Request a Delisting
Believe your IP address or domain is listed in error? Tell us who you are and what was fixed — our security team reviews every confirmed request and removes remediated indicators.
How it works
Submit your request
Fill in the form with the IP or domain, who you are, why the listing is incorrect, and what remediation was performed.
Confirm your email
Click the confirmation link we send you. Requests are only reviewed after email confirmation — the link expires in 24 hours.
Security review
Our team checks the indicator against current threat feeds, scanner verdicts, and exposure data before deciding.
Decision by email
You receive the decision with reviewer notes. Approved delistings take effect immediately across our API and reports.
Submit your delisting request
All fields are reviewed by a human. Detailed, honest requests are approved faster.
Delisting FAQ
Who can request a delisting?
Anyone responsible for an IP address or domain — owners, network administrators, or security teams acting on their behalf. We ask for your name, organization, and role so our reviewers can assess the request, and we verify your email address before any review starts.
How long does the review take?
Most requests are reviewed within a few business days. Complex cases — for example indicators still flagged by multiple independent sources — can take longer because we re-check the evidence before deciding.
What evidence should I include?
The strongest requests explain what caused the listing and what was done about it: malware removed, a compromised server rebuilt, an open service closed, or a change of IP ownership. If the indicator was never malicious, explain what it is used for and why the detection is a false positive.
Why was my request rejected?
The most common reason is that the indicator still shows active malicious signals — listings on independent blocklists, malware detections, or exposed vulnerable services. Fix the underlying issue first, request delisting from the source blocklists, then submit a new request with the updated details.
Can a delisted indicator be re-listed?
Yes. Delisting reflects the state at review time. If threat feeds flag the indicator again with new evidence of malicious activity, our team can revoke the delisting to keep verdicts accurate for everyone who relies on our data.
Does delisting remove me from other blocklists?
No. IsMalicious aggregates many independent intelligence sources, and each maintains its own listings. Approved delistings stop IsMalicious from reporting the indicator as malicious, but you should also request removal from the original source blocklists.