FAQ
What is the purpose of this tool?
The purpose of this tool is to lookup information about entries in my personal blocklist,
The malicious website blocklist. This tool makes it easier for me to remove dead domains, investigate false positives, and check if a domain is already listed. It also makes it easier for users of my list to file issue reports.
What does last checked mean?
Every domain in my list has a counter which is incremented whenever the list is updated (and also every Friday). Once that counter hits a certain number, a series of automated checks will be run to determine if the domain is still alive. This counter can be seen in on "Check counter" line below. This checking is currently disabled.
Why is no data listed for the "open ports"?
A while ago, I added a feature to run a port scan on newly added domains. However, this caused many problems, and the feature was quickly removed. Few, if any, domains actually have port scan data. If you look at the code of the page, there is an area where that data would be displayed if the entry had that data. This feature was replaced by checking if a simple HTTP web server is running, and that feature is now disabled.
Where does domain ownership data come from?
Domain ownership data comes from a manually maintained
file part of my Site Reports project. The data in that repository was originally for a defunct browser extension known as
Check Site which would show reports, including ownership, for websites. Most of the other data in the Site Reports repository is unmaintained and of questionable quality.
Site ownership data is only available for a very limited number of websites, due to the data being manually vetted and added by me. There is no standard vetting process; often domains are added because they are used on or referenced by official websites of their purported owner. Due to this, the quality varies. Known malicious and scam websites will not be added, even if there are multiple owned by the same company or organization. However, addition to the dataset is not an endorsement.
What does "allowlisted" mean?
The Malicious Website Blocklist has
an allowlist of known legitimate domains. This is used in automated checks to identify false positives. If a domain is included in this allowlist, it will be listed as "allowlisted" here, even if it is in the Malicious Website Blocklist.
What does the comments section mean?
The links and comments displayed in the comments section are in-line comments left in the filterlist itself. These are comments left in the filterlist file by the maintainer (me) or a contributor to describe why a filter was added. Not all filters have a comment directly above them, such as if there are multiple filters in one area. In that case, the tool will display a filter as having no comments.
If a comment is detected to likely be a URL, it will be turned into a link. These links may not be safe to visit; user discretion is advised.
New entries do not list comments.
Why is the linked commit incorrect?
There have been several times where the script used to track entries in the MWB has broken, resulting in entries not being added to the database when they are first added. Instead, they will be added to the database whenever I fix the script or whatever other error was occuring. When adding a new entry to the database, the script looks for the last commit and associates it with the new entry. Normally, this is fine since the script runs whenever there is a new commit. However, if it doesn't run after a commit - such as due to an error - it will instead store the most recent commit when the script ran, which isn't the commit which added the entry.
TLDR; the commit shown was the last commit before the script ran, and sometimes the script doesn't run right after the commit which added an entry.
Results
The malicious website blocklist:
First added:
Removed:
Last checked:
Check status: ()
Check counter:
Dead since: Unknown
Alive when added: Unknown
Alive when removed: Unknown
Had www subdomain when added: Unknown
Had www subdomain when checked: Unknown
Added in commit:
IP Addresses:
Open ports
Has HTTP on default port (80): Unknown
Domain owner:
Allowlisted:
HaGeZi's Light DNS Blocklist (does not include the MWB):
HaGeZi's Threat Intelligence Feeds DNS Blocklist (includes the MWB):
Dandelion Sprout's antimalware (does not include the MWB):
In PUP list:
In "uBlock" Combo list:
In Lite MWB:
Comments: