Most Popular

Professional Plan

$149 / month or $119/mo annual

Full threat intelligence, domain reverse lookups, abuse detection, and priority support — the complete toolkit.

2M requests/month Priority support Domain intelligence

2M

requests / month

32+

data fields

99.9%

uptime SLA

Everything in Starter, plus

Threat Intelligence

Multi-source threat scoring from public blocklists, honeypot data, and abuse reports.

  • Abuse score (0–100)
  • Blocklist presence
  • Tor exit node detection
  • Threat category tags

Domain Intelligence

Look up any domain — WHOIS, registrar, creation date, DNS records, and hosted IP.

  • Full WHOIS data
  • Registrar & creation date
  • DNS records (A, MX, NS)
  • Hosted IP lookup

Reverse IP Lookup

Find all domains hosted on an IP address — useful for shared hosting analysis and fraud detection.

  • Hosted domain count
  • Top domains on IP
  • Shared hosting flag
Sample Response

32+ fields including threat data

The Professional response extends the Starter payload with a full threat object and domain intelligence endpoints.

threat.abuse_score

0–100 risk score aggregated from 15+ sources

threat.is_tor

Real-time Tor exit node check

threat.blocklists

Array of matching blocklist names

{
  "ip":        "185.220.101.5",
  "country":   "Germany",
  "city":      "Frankfurt",
  "asn":       "AS51813",
  "org":       "Packethub S.A.",
  "is_vpn":    true,
  "is_tor":    true,
  "threat": {
    "abuse_score":  94,
    "is_tor":       true,
    "is_attacker":  true,
    "is_spammer":   false,
    "blocklists": [
      "spamhaus-drop",
      "firehol-level1"
    ]
  },
  "reverse_domains": 0
}

Rate limits & quotas

LimitValue
Monthly requests2,000,000
Requests per second500
Batch endpoint (up to 100 IPs)Not included
SLA uptime99.9%
SupportPriority email (8h)
Domain lookupsIncluded
Threat intelligenceIncluded

Common questions

The abuse score (0–100) is a weighted aggregate from over 15 sources including Spamhaus DROP, Firehol, Project Honeypot, UCEPROTECT, and internal honeypot signals. A score above 70 indicates high risk; above 90 is near-certain malicious activity.
We return the total count of hosted domains plus a sample of up to 10 domain names. For full enumeration of large shared-hosting IP ranges, the Business plan provides paginated results.
Domain WHOIS data is refreshed every 24 hours and served from cache. For newly registered domains, live WHOIS is queried directly and may take a few hundred milliseconds longer.
Yes, instantly. Your API key remains the same and new fields appear in the response within seconds of upgrading.

The complete IP intelligence toolkit

Join thousands of developers using Professional for fraud prevention, geo-targeting, and threat detection.