPN Commercial VPN
37 138.199.1.0/24 Hola VPN Commercial VPN
38 185.76.10.0/24 StrongVPN Commercial VPN
39 45.85.118.0/24 Norton VPN Commercial VPN
40 89.187.160.0/22 Kaspersky VPN Commercial VPN
41 5.181.233.0/24 Bright Data Residential Proxy
42 185.119.56.0/22 Bright Data Residential Proxy
43 154.92.116.0/24 Oxylabs Residential Proxy
44 195.158.3.0/24 Oxylabs Residential Proxy
45 45.131.108.0/22 Smartproxy Residential Proxy
46 104.239.37.0/24 GeoSurf Residential Proxy
47 198.23.239.0/24 PacketStream Residential Proxy
48 45.94.47.0/24 IPRoyal Residential Proxy
49 185.130.105.0/24 Webshare Residential Proxy
50 104.143.226.0/24 Storm Proxies Residential Proxy
51 92.119.231.0/24 Soax Residential Proxy
52 195.80.150.0/24 NetNut Residential Proxy
53 45.95.96.0/22 Shifter Residential Proxy
54 103.214.44.0/24 Rayobyte Residential Proxy
55 198.44.255.0/24 Rayobyte Residential Proxy
56 185.76.9.0/24 Infatica Residential Proxy
57 38.154.227.0/24 Proxy-Cheap Residential Proxy
58 104.250.55.0/24 RSocks Residential Proxy
59 91.241.217.0/24 ProxySale Residential Proxy
60 45.140.13.0/24 ProxySale Residential Proxy
61 80.240.27.0/24 Open SOCKS Proxy Open Proxy
62 41.57.97.0/24 Open HTTP Proxy Open Proxy
63 95.154.73.0/24 Open SOCKS Proxy Open Proxy
64 103.216.51.0/24 Open HTTP Proxy Open Proxy
65 190.103.177.0/24 Open SOCKS Proxy Open Proxy
66 194.233.69.0/24 Unidentified VPN Commercial VPN
67 45.153.160.0/22 Unidentified VPN Commercial VPN
68 103.108.229.0/24 Unidentified Proxy Open Proxy
69 185.244.214.0/24 iVPN.net Commercial VPN
70 104.238.45.0/24 Hide.me Commercial VPN
71 185.191.124.0/22 Hide.me Commercial VPN
72 194.36.25.0/24 Mysterium VPN Commercial VPN
73 89.44.9.0/24 VPN.ht Commercial VPN
74 45.76.0.0/20 Unidentified Proxy Open Proxy
75 185.153.176.0/22 OVPN Commercial VPN
76 217.138.193.0/24 Azire VPN Commercial VPN
77 31.171.152.0/24 Unidentified VPN Commercial VPN
78 86.106.74.0/24 VPNArea Commercial VPN
79 45.63.0.0/20 Unidentified Proxy Open Proxy
80 185.156.46.0/24 WeVPN Commercial VPN
81 103.230.188.0/24 BolehVPN Commercial VPN
82 196.245.163.0/24 X-VPN Commercial VPN
83 92.223.89.0/24 Unidentified VPN Commercial VPN
84 185.185.25.0/24 Speedify Commercial VPN
85 193.138.218.0/24 AzireVPN Commercial VPN
86 89.248.167.0/24 Open SOCKS Proxy Open Proxy
87 109.248.149.0/24 ThunderVPN Commercial VPN
88 91.90.44.0/24 Unidentified Proxy Open Proxy
89 185.107.56.0/22 AnonVPN Commercial VPN
90 104.200.20.0/24 Unidentified Proxy Open Proxy
91 185.232.21.0/24 RusVPN Commercial VPN
92 45.132.75.0/24 VPN Unlimited Commercial VPN
93 79.110.52.0/24 Unidentified VPN Commercial VPN
94 103.195.100.0/24 Unidentified Proxy Open Proxy
95 185.216.33.0/24 Betternet Commercial VPN
96 185.25.204.0/24 F-Secure VPN Commercial VPN
97 45.86.203.0/24 Unidentified VPN Commercial VPN
98 193.32.127.0/24 Unidentified VPN Commercial VPN
99 185.248.85.0/24 Bitdefender VPN Commercial VPN
100 91.132.136.0/24 Avira Phantom VPN Commercial VPN

