Surbl
SURBL BV is a Netherlands-based, privately held provider of DNS-based domain and URI reputation intelligence feeds, founded in 2004 and serving ISPs, email security vendors, universities, and URL shorteners via free public DNS and a paid subscription data feed.
- Company typePrivate
- Founded2004
- HeadquartersStolwijk, Netherlands
- Headcount1–10
- GTM typeB2B
- OfferingSoftware
What Surbl does
SURBL BV, incorporated in the Netherlands and headquartered in Amsterdam, has operated since 2004 as a domain and URI reputation intelligence provider. Its core technology is a DNS-based blocklist (DNSBL) system that publishes near real-time feeds of malicious and abused domains, supported by infrastructure delivering updates more than 240 times daily (Multi list updating every 30-40 seconds on average). The product portfolio spans the public Multi dataset, the Fresh dataset (newly delegated TLD domains with UNIX Epoch timestamps), HashBL (cryptographic hashes of abused cloud providers, email addresses, URIs, shortener links, crypto addresses, and phone numbers), category-specific feeds (ABUSE, PH, MW, CR, CT, DM), shortener domain lists, and the UriQ URI-level API. Data is delivered via DNS, RPZ, rsync, CSV, and real-time JSON, and is natively consumed by Apache SpamAssassin, milter-link, MailMarshal, Exim, Sendmail, Postfix, and major DNS firewalls.
SURBL operates a freemium commercial model. The Free Query Service (FQS) is available to organizations under 1,000 users or 250,000 messages/day via a worldwide network of public DNS servers. The Sponsored Data Service (SDS) is a paid annual subscription offering higher update frequency, rsync delivery, and unlimited technical support for commercial users, resold via securityZONES. Customers include ISPs (Easynet France, Tiscali Benelux, Wanadoo NL, Sonic.net, XMission), email security vendors (SpamCop, MailGuard, MailRoute, Cumberland Technologies), universities (Yale School of Medicine, University of Bristol), URL shorteners (bit.ly, TinyURL, SnipURL), and data partners (PhishTank, PhishLabs, URLAbuse, abuse.ch, Telenor). The company reports zero external funding, founder/operator ownership under Raymond Dijkxhoorn, and self-sustaining economics since inception.
Surbl firmographics
Firmographics- Name
- Surbl
- Legal name
- SURBL BV
- Website
- https://surbl.org
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- SURBL BV is a Netherlands-based, privately held provider of DNS-based domain and URI reputation intelligence feeds, founded in 2004 and serving ISPs, email security vendors, universities, and URL shorteners via free public DNS and a paid subscription data feed.
- Ownership category
- akta.pro rank
Surbl industry classification
Industry- Product category
- Threat Intelligence Data Feeds
- NAICS
- Directory and Mailing List Publishers (51314)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Spam, Fake Engagement & Content Abuse Prevention (HDADALAG)
Keywords
Where Surbl is headquartered
LocationHeadquarters
- HQ city
- Stolwijk
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Surbl business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Infrastructure, Personnel, Operations, Marketing or Sales, Supply Chain
Revenue model
- Sponsored Data Service (SDS): Paid subscription service for professional users providing higher performance through faster updates and fresher data. Includes unlimited access to technical support team. Required for organizations with 1,000+ users or commercial products/services. Data provided via rsync feed with automatic updates.
- Free Query Service (FQS): Free DNS query service for individual users, small businesses, and non-profits under 1,000 users or 250,000 messages/day. Provides revenue from paid SDS subscriptions that cross-subsidize the free service.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Others | Free Query Service (FQS) - Free tier for small organizations |
| Subscription | Annual | Sponsored Data Service (SDS) - Professional paid tier |
Go-to-market motion2 records
Distribution channels4 records
Marketing channels5 records
Surbl product offering
Product offeringCore offering
SURBL operates a DNS-based reputation and threat intelligence data service that lists domains, URIs, cryptographic hashes, and other indicators of malicious or abused internet resources. Its primary product is the Multi dataset (a bitmasked combination of abuse, phishing, malware, cracked, click-tracker, and disposable-email lists), supplemented by Fresh (recently delegated TLD domains), HashBL (hash-based abuse indicators), and the UriQ URI query API. Data is delivered via free public DNS queries for small organizations and paid DNS/RPZ/rsync/API/RTF feeds for professional and commercial users, supporting email filtering, DNS firewalls, SMS protection, and safe browsing.
Product overview
SURBL is a reputation intelligence and threat intelligence data service provider. The company operates a DNS-based blocklist system that identifies malicious or abused web domains and URIs. The core offering consists of multiple dataset products: the Multi combined dataset (the primary public dataset available via free DNS queries), the Fresh domain feed (recently delegated TLD domains with timestamps), HashBL (cryptographic hashes of abused items including crypto addresses, phone numbers, and email addresses), URI query services, and shortener domain lists. Data is delivered via DNS (RPZ, public DNS queries), RSYNC for sponsored data service, CSV, and real-time JSON feeds. The service is designed for mail filtering, DNS firewalls, web access security, SMS protection, and botnet traffic mitigation. Since 2004, SURBL has been providing free public DNS query access for small organizations while offering paid data feeds for professional/high-volume users.
