URLAbuse
URLAbuse is a Grenoble-based cybersecurity company operating a community-driven URL and domain blocklist that delivers evidence-backed threat intelligence on phishing, malware, and DNS abuse to registrars, registries, hosting providers, CERTs, and large enterprises globally.
- Company typePrivate
- Founded2023
- HeadquartersGrenoble, France
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What URLAbuse does
URLAbuse is a private cybersecurity company headquartered in Grenoble, France, that operates a community-driven URL and domain blocklist platform focused on DNS abuse. Its mission is to identify, document, and forward malicious domains and URLs involved in phishing, malware distribution, fake online shops, scams, and illegal gambling to the entities best positioned to act, namely domain registries, registrars, hosting providers, and national CERTs. The platform combines community reporting, automated scanners, and honeypots with a two-component phishing detection engine (brand-agnostic plus brand-specific, covering 260+ brands) to produce what the company describes as actionable threat intelligence, where each record carries screenshots, metadata, target information, and context rather than raw blocklist data.
The product surface spans the URLAbuse Blocklist Feed, a DNS-based blocklist (dbl.urlabuse.com) returning 127.0.0.2 for blacklisted domains and NXDOMAIN for clean ones, multiple APIs (a Report URL API for trusted reporters, a Get Trusted Report API, an internal admin CTI API, and a public DBL HTTP lookup endpoint requiring no authentication), an Email Notification Service delivering over 1,500 notifications per day to registries, registrars, and hosting providers, a Management Panel for registered users, an "Is It Blocked?" domain checker, and a Chrome Extension launched in January 2026. Infrastructure is hosted across dozens of servers globally and is underwritten by a sponsorship from KOR Labs.
URLAbuse runs a freemium commercial model: the public blocklist and DNSBL are free, while a commercial threat intelligence feed, authenticated APIs, and deeper investigations form the paid side. Customer and partner signals include major registrars (GoDaddy, Namecheap, Realtime Register, Radix), DNS/security operators (Quad9, SURBL), government CERTs (CERT-EE, GovCERT-CH), and large enterprises (Orange, Thales). The company is led by founder Sourena Maroofi, operates with 1-10 employees, and has not disclosed institutional funding rounds; growth has been financed through commercial operations and its KOR Labs infrastructure sponsorship.
URLAbuse firmographics
Firmographics- Name
- URLAbuse
- Legal name
- URLAbuse
- Website
- https://urlabuse.com
- Company type
- Private
- Founded year
- 2023
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- URLAbuse is a Grenoble-based cybersecurity company operating a community-driven URL and domain blocklist that delivers evidence-backed threat intelligence on phishing, malware, and DNS abuse to registrars, registries, hosting providers, CERTs, and large enterprises globally.
- Ownership category
- akta.pro rank
URLAbuse industry classification
Industry- Product category
- Threat Intelligence Platform
- NAICS
- Web Search Portals, Libraries, Archives, and Other Information Services (5192)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Spam, Fake Engagement & Content Abuse Prevention (HDADALAG)
- akta.pro secondary industries
- Email Phishing & BEC Protection (HDADAKAB), Email & Collaboration Threat Detection/Response (ICR/CTDR) (HDADAKAI)
Keywords
Where URLAbuse is headquartered
LocationHeadquarters
- HQ city
- Grenoble
- HQ country
- France
- HQ region
- Europe
Offices1 record
Markets served
URLAbuse business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Infrastructure, Operations
Revenue model
- Commercial Threat Intelligence Feed: The company runs its own scanners, conducts investigations, and tracks malicious campaigns. The data generated from these commercial operations is made available on a paid basis to sustain and grow the URLAbuse initiative. Organizations can subscribe to commercial feed access.
- API Access for Trusted Reporters: API tokens provided to trusted third-parties who want to report URLs to URLAbuse. The company likely offers tiered API access with different rate limits or capabilities.
- Free Public Data: Public blocklist accessible for free via DNSBL and HTTP API. This drives awareness and community contribution while the commercial feed monetizes professional users.
Go-to-market motion3 records
Distribution channels4 records
Marketing channels5 records
URLAbuse product offering
Product offeringCore offering
URLAbuse operates a community-driven URL and DNS threat intelligence platform that collects, verifies, and distributes data on malicious domains involved in phishing, malware distribution, scams, and other DNS abuse. The platform delivers its intelligence through a public blocklist feed, a DNS-based blocklist (DBL) nameserver, public and authenticated APIs, and a daily email notification service that forwards actionable abuse cases (with screenshots, defanged URLs, and target details) to domain registries, registrars, and hosting providers. A commercial threat intelligence feed monetizes deeper access for organizations needing professional-grade data.
Product overview
URLAbuse is a cybersecurity platform providing community-driven URL threat intelligence through multiple delivery mechanisms. The core offering is the URLAbuse Blocklist Feed — a community-contributed database of malicious domains and URLs — paired with the URLAbuse DBL (DNS Blocklist) for DNS-layer integration. The platform distributes its intelligence via public APIs (Report URL API, Get Trusted Report API, DBL HTTP API), an admin-only Internal Report API, and a web-based domain checking tool (Is It Blocked?). Email Notification Service delivers daily alerts to registries and hosting providers, while the URLAbuse Chrome Extension extends protection to browsers. Users access the system through Registration/Login and Management Panel interfaces. The service operates on a dual model: free public data and community contributions, with commercial access available for advanced intelligence.
