Intelligence & OSINT · free, no signup
Threat Intel Indicator / IP Lookup
Look up a single indicator against sources that need no API key: public DNS blocklists, RDAP registration data, reverse DNS with forward confirmation, the published Tor exit list, and a public malware hash registry. Its discipline is the distinction most tools lose — a blocklist that REFUSED the query is reported as unanswered, never as a clean result, because those look identical once summarised and only one of them means anything. Listings are read by return code, so end-user address space is reported as a statement about the address's role rather than an accusation. Nothing connects to the indicator, nothing is attributed to an actor or country, and the commercial feeds this tool deliberately does not depend on are named as missing coverage.
Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.
Look up one IP address, domain or file hash against sources that need no API key — public DNS blocklists, registration records, reverse DNS, the Tor exit list and a public malware hash registry.
When a source refuses the query, this says so instead of reporting the indicator clean — those are different answers, and only one of them means anything. Nothing here connects to the indicator, and nothing is attributed to an actor or country.
What happens to what you enter
- The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
- Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
- An email address is stored only where a tool offers to send you a report and you choose to give one.
Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.
When a free check is not enough
This tool reads what is public and reports what it can see. The Threat Intelligence & Exposure Monitoring engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.
Explore Threat Intelligence & Exposure Monitoring