Understanding VPN and proxy detection

VPN and proxy detection is critical for fraud prevention, content licensing, and abuse mitigation. Commercial VPN services like NordVPN, ExpressVPN, and Surfshark allow users to mask their real IP address, making it difficult to enforce geographic restrictions or identify repeat offenders. Residential proxies - offered by services like Bright Data, Oxylabs, and Smartproxy - are even harder to detect because they route traffic through real consumer IP addresses.

Our VPN and proxy database maps IP ranges (in CIDR notation) to specific providers and proxy types. This structured approach lets you make nuanced decisions: you might choose to block all open proxies outright while only flagging commercial VPN connections for additional verification. The database includes three proxy classifications - commercial VPN, residential proxy, and open proxy - so your rules can be as granular as your use case demands.

Because the database is delivered as a downloadable file rather than an API, IP lookups happen at network speed with zero latency overhead. A CIDR trie or prefix tree makes lookups O(1) regardless of database size. This is the same approach used by high-traffic CDNs and firewalls - battle-tested and performant at any scale.

Database 3 of 5

Tor exit node IPs

The Tor network routes traffic through multiple relays to anonymize the user. Exit nodes are the final hop - the IP address your server actually sees. Our database tracks active exit nodes and is updated continuously.

# Exit Node IP
1 176.10.99.200
2 185.220.101.1
3 185.220.101.2
4 185.220.101.3
5 185.220.101.4
6 185.220.101.5
7 185.220.101.6
8 185.220.101.7
9 185.220.101.8
10 185.220.101.9
11 185.220.101.10
12 185.220.101.11
13 185.220.101.12
14 185.220.101.13
15 185.220.101.14
16 185.220.101.15
17 185.220.102.240
18 185.220.102.241
19 185.220.102.242
20 185.220.102.243
21 185.220.102.244
22 185.220.102.245
23 185.220.102.246
24 185.220.102.247
25 185.220.102.248
26 185.220.102.249
27 185.220.102.250
28 185.220.102.251
29 185.220.102.252
30 185.220.102.253
31 185.220.102.254
32 185.220.102.255
33 199.249.230.64
34 199.249.230.65
35 199.249.230.66
36 199.249.230.67
37 199.249.230.68
38 199.249.230.69
39 199.249.230.70
40 199.249.230.71
41 199.249.230.72
42 199.249.230.73
43 199.249.230.74
44 199.249.230.75
45 199.249.230.76
46 199.249.230.77
47 199.249.230.78
48 199.249.230.79
49 204.85.191.8
50 204.85.191.9
51 204.85.191.10
52 204.85.191.30
53 204.85.191.31
54 204.85.191.32
55 204.85.191.33
56 204.85.191.34
57 77.247.181.162
58 77.247.181.163
59 77.247.181.164
60 77.247.181.165
61 62.210.105.116
62 62.210.105.117
63 62.210.105.118
64 62.210.105.119
65 51.15.43.205
66 51.15.43.206
67 51.15.43.207
68 51.15.43.208
69 178.17.170.23
70 178.17.170.24
71 178.17.170.25
72 178.17.170.156
73 193.218.118.100
74 193.218.118.101
75 193.218.118.102
76 193.218.118.103
77 109.70.100.1
78 109.70.100.2
79 109.70.100.3
80 109.70.100.4
81 109.70.100.5
82 109.70.100.6
83 109.70.100.7
84 109.70.100.8
85 23.129.64.100
86 23.129.64.101
87 23.129.64.102
88 23.129.64.103
89 23.129.64.104
90 23.129.64.105
91 23.129.64.106
92 23.129.64.107
93 23.129.64.108
94 23.129.64.109
95 23.129.64.110
96 23.129.64.111
97 162.247.74.200
98 162.247.74.201
99 162.247.74.202
100 162.247.74.203
101 162.247.74.204
102 162.247.74.205
103 162.247.74.206
104 162.247.74.207
105 45.66.33.9
106 45.66.33.10
107 45.66.33.11
108 45.66.33.12

