Threat-intelligence feed
General BlacklistsLast verified Page fetched
DNS RD Abuse is a general blacklists threat-intelligence feed tracked by WhisperGraph as a FEED_SOURCE node. The Whisper Internet Directory publishes this page so security analysts and LLM agents can link to it as a stable record for DNS RD Abuse.
DNS RD Abuse is a feed of IP addresses observed sending recursive DNS queries to authoritative servers that should never receive them — a classic indicator of a misconfigured open resolver or a host actively participating in DNS amplification abuse. Source data comes from the DataPlane.org passive-sensor network. The feed is most useful to authoritative-DNS operators as an enrichment overlay on top of QPS-based abuse detection; including a known-RD-abuser list lets operators short-circuit threshold-based decisions for hosts already on multiple aggregator deny-lists. It is indexed here as a record for DNS-amplification mitigation playbooks.
Live data unavailable. WhisperGraph returned an error (WhisperGraph 503) while looking up this FEED_SOURCE node. The editorial content above is authoritative; the live-data check will retry on the next page revalidation.
Indicators: Computing — check back later. The precompute pipeline is building this feed's indicator sample from the host corpus and will populate the count and representative addresses on an upcoming run.
Look up which threat feeds list a given IP — the indicator-anchored query that powers the threat card:
MATCH (ip:IPV4 {name: $ip})-[:LISTED_IN]->(f:FEED_SOURCE)
WHERE f.name = "DNS RD Abuse"
WITH f
MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
RETURN f.name AS feed, c.name AS categoryVerify the feed's graph-side identity directly:
MATCH (f:FEED_SOURCE {name: "DNS RD Abuse"})
OPTIONAL MATCH (f)-[:BELONGS_TO]->(c:CATEGORY)
RETURN f.id AS id, f.name AS name, c.name AS categoryOr query Whisper from your own LLM workflow via the Whisper MCP server.
Pivot from DNS RD Abuse into adjacent entities.