CentralMail Logo Security Intelligence

Real-Time Spam Threat Analysis & Blacklist Distribution Platform

Professional Spam Intelligence Platform

Welcome to CentralMail's advanced spam detection and threat intelligence system. This platform operates a sophisticated honeypot network spanning many thousands of monitored domains, capturing and analyzing spam attempts in real-time from sources worldwide.

Our multi-vector detection system includes:

  • Direct Honeypot Monitoring: thousands of unused domains configured as spam traps to attract and catalog unsolicited communications
  • Open Relay Detection: Simulated open relay service capturing spammers attempting to exploit mail servers for unauthorized relay
  • Production Mail Analysis: Real-time feed from production email security appliance (EFA) forwarding all detected spam for comprehensive analysis
  • Geographic Intelligence: IP geolocation tracking identifying spam origins by country with threat correlation
  • Behavioral Analysis: Automated threat level assessment based on spam frequency, domain patterns, and attack vectors

All collected intelligence is processed through our proprietary multi-stage analysis engine, which automatically categorizes threats by severity level, geographic origin, and behavioral patterns. Our sophisticated scoring algorithms evaluate each spam source across multiple dimensions including attack frequency, targeted domains, and historical patterns. This comprehensive analysis is then made available through continuously updated blacklists distributed in multiple formats for seamless integration with various mail server platforms.

Our honeypot network operates in real-time streaming mode, with all trap activations immediately logged and analyzed. Relay attempt data is similarly processed with zero latency, ensuring newly identified spam sources are flagged within seconds of detection. For operational consistency and automated scheduled updates, all IP addresses from across our distributed monitoring infrastructure are consolidated into unified master blacklists daily at 0200 UTC.

🎯 TOP THREATS

Most Active IP
80.94.95.242
πŸ”₯ 46,006 attacks HU
Highest Origin
BG
πŸ“ 38,983 threats
Latest Attack
80.94.95.242
BG AUTH_ATTACK
⏱️ 07:42:20
Updated: 07:42:37 UTC
120,998 Total Threats
9,781 Unique IPs
2,328 Today
38,975 This Week
120,431 This Month
52 Critical
50 High
375 Medium
548 Relay
682 Honeypot
9,010 Blocked IPs
4,091 Blocked Domains

πŸ“₯ Download Current Blacklists Honeypots > Real-Time

AbuseIPDB Contributor Badge

🚫 Honeypot IP Stream 9,010 ip's Confirmed spam IPs 🌐 Honeypot Domain Stream 4,091 domains Malicious domains πŸ“Š Consolidated Daily List 158,793 ip's Updates at 0200 UTC every day πŸ“ˆ Open Relay Targets 19 domains / 548 hits Active Spammer Relay Targeting

Implementation Guide

Postfix Integration:

  • Download postfix-centralmail.txt to /etc/postfix/centralmail_blacklist (Pre Formatted) Full List
  • Add to main.cf: smtpd_client_restrictions = check_client_access hash:/etc/postfix/centralmail_blacklist
  • Run: postmap /etc/postfix/centralmail_blacklist && postfix reload

SpamAssassin Integration:

  • Download domains.txt and add to local.cf
  • Format: blacklist_from *@domain.com
  • Restart SpamAssassin service

Automated Updates: Set up cron job to download lists every 15 minutes for maximum protection

Check Your IP Status

πŸ“Š 24-Hour Threat Activity Analysis

6,394
TOTAL THREATS
447
PEAK HOUR
266.4
AVG PER HOUR
24
ACTIVE HOURS
Critical High Medium Low Trend Line