Why Tor exit node detection matters

The Tor (The Onion Router) network is designed to provide anonymity by encrypting and routing traffic through a series of volunteer-operated relays. While Tor serves legitimate privacy needs - journalists, activists, and privacy-conscious users rely on it daily - it is also frequently used to conduct fraud, bypass bans, and abuse online services. For businesses, the ability to identify traffic originating from Tor exit nodes is a key layer of defense.

Tor exit nodes are the final relay in the circuit - the IP address that connects to your server. Because exit node operators volunteer their IP addresses publicly, maintaining an accurate list requires continuous monitoring of the Tor directory authorities and consensus documents. Our database tracks active exit nodes, bridge relays, and historical Tor IPs to minimize both false positives and false negatives.

Common use cases for Tor detection include blocking anonymous account creation on social platforms, preventing fraudulent purchases on e-commerce sites, flagging suspicious login attempts in banking applications, and enforcing geographic content licensing. As with all AntiProxies databases, the Tor exit node list is a local file - no external API calls, no per-query costs, and no user data shared with third parties.

Database 4 of 5

ISP reputation data

Not all networks are equal. Our ISP reputation database profiles 471 internet service providers worldwide with abuse history, ASN mapping, risk scoring, and country attribution.

# ISP Name ASN Country Risk Abuse reports
1 Comcast Cable AS7922 US low 2
2 AT&T Services AS7018 US low 3
3 Verizon Business AS701 US low 1
4 Deutsche Telekom AS3320 DE low 2
5 BT Group AS2856 GB low 1
6 Orange S.A. AS3215 FR low 2
7 Telefonica AS3352 ES low 3
8 NTT Communications AS4713 JP low 1
9 China Telecom AS4134 CN high 87
10 China Unicom AS4837 CN high 74
11 Rostelecom AS12389 RU high 65
12 BSNL India AS9829 IN high 58
13 Pakistan Telecom AS17557 PK high 52
14 Vietnam Posts & Telecom AS45899 VN medium 31
15 Türk Telekom AS9121 TR medium 28
16 Airtel India AS9498 IN medium 22
17 Globe Telecom AS4775 PH medium 19
18 Telkom Indonesia AS17974 ID medium 25
19 Ethiopian Telecom AS24757 ET high 44
20 MTS Russia AS8359 RU high 55
21 TransTeleCom Russia AS20485 RU high 49
22 Kyivstar AS15895 UA medium 18
23 Vodafone Germany AS3209 DE low 4
24 Telia Company AS1299 SE low 2
25 Swisscom AS3303 CH low 1
26 KPN Netherlands AS1136 NL low 3
27 Telstra AS1221 AU low 2
28 Bell Canada AS577 CA low 2
29 Claro Brazil AS4230 BR medium 17
30 Telmex Mexico AS8151 MX medium 21
31 MTN Nigeria AS29465 NG high 42
32 Safaricom Kenya AS33771 KE medium 14
33 Jio India AS55836 IN medium 26
34 SK Broadband AS9318 KR low 5
35 SoftBank Japan AS17676 JP low 3
36 Singtel AS9506 SG low 2
37 PLDT Philippines AS9299 PH medium 16
38 True Internet Thailand AS17552 TH medium 13
39 Telkom South Africa AS36937 ZA medium 20
40 Etisalat UAE AS8966 AE low 4
41 STC Saudi Arabia AS39386 SA low 6
