client9 / ipcat

Categorization of IP Addresses
MIT License
529 stars 132 forks source link

My site is blacklisted #147

Open otkaudes opened 5 years ago

otkaudes commented 5 years ago

I'm not sure where to put such a request but I notice your service has blacklisted my site (mycockerspaniel.com, 67.225.160.120). My site has very little traffic and my email is handled by mandrillapp. My site sent out a total of 47 email last week and that's about the norm. Mandrill lists my mailserver as excellent with zero complaints in the past 3 months.

Could you please tell me why this happenend so I can inform mandrillapp?

shawnps commented 5 years ago

Hi @otkaudes

The purpose of this list is to label IP addresses that are known to be computer servers. Since your website runs on a server (apparently on Liquid Web), it makes sense that your website's IP is on the list.

Did someone at Mandrillapp say that your email was blocked because your website's IP is in this list?

otkaudes commented 5 years ago

No Apility.io is telling me this:

67.225.160.120 WAS FOUND IN 1 BLACK LIST (S) IPCATV4-DC - Datacenter IPv4 space

Info on this blacklist points here on github but thanks for the information.

otkaudes commented 5 years ago

Your service is listed like so:

Nick Galbreath's IP categorization list. This is a list of IPv4 address that correspond to datacenters, co-location centers, shared and virtual webhosting providers. In other words, ip addresses that end web consumers should not be using.

A connection made from any of these IP addresses can happen not very often and it could mean that the connection is not made by a human but a computer hosted in a datacenter. Hence, it could point to a potential abuser.

shawnps commented 5 years ago

@otkaudes there's also a blog post here that explains that the IPs in this list are not necessarily harmful:

https://apility.io/2018/10/31/ip-blacklist-ipcatv4-datacenter-ip-space/

This month we have a new list that should not be considered harmful, but can help cybersecurity analysts and SecOps to find out if an IP can be malicious.