webfilteringdatabase.com
Home Find Your Solution
Features
Domain Categorization API Real-Time Classification 59 Filtering Categories Offline Database (100M) ML Classification Content Classification
Industries
K-12 Schools Corporate Healthcare Government ISPs
Tools
Domain Lookup Bulk Categorization Category Explorer
Resources
Pricing API Documentation Login / Sign Up
Security Category

Spam Domain Filtering

Block the domains behind unsolicited email and web spam at the source. Over 6.8 million spam and spamvertised domains classified with multi-signal detection for email security gateways, DNS filtering, and web protection platforms.

How Spam Domains Are Detected

Spam is an infrastructure problem as much as a content problem. Behind every spam campaign is a set of domains: the sending domains that originate messages, the link domains that spam messages advertise ("spamvertised" domains), and the redirect and tracking domains that sit between them. Blocking this infrastructure stops spam whether it arrives by email, SMS, comment forms, or social media. Our spam category maps more than 6.8 million such domains.

Detection draws on spam-trap networks, honeypot inboxes, and large-scale message telemetry. Domains that appear predominantly in unsolicited bulk messages, that are advertised in spam bodies, or that host the landing pages spam links point to are scored against volume, recency, and reputation. Newly registered domains used exclusively in bulk mailings are flagged rapidly, before they accumulate a long abuse history.

Spammers rotate domains aggressively and use URL shorteners, open redirects, and snowshoe techniques to spread activity thinly across many hosts. Our pipeline follows redirect chains to the true destination, clusters snowshoe domains by shared registration and hosting fingerprints, and correlates sending and landing infrastructure so that an entire campaign can be blocked from a handful of observed messages.

The Spam Ecosystem

Spam is often dismissed as a nuisance, but the infrastructure behind it is a serious and well-organised industry. Behind a single campaign sit sending domains, redirect and tracking hops, and the landing pages that spam ultimately drives traffic to. These 'spamvertised' destinations are where the money is made — through scams, counterfeit goods, malware, or affiliate fraud — and they are the part of the ecosystem that persists long after any individual message is deleted.

Spammers survive by moving fast and spreading thin. Snowshoe techniques distribute volume across hundreds of low-reputation domains so that no single one crosses a blocking threshold. URL shorteners and open redirects hide the true destination behind a trusted-looking link. Domains are registered in bulk, used for a day, and abandoned. Any defence that reacts only to accumulated reputation is always a step behind, blocking yesterday's domains while today's are already in inboxes.

Blocking at the infrastructure layer changes the economics. By following redirect chains to their true destination, clustering snowshoe domains by shared registration and hosting fingerprints, and correlating sending domains with the landing pages they promote, an entire campaign can be identified and blocked from a handful of observed messages. Because the landing infrastructure is more expensive for spammers to rotate than the sending domains, targeting it inflicts more lasting damage on the operation.

For defenders, spam-domain intelligence pays off well beyond the inbox. The same domains that appear in unsolicited email show up in SMS spam, social-media spam, comment-form abuse, and fraudulent account sign-ups. A single, continuously updated view of spam infrastructure lets an organisation defend all of these surfaces at once — email gateway, web filter, and application form validation — from one source of truth.

Detection Methodology

Message telemetry and infrastructure signals combine to identify spam sources and spamvertised domains

Spam-Trap Networks

Dedicated spam-trap addresses receive only unsolicited mail. Any domain that sends to or is advertised within trap-caught messages is a high-confidence spam indicator, providing ground-truth evidence untainted by legitimate correspondence.

Redirect-Chain Following

Spam links frequently pass through URL shorteners and open redirects to disguise their destination. Our crawler follows the full chain to the final landing page and classifies the true destination, not just the intermediary, defeating a common evasion technique.

Snowshoe Clustering

Snowshoe spam spreads volume across many low-reputation domains to stay under per-domain thresholds. Clustering by shared name servers, registration timing, hosting ranges, and template reuse identifies the whole spread from a few observed members.

Volume & Recency Scoring

A domain seen only in bulk unsolicited traffic, especially one registered days earlier, scores far higher than an established domain with mixed legitimate use. Weighting volume against recency and reputation separates genuine spam infrastructure from ordinary mail.

Template & Payload Matching

Spam campaigns reuse landing-page templates, tracking pixels, and affiliate identifiers. Matching these artefacts links domains operated by the same spammer even when hosting and naming differ, extending coverage across the operation.

Continuous Re-scoring

Reputation is dynamic: a compromised legitimate domain may send spam temporarily, and a burned spam domain may be abandoned. Continuous re-scoring adds and removes classifications as behaviour changes, keeping the feed aligned with live activity.

Policy & Use Cases

Spam-domain filtering strengthens email gateways, protects web users, and reduces abuse-driven risk

Email Security Gateways

Secure email gateways combine our spam-domain feed with content analysis to block messages whose sending or link domains are known spam sources. Infrastructure-level signals catch campaigns that evade content filters through obfuscation.

  • High-confidence sender and link-domain reputation
  • Complements content-based spam scoring
  • Catches obfuscated and image-only spam by URL
  • Reduces false negatives on novel campaigns
  • Machine-readable feeds for gateway integration

Web & DNS Filtering

Web-filtering and protective-DNS platforms block spamvertised landing pages so that users who click a spam link — in email, SMS, or social media — never reach the destination. This closes the loop between message delivery and payload.

