Every DNS resolver answering on the open internet.
Each address that answers DNS on UDP port 53, flagged for whether it advertises recursion and whether it actually resolves a query end to end — the line between an ordinary name server and an open resolver that can be abused for reflection attacks. Built from internet-wide measurement over a 90-day window.
Schema at a glance.
See documentation →The database's schema and metadata are documented carefully. It is published as CSVGZ.
Sample rows for this build are not published yet. Ask us for a slice and we will send one from the current build.
Downloading it from code.
Database API reference →One call gets you the current DNS Resolver IP build. Every official client wraps it three ways: straight to disk, a time-limited link you hand to your own runner, or bytes in memory. A file written to disk lands only once the whole transfer has arrived, and checksums() returns the published digests to verify it against.
download()downloadUrl()downloadBytes()metadata()checksums()import osfrom internetdata import InternetDataclient = InternetData(os.environ["INTERNETDATA_API_KEY"])# what is in today's build, without moving the filemeta = client.database.metadata("dns_resolver_ip_v1")client.database.download("dns_resolver_ip_v1", "csvgz", "./dns_resolver_ip_v1.csv.gz")sums = client.database.checksums("dns_resolver_ip_v1", "csvgz")print(meta.updated, meta.entries, sums["sha256"])
Getting your hands on it.
The file is the product. Teams join DNS Resolver IP against traffic they already log, inside their own infrastructure, and never send an address anywhere to get an answer.
Reflection-attack defense
Identify open recursive resolvers that can be abused for DNS reflection and amplification.
Address-space hygiene
Audit your own ranges for resolvers that answer the open internet when they should not.
Risk scoring
Separate ordinary name servers from resolvers that recurse for anyone, using the recursion and answer flags.
An official client for every major language.
All SDKs on GitHub →Twelve official clients for the languages you ship in, each wrapping the database endpoints — list what you are licensed for, poll a build, follow the download redirect, verify what landed. Install commands are in the docs.
No loose ends.
How often does this database rebuild?
Each Probe database publishes its own cadence and its last build date — the port-scan databases weekly, BGP Route daily. The scan databases carry a rolling 90-day observation window, so first seen and last seen are relative to it. Ask the metadata endpoint before you fetch.
What does an open port actually tell me?
That the host answered on that port during the window. Where the protocol exchange completed, the row also carries the service banner, and session_ok is true; where the port was open but silent, session_ok is false. The open set and the confirmed service ship in one file so you can tell them apart.
What is in a row?
For the port-scan databases, one host: its address, the port, and what it returned. For BGP Route, one announced prefix and origin, with its RPKI standing. IPv4 and IPv6 are in the same file.
Which formats does a build ship in?
Gzipped CSV. These databases are keyed per host, or per prefix for BGP Route, rather than per range, so there is no MMDB form.
Does a flag here mean we should block?
No. It means the address exposes that service, or announces that route. Blocking is a policy decision — the columns exist so it can be yours rather than ours.
Test the real build first.
An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.