πŸ† βœ“ Trusted since 1992 β€” 34 Years of Excellence

πŸ›‘οΈ CentralMail Threat Intelligence

Real-time spam and email threat intelligence from a live honeypot network spanning thousands of monitored domains

White-label threat maps and blacklist feeds for your security platform β€’ Price on application

πŸ•³οΈ
1,000sHoneypot Domains
⏱️
15 minBlacklist Updates
🌍
GlobalCoverage
🏷️
White-LabelReady

πŸ—ΊοΈ Live Threat Map

Our live threat map shows real-time spam attack origins across the globe β€” country by country, attack by attack. Embeddable into your platform and fully white-labelable with your own branding.

🌐 CentralMail Live Spam Threat Map

The threat map updates in real-time, plotting active spam sources by country and attack volume. See exactly where threats are originating, which IPs are most active, and how attack patterns shift throughout the day.

128,000+Total Threats
10,000+Unique IPs
9,300+Blocked IPs
4,100+Blocked Domains
159,000+Daily Consolidated
πŸ—ΊοΈ Open Live Threat Map β†’

πŸ’Ό Professional Spam Intelligence You Can Sell

CentralMail operates a sophisticated multi-vector spam detection and threat intelligence system. Our honeypot network captures and analyses spam attempts in real-time from sources worldwide, delivering actionable intelligence through continuously updated blacklist feeds and embeddable live threat maps β€” ready to white-label and resell as part of your own security platform.

Everything Included

πŸ—ΊοΈ

Live Spam Threat Map

Embeddable real-time world map showing active spam sources by country, attack volume and threat severity. Auto-refreshes and fully white-labelable with your own branding and domain.

πŸ•³οΈ

Honeypot Network

Thousands of unused domains configured as spam traps, attracting and cataloguing unsolicited communications from spammers worldwide. Continuously expanding coverage.

πŸ“‘

Open Relay Detection

Simulated open relay service capturing spammers attempting to exploit mail servers for unauthorised relay. Relay targets logged and distributed in real-time feeds.

πŸ“‹

Blacklist Feeds

IP and domain blacklists updated every 15 minutes in multiple formats: Postfix-ready, SpamAssassin-compatible. Consolidated daily list covers 159,000+ IPs.

πŸ“¬

Production Mail Analysis

Real-time feed from production email security appliances forwarding all detected spam for comprehensive cross-referencing and pattern analysis.

🌍

Geographic Intelligence

IP geolocation tracking identifying spam origins by country with threat correlation. Country-level threat ranking, peak attack analysis and trend reporting.

πŸ”

Behavioural Analysis

Automated threat scoring evaluating each source across attack frequency, domain patterns, historical behaviour and attack vectors. Critical, High, Medium severity classification.

🏷️

White-Label Ready

Your logo, your domain, your brand. The threat map and dashboard can be embedded directly into your customer portal or security product as a fully branded service.

βš™οΈ Technical Specifications

Full detail of what the platform delivers

SpecificationDetail
Honeypot DomainsThousands of monitored domains across multiple TLDs
Detection VectorsDirect honeypot, open relay simulation, production mail feed
Blacklist Update FrequencyEvery 15 minutes + consolidated daily at 02:00 UTC
IP Blacklist FormatsRaw IP list, Postfix hash format, consolidated combined list
Domain Blacklist FormatsRaw domain list, SpamAssassin compatible format
Threat ClassificationCritical, High, Medium severity levels
Geographic CoverageGlobal β€” IP geolocation across all monitored sources
Dashboard Refresh60-second auto-refresh, real-time streaming for new threats
Threat MapLive embeddable world map β€” centralmail.co.uk/threat-map.php
AbuseIPDB IntegrationActive contributor β€” all confirmed threats reported automatically
API AccessAvailable β€” feed integration and IP status lookup
White-LabelFull custom branding, domain, logo and colour scheme
Embeddingiframe-embeddable threat map for customer portals

Who Uses This

ISPs & Hosting Providers

Protect your mail infrastructure and offer customers a value-added spam intelligence feed branded as your own service.

Security Vendors

Embed live threat intelligence into your SIEM, mail gateway or security dashboard to enrich your product offering.

Enterprise IT Teams

Automate blacklist updates for Postfix and SpamAssassin every 15 minutes without maintaining your own honeypot infrastructure.

MSSPs

White-label the threat map and dashboard as a managed service deliverable β€” differentiate with real-time visual intelligence.

Mail Server Administrators

One cron job pulls the latest consolidated blacklist directly into Postfix or SpamAssassin. No complex setup, no maintenance burden.

Threat Researchers

Continuously updated corpus of real spam data, source IPs, targeted domains and attack patterns for research and analysis.

Pricing

Pricing depends on your specific requirements β€” feed volume, white-label scope, API access level and embedding requirements. Contact us to discuss.

CentralMail Threat Intelligence

POA

Price on application β€” tailored to your integration requirements, data volume and white-label scope.

  • Live spam threat map
  • Real-time blacklist feeds (15-min updates)
  • Honeypot network intelligence
  • Open relay detection data
  • Geographic threat analysis
  • White-label & embeddable
  • API access available
πŸ“© Request a Quote

Frequently Asked Questions

How often are the blacklists updated?
The real-time IP and domain streams update every 15 minutes. A consolidated master list covering all sources is generated daily at 02:00 UTC and typically contains 159,000+ IPs.
Can I embed the threat map in my own platform?
Yes. The live threat map at centralmail.co.uk/threat-map.php is iframe-embeddable and can be white-labelled with your own domain, logo and colour scheme. We handle all the infrastructure.
How do I integrate the blacklists with Postfix?
Download the pre-formatted Postfix file to /etc/postfix/centralmail_blacklist, add a single line to main.cf, run postmap and reload Postfix. Full instructions are provided on the platform.
What threat categories are covered?
Honeypot activations, open relay attempts, production spam feed detections. All classified by severity (Critical, High, Medium) and type.
Is there an API for automated integration?
Yes, API access is available for feed integration and IP status lookup. Details and rate limits are provided on request.
Do you report to AbuseIPDB?
Yes. We are an active AbuseIPDB contributor and all confirmed threat IPs are automatically reported, contributing to the global community blacklist.

Ready to Add Threat Intelligence to Your Platform?

White-label spam threat maps and blacklist feeds β€” branded as your own service

Get in Touch Today β†’

Price on application β€’ No obligation β€’ Response within 24 hours