Differentiator
Problem solved
Functional benefit
Products and services
- Multi Dataset The principal public dataset listing domains of malicious or abused web sites. It is bitmask-encoded to combine ABUSE, PH, MW, CR, CT, and DM category membership in a single DNS response and is used to filter or tag unsolicited messages based on links in message bodies regardless of sender IP addresses. Available via public DNS queries and as a private RPZ dataset, updated more than 240 times daily.
- Fresh Dataset Private dataset of domains recently added to TLD zone file delegations, including UNIX Epoch timestamps of detected changes. Used as one of multiple factors to indicate domain reputation, since younger domains are statistically more likely to be abusive. Selected subsets are available for RPZ.
- HashBL Private dataset of cryptographic hashes for items connected to internet abuse, enabling exact matching of bad indicators in applications. Categories include abused public cloud providers, abused sender and reply-to email addresses, full URI listings, abused shortener links, crypto address listings, and phone number listings.
- Shortener Domain List Private dataset listing known URI shortener services ranging from major ones like bit.ly and t.co to minor hobbyist shorteners, used for tracking and security analysis of shortened URLs.
- Abused Shortener URI List Private dataset containing specific recently appeared abused shortener URIs, identifying instances where shortener services are exploited for malicious purposes.
- UriQ (URI Query API) API that checks full URIs, in particular for legitimate but cracked or abused sites that cannot be listed at the host (domain or IP) level in the main dataset, enabling granular URI-level reputation checks.
- Free Query Service (FQS) Free public DNS query service for individual users and organizations with fewer than 1,000 users or scanning fewer than 250,000 messages per day. Accessed via a worldwide network of geographically diverse public DNS servers; restricted from embedding in fee-charging products or services.
- Sponsored Data Service (SDS) Paid data feed service required for organizations with 1,000+ users or commercial applications. Provides rsync feed with automatic updates, fresher data, higher detection rates, and unlimited technical support; available in DNS, RPZ, rsync, CSV, RTF (JSON), and REST API formats.
- AB - Abuse Sites Dataset Private dataset containing spam and other abuse sites including pills, counterfeits, dating, and similar categories. Sources include internal proprietary research, passive DNS data, TLD operator zone files, and contributions from Internet security, anti-abuse, ISP, and ESP communities including Telenor.
- PH - Phishing Sites Dataset Private dataset of phishing sites aggregated from multiple sources including PhishTank, PhishLabs, URLAbuse, and proprietary internal research.
- MW - Malware Sites Dataset Private dataset of malware hosting sites sourced from abuse.ch, URLAbuse, and proprietary research; some cracked hosts are also included since many cracked sites also distribute malware.
- CR - Cracked Sites Dataset Private dataset listing sites with stolen credentials or exploited vulnerabilities (e.g., cracked WordPress or Joomla sites hosting malicious content, often redirecting to spam sites). Cracked sites may still contain legitimate content alongside the abuse.
- CT - Click Tracker Domains Dataset Private dataset of domains used for tracking clicks in emails, specifically from senders that send to mailboxes without confirmed opt-in (e.g., emails sent to spamtraps).
- DM - Disposable Email Domains Dataset Private dataset listing domains classified as disposable email solutions, useful for identifying users attempting to hide their true identity during service sign-ups.
Quantifiable outcome
- Detects 95% of unsolicited messages when combined with sender IP lists
- +2 more outcomes
Companies that use Surbl
Customer profileNamed customers14 records
Segments5 records
Ideal customer profiles5 records
Surbl technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration11 records
AI capability3 records
Feature6 records
Surbl partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered core.
- securityZONEScoresecurityZONES is an authorized reseller of SURBL Data Feeds, distributing SURBL's threat intelligence products to customers worldwide.
- PhishTankcorePhishTank phishing data is included as a source in SURBL's PH (Phishing) dataset, contributing to the comprehensive phishing threat intelligence.
- PhishLabscorePhishLabs phishing intelligence data feeds into SURBL's PH phishing detection dataset.
- URLAbusecoreURLAbuse data included in both PH (Phishing) and MW (Malware) datasets for enhanced threat detection.
- abuse.chcoreabuse.ch malware data sources included in SURBL's MW (Malware) dataset.
- Apache SpamAssassincoreSpamAssassin has built-in support for SURBL intelligence with URIDNSBL plugin enabled by default. SA4 supports full domain lookups with many advantages.