  • Blocks spamvertised landing pages at click time
  • Protects against SMS and social-media spam links
  • DNS-layer coverage for all devices
  • Follows redirects to the true destination
  • Reduces exposure to scam and phishing follow-ons

Form & Comment Protection

Web applications use the feed to reject spam submitted through contact forms, comment sections, and sign-up flows. Blocking known spam domains in submitted links and email addresses cuts comment spam and fake registrations.

  • Rejects spam links in user-generated content
  • Blocks disposable and spam-source email domains
  • Reduces moderation workload
  • API lookups integrate into form validation
  • Protects community platforms from abuse

Brand & Abuse Protection

Security and anti-abuse teams monitor for spam campaigns that impersonate their brand or abuse their platform. The feed helps identify malicious infrastructure quickly so that takedowns and blocks can be coordinated.

  • Surfaces brand-impersonating spam infrastructure
  • Supports takedown and abuse-response workflows
  • Correlates campaigns across many domains
  • Historical data for investigation
  • Feeds SOC and anti-abuse tooling

Spam Category Statistics

Coverage and accuracy metrics for spam sources and spamvertised domains

6.8M+
Spam Domains Tracked
99.1%
Classification Accuracy
<0.2%
False Positive Rate
10 min
Feed Refresh Interval

Protecting Legitimate Senders

Aggressive spam blocking risks catching legitimate bulk senders — newsletters, transactional mail providers, and marketing platforms that operate with consent. Misclassifying these as spam damages deliverability for legitimate businesses. Our scoring separates genuine spam infrastructure from high-volume legitimate mail by weighting consent signals, authentication posture, and complaint ratios.

Domains publishing valid SPF, DKIM, and DMARC records, maintaining low complaint rates, and appearing in solicited as well as bulk traffic are protected from over-blocking. Shared marketing platforms are evaluated at a granularity that isolates abusive tenants without blacklisting the whole provider.

Every classification carries confidence and supporting evidence, so gateway operators can quarantine rather than reject on borderline scores, and can tune thresholds to balance spam suppression against the risk of blocking wanted mail.

Integration Guide for Spam Filtering

Deploy spam-domain blocking across email, DNS, and application layers

Deployment Options

Email gateways consume the feed as sender- and link-domain reputation, combining it with content scoring to catch campaigns that evade text analysis. High-confidence infrastructure signals reduce both false negatives on novel spam and false positives on legitimate mail.

Protective DNS and web filtering block spamvertised landing pages so that clicked links fail to resolve, protecting users across email, messaging, and social channels. Web applications call the API during form and sign-up validation to reject spam links and disposable email domains.

The real-time API returns classification, spam subtype, and confidence in a single call, while bulk and streaming feeds support gateway synchronisation and enrichment of existing reputation systems.

  • DNS RPZ and domain feeds refreshed every 10 minutes
  • Sender and link-domain reputation for email gateways
  • REST API with sub-10ms response times
  • SDKs for Python, Node.js, Go, Java, and C#

Domain Classification API

// Check spam classification
curl -X GET "https://api.webfilteringdb.com/v1/lookup" \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -d '{"domain": "example-domain.com"}'

// Response
{
  "domain": "example-domain.com",
  "categories": ["spam"],
  "subcategory": "spamvertised",
  "confidence": 0.98,
  "action": "block"
}

Postfix / SpamAssassin Config

# SpamAssassin URIDNSBL against the spam feed
urirhssub  WFDB_SPAM  spam.rhsbl.webfilteringdb.com.  A  127.0.0.2
body       WFDB_SPAM  eval:check_uridnsbl('WFDB_SPAM')
score      WFDB_SPAM  4.0

# Postfix RHSBL for sender domains
smtpd_sender_restrictions =
    reject_rhsbl_sender spam.rhsbl.webfilteringdb.com

Frequently Asked Questions

Common questions about deployment, coverage, and policy

What is a spamvertised domain?

A spamvertised domain is a website advertised in spam messages — the destination a spam link points to, as opposed to the domain that sent the message. These landing pages host the scam, counterfeit shop, malware, or affiliate offer that the campaign is designed to drive traffic to, and blocking them protects users who click a spam link on any channel.

How does this complement my existing spam filter?

Most spam filters score message content. The spam-domain category adds infrastructure reputation for the sending and link domains, which catches campaigns that evade content analysis through obfuscation, image-only messages, or minimal text. Used together, infrastructure and content scoring reduce both false negatives and false positives.

Won't this block legitimate bulk senders?

Our scoring protects legitimate high-volume senders by weighting authentication posture (SPF, DKIM, DMARC), complaint ratios, and the presence of solicited traffic. Shared marketing platforms are evaluated at a granularity that isolates abusive tenants rather than blacklisting the whole provider, keeping the false-positive rate low.

Can it stop spam in web forms and sign-ups?

Yes. By calling the API during form or registration validation, applications can reject submissions that contain known spam links or disposable email domains. This cuts comment spam and fraudulent account creation at the point of entry, reducing downstream moderation and abuse-handling work.

How does redirect-following improve coverage?

Spam links frequently pass through URL shorteners and open redirects to hide their destination. Our crawler follows the full chain and classifies the true landing page, so a shortened or redirected link resolves to the correct spam classification rather than being judged on the harmless-looking intermediary.

What delivery formats are available?

The category is available as DNS RPZ and RHSBL feeds for email gateways, sender- and link-domain reputation data, a real-time REST API with sub-10ms responses, and bulk feeds, with SDKs for Python, Node.js, Go, Java, and C#.

Related Categories

Combine spam filtering with related threat categories for layered protection

Block Spam at the Infrastructure Layer

Stop spam by blocking the domains behind it, in email and on the web. 6.8 million spam and spamvertised domains classified and refreshed every ten minutes.