42 Beeline Russia AS3216 RU high 47
43 Megafon Russia AS31133 RU high 41
44 Ukrtelecom AS6849 UA medium 23
45 A1 Telekom Austria AS1901 AT low 2
46 Proximus Belgium AS5432 BE low 1
47 TDC Denmark AS3292 DK low 2
48 Elisa Finland AS6667 FI low 1
49 OTE Greece AS6799 GR low 5
50 Eircom Ireland AS5466 IE low 3
51 Telecom Italia AS3269 IT low 7
52 Telenor Norway AS2119 NO low 1
53 TP Poland AS5617 PL medium 12
54 MEO Portugal AS3243 PT low 3
55 Digi Romania AS20530 RO medium 15
56 Tele2 Sweden AS1257 SE low 2
57 Sunrise Switzerland AS6730 CH low 1
58 Spectrum (Charter) AS20115 US low 4
59 Cox Communications AS22773 US low 3
60 CenturyLink AS209 US low 5
61 Frontier Communications AS5650 US low 4
62 T-Mobile US AS21928 US low 3
63 Shaw Communications AS6327 CA low 2
64 Rogers Canada AS812 CA low 3
65 Vodafone UK AS1273 GB low 3
66 Sky UK AS5607 GB low 2
67 Free France AS12322 FR low 5
68 SFR France AS15557 FR low 4
69 Movistar Spain AS3352 ES low 3
70 MasMovil Spain AS15704 ES low 4
71 UPC Switzerland AS6830 CH low 2
72 Ziggo Netherlands AS33915 NL low 3
73 Tiscali Italy AS8612 IT medium 9
74 UPC Romania AS6830 RO medium 11
75 Hathway India AS17488 IN medium 16
76 ACT Fibernet India AS45194 IN medium 10
77 Viettel Vietnam AS7552 VN medium 19
78 FPT Telecom AS18403 VN medium 14
79 Thai Mobile AS131090 TH medium 11
80 Telconet Ecuador AS27947 EC medium 13
81 Cantv Venezuela AS8048 VE high 38
82 Iran Telecom AS58224 IR high 61
83 Bangladesh Telecom AS17494 BD high 35
84 Vodacom Tanzania AS36908 TZ medium 12
85 Glo Mobile Nigeria AS37148 NG high 39
86 Airtel Nigeria AS36873 NG high 36
87 Maroc Telecom AS6713 MA medium 15
88 Algerie Telecom AS36947 DZ medium 18
89 Tunisie Telecom AS2609 TN medium 11
90 LibanCell AS42003 LB medium 10
91 Turkcell AS34984 TR medium 14
92 Vodafone Turkey AS15897 TR medium 12
93 Dialog Sri Lanka AS18001 LK medium 9
94 Nepal Telecom AS17501 NP medium 16
95 Ncell Nepal AS133071 NP medium 13
96 Grameenphone Bangladesh AS58587 BD high 32
97 Unitel Angola AS36998 AO medium 15
98 Zamtel Zambia AS37146 ZM medium 10
99 TelOne Zimbabwe AS37204 ZW high 29
100 Afghan Wireless AS55330 AF high 33
101 Iraqi Telecom AS203214 IQ high 40

How ISP reputation scoring helps prevent fraud

IP geolocation tells you where a user is. ISP reputation tells you how trustworthy that connection is. Two users in the same city can have wildly different risk profiles depending on their ISP's abuse history. A customer on Comcast or Deutsche Telekom is statistically far less likely to be committing fraud than one routed through a high-abuse ISP with a long track record of hosting botnets and spam operations.

Our ISP reputation database assigns risk scores (low, medium, high) based on historical abuse data, botnet participation, spam origin rates, and the proportion of anonymized traffic emanating from each network. Each entry includes the ISP name, Autonomous System Number (ASN), country, and a numeric abuse history indicator. This lets you build nuanced risk models that go far beyond simple IP blocking.

Practical applications include adaptive authentication (requiring extra verification for high-risk ISPs), dynamic pricing protection (flagging suspicious orders from networks known for fraud), and signup quality scoring. Because ISP reputation changes slowly compared to individual IP addresses, the data remains accurate between monthly updates and is well-suited for batch processing workflows.

Database 5 of 5

Datacenter & cloud IP ranges

Real users browse from residential ISPs, not from AWS, Hetzner, or DigitalOcean. Our datacenter database maps IP ranges to providers and classifies them as cloud, hosting, or colocation - helping you distinguish bots and scrapers from legitimate visitors.

# CIDR Range Provider Type
1 3.0.0.0/15 Amazon Web Services Cloud
2 13.52.0.0/14 Amazon Web Services Cloud
3 18.144.0.0/15 Amazon Web Services Cloud
4 52.8.0.0/16 Amazon Web Services Cloud
5 54.67.0.0/16 Amazon Web Services Cloud
6 35.186.0.0/16 Google Cloud Cloud
7 35.190.0.0/17 Google Cloud Cloud
8 35.192.0.0/14 Google Cloud Cloud
9 34.64.0.0/14 Google Cloud Cloud
10 34.80.0.0/15 Google Cloud Cloud
11 20.33.0.0/16 Microsoft Azure Cloud
12 20.40.0.0/13 Microsoft Azure Cloud
13 40.74.0.0/15 Microsoft Azure Cloud
14 40.76.0.0/14 Microsoft Azure Cloud
15 104.40.0.0/13 Microsoft Azure Cloud
16 64.225.0.0/16 DigitalOcean Cloud
17 134.209.0.0/16 DigitalOcean Cloud
18 157.245.0.0/16 DigitalOcean Cloud
19 167.172.0.0/16 DigitalOcean Cloud
20 188.166.0.0/16 DigitalOcean Cloud
21 128.199.0.0/16 DigitalOcean Cloud
22 139.59.0.0/16 DigitalOcean Cloud
23 95.216.0.0/16 Hetzner Hosting
24 135.181.0.0/16 Hetzner Hosting
25 65.108.0.0/16 Hetzner Hosting
26 49.12.0.0/16 Hetzner Hosting
27 159.69.0.0/16 Hetzner Hosting
28 116.202.0.0/16 Hetzner Hosting
29 5.161.0.0/16 Hetzner Hosting
30 168.119.0.0/16 Hetzner Hosting
31 104.16.0.0/13 Cloudflare Cloud
32 172.64.0.0/13 Cloudflare Cloud
33 131.0.72.0/22 Cloudflare Cloud
34 141.101.64.0/18 Cloudflare Cloud
35 45.63.0.0/16 Vultr Cloud
36 108.61.0.0/16 Vultr Cloud
37 149.28.0.0/16 Vultr Cloud
38 207.246.0.0/16 Vultr Cloud
39 45.76.0.0/16 Vultr Cloud
40 45.32.0.0/16 Vultr Cloud
41 159.89.0.0/16 DigitalOcean Cloud
42 51.15.0.0/16 Scaleway Cloud
43 163.172.0.0/16 Scaleway Cloud
44 212.47.224.0/19 Scaleway Cloud
45 62.210.0.0/16 Scaleway Hosting
46 192.99.0.0/16 OVH Hosting
47 198.50.0.0/16 OVH Hosting
48 51.68.0.0/16 OVH Cloud
49 51.75.0.0/16 OVH Cloud
50 51.77.0.0/16 OVH Cloud
51 51.79.0.0/16 OVH Cloud
52 51.91.0.0/16 OVH Cloud
53 54.36.0.0/16 OVH Hosting
54 158.69.0.0/16 OVH Hosting
55 37.187.0.0/16 OVH Hosting
56 185.199.108.0/22 GitHub Pages Cloud
57 151.101.0.0/16 Fastly CDN Cloud
58 199.232.0.0/16 Fastly CDN Cloud
59 23.235.32.0/20 Fastly CDN Cloud
60 198.41.128.0/17 Cloudflare Cloud
61 66.220.144.0/20 Facebook/Meta Cloud
62 31.13.24.0/21 Facebook/Meta Cloud
63 157.240.0.0/17 Facebook/Meta Cloud
64 69.171.224.0/19 Facebook/Meta Cloud
65 209.85.128.0/17 Google Cloud
66 216.58.192.0/19 Google Cloud
67 142.250.0.0/15 Google Cloud
68 45.55.0.0/16 DigitalOcean Cloud
69 46.101.0.0/16 DigitalOcean Cloud
70 138.68.0.0/16 DigitalOcean Cloud
71 161.35.0.0/16 DigitalOcean Cloud
72 143.244.128.0/17 DigitalOcean Cloud
73 23.88.0.0/16 Hetzner Hosting
74 78.46.0.0/15 Hetzner Hosting
75 88.198.0.0/16 Hetzner Hosting
76 176.9.0.0/16 Hetzner Hosting
77 148.251.0.0/16 Hetzner Hosting
78 5.9.0.0/16 Hetzner Hosting
79 136.243.0.0/16 Hetzner Hosting
80 178.63.0.0/16 Hetzner Hosting
81 50.116.0.0/16 Linode/Akamai Cloud
82 72.14.176.0/20 Linode/Akamai Cloud
83 139.144.0.0/16 Linode/Akamai Cloud
84 170.187.128.0/17 Linode/Akamai Cloud
85 194.195.208.0/20 Linode/Akamai Cloud
86 216.128.128.0/17 Choopa/Vultr Colocation
87 66.42.32.0/20 Choopa/Vultr Colocation
88 23.227.32.0/19 Shopify Cloud
89 184.104.192.0/19 GoDaddy Hosting
90 50.62.0.0/15 GoDaddy Hosting
91 198.71.128.0/17 GoDaddy Hosting
92 68.65.112.0/20 Namecheap Hosting
93 162.0.208.0/20 Namecheap Hosting
94 198.54.112.0/20 Namecheap Hosting
95 104.131.0.0/16 DigitalOcean Cloud
96 107.170.0.0/16 DigitalOcean Cloud
97 162.243.0.0/16 DigitalOcean Cloud
98 174.138.0.0/16 DigitalOcean Cloud
99 37.59.0.0/16 OVH Hosting
100 91.121.0.0/16 OVH Hosting

