This is the raw threat-intel SevinShield scans every URL against — URLhaus, OpenPhish, PhishTank, MetaMask, ScamSniffer, StevenBlack and more. It is the scanning source, not the confirmed blocklist. Aggregate counts are public — full host list is admin-only.
Two different things, deliberately: Intel database = 254,810 reference hosts we use to check what scanned pages load. Confirmed blocklist = 4 hosts our real-browser scans confirmed were actually bad, with a screenshot for each. Subscribe to the confirmed list at /blocklist.php.
Every time you submit a URL to SevinShield, the scanner records every host the page touched — every script, every iframe, every tracking pixel — and looks each one up in this intel database. A match becomes a finding:
known_malicious, high severity → verdict maliciousknown_malicious phishing → verdict maliciousad_tracker_listed low severity → verdict stays clean (these are trackers, not malware)High-or-critical matches auto-populate the public blocklist so other tenants benefit. Without this DB, every scan would say "clean" — the intel is what gives SevinShield its verdict.
The full URL/host data is gated to prevent abuse. Use your tenant API key to subscribe to /api/v1/blocklist — that returns hosts our scans confirmed bad, refreshed every minute, ready for your firewall / DNS sink / SIEM.