An IP is evaluated with multiple signals.
No single list decides on its own: reputation, history, location and feed contribute to risk.
Sentinel combines local history, DNSBL, geographical data, proxy and threat feeds to assess incoming IP addresses. In parallel, it checks the public reputation of your server IPs.
No single list decides on its own: reputation, history, location and feed contribute to risk.
An IP address placed on a blocklist can compromise mail, reputation and reliability of services.
Policies can run in monitoring mode, and the panel shows which blocklist reported the IP.
Source reputation
For each source IP, Sentinel builds a score from 0 to 100. The result combines DNSBL, activity previously observed by your infrastructure, geographic risk, proxy/Tor/VPN or datacenter networks and presence in configured feeds.

Threat feeds
Sentinel can download IP lists from configured HTTPS sources and keep them in a local managed cache.
Supports IP and CIDR lists, including FireHOL formats, Emerging Threats and generic one-entry-per-line feeds.
Each source can be set to block or just monitor the indicators found.
HTTPS-only downloads, size limits and timeouts prevent an abnormal feed from consuming resources without control.
A match can stop the request before the WAF engine, reducing processing for already known hostile sources.
Reputation of your servers
The central server periodically checks the fleet's public IPs against 20 DNSBL. The dashboard shows how many servers are clean, which are reported, the last verification and the blocklist responsible.

Operational transparency
User requests are inspected by the agent and do not pass through a Sentinel cloud proxy.
If enabled, agents download indicators from configured HTTPS URLs. The feed provider receives the download request.
Reputation checks carry out queries to configured DNSBL providers; they are not a fully offline function.
We configure reputation and feeds based on the risk and privacy required by your infrastructure.