Why datacenter IP detection is essential for bot protection

The vast majority of automated bot traffic originates from cloud servers and datacenters. Scrapers, credential stuffing tools, inventory hoarding bots, and fake account generators almost always run on cloud infrastructure because it's cheap, scalable, and disposable. By identifying connections from datacenter IP ranges, you can filter out a significant portion of non-human traffic without affecting real users.

Our datacenter database covers all major cloud providers - Amazon Web Services, Google Cloud Platform, Microsoft Azure, DigitalOcean, Hetzner, Vultr, OVH, Scaleway, Linode, and dozens more - as well as traditional hosting and colocation providers. Each entry is classified by type (cloud, hosting, colocation), which allows you to make informed decisions. For instance, you might allow traffic from known CDN ranges (Cloudflare, Fastly) while blocking or challenging requests from general-purpose cloud servers.

This database is particularly valuable for e-commerce sites combating inventory hoarding, ticket platforms fighting scalper bots, and any application that needs to distinguish between real browser sessions and headless automation. Combined with the VPN/proxy database, it provides comprehensive coverage of non-residential IP sources.

Ready for the full databases?

The samples above are just a fraction of what's included. Get every database - 1,000+ VPN providers, 148,484 disposable domains, 471 ISP profiles, and more - for €99/year.

Monthly updates · Unlimited servers · No per-query fees · Your data stays on your infrastructure

What is threat intelligence data?