Scale indicators5 records
Recent moves6 records
Expansion highlights12 records
Surbl competitors and assessment
Company assessmentEmerging players
- abuse.ch (URLhaus/ThreatFox): abuse.ch runs open malware-URL and IOC-sharing projects (e.g., URLhaus) and contributes data into SURBL's MW dataset; it is both a partial data source and a competing community-driven reputation feed.
- Spfbl (Sender Policy Framework Blocklist): Spfbl provides DNSBL-style reputation intelligence including URI/email sender abuse signals, overlapping with SURBL's remit but focused on the Brazilian/Portuguese-speaking ecosystem.
Others
- Phishtank: PhishTank is a community phishing-URL verification project whose data SURBL ingests into its PH dataset; it is an adjacent community contributor rather than a direct commercial rival but touches the same phishing-URL intelligence domain.
Broad incumbents
- Cisco Talos Intelligence: Cisco Talos operates one of the largest commercial threat intelligence operations globally; it produces URL/domain reputation data that competes with SURBL's feeds and is bundled into Cisco's email and DNS security products.
- Proofpoint (Threat Intelligence/PURL/ET Intelligence): Proofpoint operates commercial URL reputation intelligence (formerly Emerging Threats/PURL) widely deployed in enterprise mail environments, competing with SURBL on URL reputation feeds but as part of a much broader cybersecurity portfolio.
- Recorded Future: Recorded Future aggregates domain/URL reputation alongside broader threat intelligence; it competes with SURBL for security-team budget on richer intelligence rather than raw DNSBL data feeds.
Direct peers
- Invaluement: Invaluement publishes URI reputation blocklists consumed by mail filtering platforms, directly competing with SURBL's Multi dataset on near-identical use cases.
- Spamhaus: Spamhaus is the dominant DNSBL/URI reputation data provider; SURBL and Spamhaus compete head-to-head for paid reputation feed customers and free public DNSBL queries across email security gateways.
- URIBL: URIBL operates a URI-domain reputation blocklist that overlaps directly with SURBL's Multi product, used by the same email gateway vendors for URI-based spam and phishing detection.
- Spamcop (Cisco): SpamCop delivers spam-reporting-driven reputation intelligence very similar to SURBL's abuse lists; SURBL historically absorbed SpamCop-derived data and still competes for the same spam-filter decisioning market.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights6 records
Customer concentration
Surbl social profiles
Digital presenceSurbl financial estimates
Financial estimateRevenue estimate
Valuation estimate
Surbl leadership team
Management profileNumber of profiles
Profiles1 record
Surbl funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Surbl M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Surbl
What does Surbl do?
SURBL operates a DNS-based reputation and threat intelligence data service that lists domains, URIs, cryptographic hashes, and other indicators of malicious or abused internet resources. Its primary product is the Multi dataset (a bitmasked combination of abuse, phishing, malware, cracked, click-tracker, and disposable-email lists), supplemented by Fresh (recently delegated TLD domains), HashBL (hash-based abuse indicators), and the UriQ URI query API. Data is delivered via free public DNS queries for small organizations and paid DNS/RPZ/rsync/API/RTF feeds for professional and commercial users, supporting email filtering, DNS firewalls, SMS protection, and safe browsing.
Is Surbl a public or private company?
Surbl is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Surbl founded?
Surbl was founded in 2004. It employs 1 to 10 people.
Where is Surbl based?
Surbl is headquartered in Stolwijk, Netherlands, in the Europe region.
How does Surbl make money?
Two revenue lines are on record. Sponsored Data Service (SDS) is the primary driver. The others are free Query Service (FQS).
Who are Surbl's main competitors?
Emerging players on record are abuse.ch (URLhaus/ThreatFox) and Spfbl (Sender Policy Framework Blocklist). Phishtank is listed as an others. Broad incumbents are Cisco Talos Intelligence, Proofpoint (Threat Intelligence/PURL/ET Intelligence) and Recorded Future. Direct peers are Invaluement, Spamhaus, URIBL and Spamcop (Cisco).
Does Surbl have an API?
Yes. SURBL provides a RESTful API for data feed access. The main data access methods are DNS queries (free public service), DNS Response Policy Zones (RPZ) for DNS firewalls, RSYNC for sponsored data service, and real-time feeds (RTF/JSON) for high-volume professional users. The UriQ (URI Query) API specifically checks full URIs for legitimate but cracked or abused sites. Data feed formats include: API (RESTful API), CSV, DNS (Private Query Service), RPZ (DNS Response Policy Zones), RSYNC (Sponsored Data Service), and RTF (JSON Real-time feeds). Rsync and DNS are typically used for mail filtering; RPZ is used for web filtering.
What industry is Surbl in?
Surbl's product category is Threat Intelligence Data Feeds. Its primary akta.pro industry code is HDADALAG, Spam, Fake Engagement & Content Abuse Prevention. Its NAICS code is 51314 and its SIC code is 7370.