IPAbuse Developers
Intermediate12 min

Integrating a Blocklist

IPAbuse publishes live blocklists filtered by abuse category and risk level. This tutorial shows how to download the list and apply it to Nginx or a Node.js application.

1

Download the blocklist

The blocklist endpoint returns IP addresses as plain text (one per line) or JSON. Filter by category and riskLevel to keep it focused.

cURL
# Plain text — one IP per line, suitable for firewall rules
curl "https://api.ipabuse.org/v1/ip/blocklist?category=SPAM&riskLevel=HIGH&format=txt" \
  -H "X-API-Key: YOUR_API_KEY" -o blocklist.txt
2

Apply to Nginx with geo module

Convert the plain-text list to an Nginx geo block and reload the config.

apply-nginx.sh
# Convert to Nginx geo format
awk '{print $1 " 1;"}' blocklist.txt > /etc/nginx/conf.d/ipabuse_blocked.conf

# Reload Nginx
nginx -s reload
3

Apply in Node.js middleware

For Express applications, load the list at startup and check each request.

middleware.js
import { readFileSync } from "fs";

const blocked = new Set(
  readFileSync("blocklist.txt", "utf8")
    .split("\n")
    .map((l) => l.trim())
    .filter(Boolean)
);

app.use((req, res, next) => {
  const ip = req.ip ?? req.socket.remoteAddress ?? "";
  if (blocked.has(ip)) {
    return res.status(403).json({ error: "Forbidden" });
  }
  next();
});
4

Automate with a cron job

Refresh the blocklist every hour to stay up to date.

cron
# /etc/cron.d/ipabuse-blocklist
0 * * * * root curl -s "https://api.ipabuse.org/v1/ip/blocklist?format=txt" \
  -H "X-API-Key: YOUR_API_KEY" -o /etc/nginx/conf.d/ipabuse_blocked.conf \
  && nginx -s reload