Threat intelligence data is structured information about known threats to digital systems. In the context of web security, it includes lists of IP addresses associated with VPNs, proxies, Tor nodes, and datacenters, as well as domains used by disposable email services and reputation scores for internet service providers. Businesses use this data to identify and block malicious or fraudulent traffic before it can cause harm.

Traditional threat intelligence is delivered as API services that charge per query and require sending user data to third-party servers. AntiProxies takes a different approach: we deliver curated, production-ready databases as downloadable files in standard formats (CSV and JSON). This means lookups happen locally on your own infrastructure - no API latency, no per-query costs, and no user data leaving your servers.

Common use cases for threat intelligence

Threat intelligence databases are used across virtually every industry that operates online. Here are the most common applications:

  • E-commerce fraud prevention: Block orders from VPNs, proxies, and datacenter IPs that are frequently associated with payment fraud, coupon abuse, and fake reviews.
  • Account security: Flag login attempts from Tor exit nodes or high-risk ISPs and trigger additional authentication steps like 2FA challenges.
  • Registration quality: Reject signups using disposable email addresses to prevent fake accounts, trial abuse, and spam.
  • Bot mitigation: Identify and block automated traffic from datacenter IPs that power scrapers, credential stuffing tools, and inventory hoarding bots.
  • Content licensing: Enforce geographic restrictions by detecting VPN and proxy connections that attempt to bypass region locks.
  • Ad fraud detection: Filter out non-human clicks and impressions originating from datacenter IPs and known proxy services.
  • Gaming anti-cheat: Detect players using VPNs to evade bans, exploit regional pricing, or gain unfair latency advantages.

Self-hosted vs. API-based threat intelligence

The two primary delivery models for threat intelligence are API services and downloadable databases. API services are convenient but come with significant trade-offs: they add latency to every request, charge per query (which can become expensive at scale), and require sending user IP addresses and email addresses to a third-party server - raising GDPR and privacy concerns.

Self-hosted databases eliminate all three issues. The data lives on your infrastructure, lookups are instant (a local hash table or CIDR trie), and costs are fixed regardless of traffic volume. For businesses processing millions of requests per month, the cost difference alone is substantial - a single €99/year license replaces API bills that can run into thousands of euros per month.

The trade-off is update frequency: API services can update in near real-time, while downloadable databases are updated on a monthly cycle. For most threat categories - VPN provider ranges, disposable email domains, ISP reputation, and datacenter allocations - this cadence is more than sufficient because the underlying data changes relatively slowly. Tor exit nodes are the most volatile category, which is why our Tor database receives more frequent updates.

Frequently asked questions

Are the free samples real production data?

Yes. Every entry on this page is drawn from the same databases our paying customers use. We publish 100 records per category so you can verify accuracy, format, and coverage before purchasing.

How often is the sample data updated?

The samples are refreshed alongside our monthly database releases. The full databases contain significantly more entries and are updated on the same schedule.

Can I use the free samples in production?

You can use these samples for testing and evaluation. For production use, purchase a license to get the complete databases with all entries and regular updates.

What formats are the full databases available in?

All databases are delivered in standard CSV and JSON formats. They integrate with any tech stack - no proprietary SDK or API dependency required.

How many entries are in the full databases?

The full package includes 1,000+ VPN providers with tens of thousands of IP ranges, 148,484 disposable email domains, continuously updated Tor exit nodes, 471 ISP profiles, and comprehensive datacenter IP ranges from all major cloud and hosting providers.

AntiProxies provides privacy-first threat intelligence databases for businesses of all sizes. Our databases cover VPN and proxy IP detection (1,000+ providers), disposable email domain filtering (148,484 domains), Tor exit node identification, ISP reputation scoring (471 profiles), and datacenter IP range mapping. All data is delivered in CSV and JSON formats with monthly updates. For €99/year, you get a single license covering unlimited servers with no per-query fees - your users' data never leaves your infrastructure. View pricing or contact us to get started.