Differentiator
Problem solved
Functional benefit
Brands
- URLAbuse DBL: DNS Blocklist nameserver service for blocking malicious domains at the DNS layer
Products and services
- URLAbuse Blocklist Feed
- URLAbuse DBL (DNS Blocklist)
- Report URL API
- Get Trusted Report API
- DBL HTTP API
- Email Notification Service
- URLAbuse Chrome Extension
Companies that use URLAbuse
Customer profileNamed customers10 records
Segments5 records
Ideal customer profiles3 records
URLAbuse technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Feature4 records
URLAbuse partnerships and signals
Strategic signalScale indicators3 records
Recent moves6 records
Expansion highlights5 records
URLAbuse competitors and assessment
Company assessmentDirect peers
- SURBL: SURBL operates a free DNSRBL that identifies spam-sending domains and is an existing URLAbuse customer/partner. It is a direct peer in the DNSBL and URL reputation space, with overlapping use cases in spam filtering and domain reputation scoring.
- OpenPhish: OpenPhish provides automated, real-time phishing intelligence feeds covering phishing URLs and targeted brands. It is comparable to URLAbuse's phishing detection engine and commercial threat-feed model.
- urlscan.io: urlscan.io is a URL scanning and analysis service that captures screenshots and contextual data for submitted URLs. It is comparable to URLAbuse's evidence-rich approach (screenshots, metadata) and serves security researchers and SOC analysts.
- VirusTotal: VirusTotal aggregates multiple URL/domain scanning engines and reputation sources into a single intelligence platform. It is comparable to URLAbuse's API-driven threat-intel platform, though at much broader scale and with broader indicator types.
- PhishTank: PhishTank is a community-driven anti-phishing database where users submit and verify phishing URLs. It overlaps directly with URLAbuse's community-driven URL reporting model and phishing detection focus.
- Spamhaus: Spamhaus is the dominant DNSBL operator and anti-spam/abuse data provider. It is the most direct comparable to URLAbuse's blocklist and DNSBL products, serving similar registrars, mail operators, and security teams with reputation data on malicious domains and IPs.
- DomainTools: DomainTools provides domain and DNS intelligence, including reputation scoring, WHOIS history, and threat data on malicious domains. It overlaps with URLAbuse's DNS-abuse focus and similar buyer profiles in security and fraud teams.
Emerging players
- Phishfort: Phishfort is a niche anti-phishing vendor focused on brand protection, takedown services, and phishing detection. It is comparable to URLAbuse as a focused, brand-targeted phishing intelligence player with overlap in target brands and takedown workflow.
- SlashNext: SlashNext specializes in phishing and social-engineering threat detection across email, browsers, and messaging. It overlaps with URLAbuse's phishing and brand-protection focus and is sold into similar enterprise security operations.
Broad incumbents
- Cisco Talos: Cisco Talos is one of the largest commercial threat intelligence operations, providing broad coverage of IPs, domains, and URLs across spam, phishing, and malware. It competes with URLAbuse for enterprise threat-intel budgets and serves many of the same buyer types.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
URLAbuse social profiles
Digital presenceURLAbuse financial estimates
Financial estimateRevenue estimate
Valuation estimate
URLAbuse leadership team
Management profileNumber of profiles
Profiles1 record
URLAbuse funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
URLAbuse M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about URLAbuse
What does URLAbuse do?
URLAbuse operates a community-driven URL and DNS threat intelligence platform that collects, verifies, and distributes data on malicious domains involved in phishing, malware distribution, scams, and other DNS abuse. The platform delivers its intelligence through a public blocklist feed, a DNS-based blocklist (DBL) nameserver, public and authenticated APIs, and a daily email notification service that forwards actionable abuse cases (with screenshots, defanged URLs, and target details) to domain registries, registrars, and hosting providers. A commercial threat intelligence feed monetizes deeper access for organizations needing professional-grade data.
Is URLAbuse a public or private company?
URLAbuse is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was URLAbuse founded?
URLAbuse was founded in 2023. It employs 1 to 10 people.
Where is URLAbuse based?
URLAbuse is headquartered in Grenoble, France, in the Europe region.
How does URLAbuse make money?
Three revenue lines are on record. Commercial Threat Intelligence Feed is the primary driver. The others are API Access for Trusted Reporters and free Public Data.
Who are URLAbuse's main competitors?
Direct peers on record are SURBL, OpenPhish, urlscan.io, VirusTotal, PhishTank, Spamhaus and DomainTools. Emerging players are Phishfort and SlashNext. Cisco Talos is listed as a broad incumbent.
Does URLAbuse have an API?
Yes. URLAbuse provides two public APIs for trusted reporters: (1) POST https://zapi.urlabuse.com/feed/report_url — allows trusted third parties to report malicious URLs with parameters including token, URL, data_type (phishing/malware/hacked/bet/scam), target, geofenced country code, and reporter name; (2) POST https://urlabuse.com/get_trusted_report — for retrieving reports with screenshot support (base64-encoded JPG), targeting specific brands, and public/private visibility options. Additionally, an internal admin API (POST https://urlabuse.com/get_report_from_cti_data) provides access to pre-verified threat intelligence data. The DBL HTTP API at https://dbl.urlabuse.com/lookup?rd={domain} offers public, unauthenticated domain lookup returning BLACKLISTED or NOTBLACKLISTED status. No authentication required for DBL lookup; tokens obtained via contact form or email. Developer documentation is at urlabuse.com/doc.html.
What industry is URLAbuse in?
URLAbuse's product category is Threat Intelligence Platform. Its primary akta.pro industry code is HDADALAG, Spam, Fake Engagement & Content Abuse Prevention, with a secondary code of HDADAKAB, Email Phishing & BEC Protection. Its NAICS code is 5192 and its SIC code is 7370.