Intermediate12 min
Integrating a Blocklist
IPAbuse publishes live blocklists filtered by abuse category and risk level. This tutorial shows how to download the list and apply it to Nginx or a Node.js application.
1
Download the blocklist
The blocklist endpoint returns IP addresses as plain text (one per line) or JSON. Filter by category and riskLevel to keep it focused.
cURL
# Plain text — one IP per line, suitable for firewall rules
curl "https://api.ipabuse.org/v1/ip/blocklist?category=SPAM&riskLevel=HIGH&format=txt" \
-H "X-API-Key: YOUR_API_KEY" -o blocklist.txt2
Apply to Nginx with geo module
Convert the plain-text list to an Nginx geo block and reload the config.
apply-nginx.sh
# Convert to Nginx geo format
awk '{print $1 " 1;"}' blocklist.txt > /etc/nginx/conf.d/ipabuse_blocked.conf
# Reload Nginx
nginx -s reload3
Apply in Node.js middleware
For Express applications, load the list at startup and check each request.
middleware.js
import { readFileSync } from "fs";
const blocked = new Set(
readFileSync("blocklist.txt", "utf8")
.split("\n")
.map((l) => l.trim())
.filter(Boolean)
);
app.use((req, res, next) => {
const ip = req.ip ?? req.socket.remoteAddress ?? "";
if (blocked.has(ip)) {
return res.status(403).json({ error: "Forbidden" });
}
next();
});4
Automate with a cron job
Refresh the blocklist every hour to stay up to date.
cron
# /etc/cron.d/ipabuse-blocklist
0 * * * * root curl -s "https://api.ipabuse.org/v1/ip/blocklist?format=txt" \
-H "X-API-Key: YOUR_API_KEY" -o /etc/nginx/conf.d/ipabuse_blocked.conf \
&& nginx -s reload