Identify the threat before it becomes an incident.

Sentinel combines local history, DNSBL, geographical data, proxy and threat feeds to assess incoming IP addresses. In parallel, it checks the public reputation of your server IPs.

Reputation 0Feed HTTPSDNSBL server control
Input traffic

An IP is evaluated with multiple signals.

No single list decides on its own: reputation, history, location and feed contribute to risk.

Your servers

Sentinel checks whether server IP addresses appear on DNS blocklists.

An IP address placed on a blocklist can compromise mail, reputation and reliability of services.

Action

Block, observe or start delisting.

Policies can run in monitoring mode, and the panel shows which blocklist reported the IP.

Source reputation

Explainable score, not a black box.

For each source IP, Sentinel builds a score from 0 to 100. The result combines DNSBL, activity previously observed by your infrastructure, geographic risk, proxy/Tor/VPN or datacenter networks and presence in configured feeds.

  • Configurable threshold: Choose when to intervene.
  • Shadow mode: observe the effect before blocking.
  • Priority allowlist: A trusted address is not penalized by other signals.
Geo-blocking and reputation →
Geographical policy and IP reputation in the Sentinel dashboard

Threat feeds

Updated indicators, applied locally.

Sentinel can download IP lists from configured HTTPS sources and keep them in a local managed cache.

Known or custom feeds

Supports IP and CIDR lists, including FireHOL formats, Emerging Threats and generic one-entry-per-line feeds.

Feed action

Each source can be set to block or just monitor the indicators found.

Controlled update

HTTPS-only downloads, size limits and timeouts prevent an abnormal feed from consuming resources without control.

Pre-filter decision

A match can stop the request before the WAF engine, reducing processing for already known hostile sources.

Reputation of your servers

We don't just control who comes in.

The central server periodically checks the fleet's public IPs against 20 DNSBL. The dashboard shows how many servers are clean, which are reported, the last verification and the blocklist responsible.

  • Automatic control Every 10 minutes.
  • Manual verification when you want to update the status.
  • Detail by source with links and instructions available for delisting.
Status of servers managed in the Sentinel dashboard

Operational transparency

What remains local and what an external source requires.

01

Local web traffic

User requests are inspected by the agent and do not pass through a Sentinel cloud proxy.

02

Optional Feed

If enabled, agents download indicators from configured HTTPS URLs. The feed provider receives the download request.

03

DNSBL lookup

Reputation checks carry out queries to configured DNSBL providers; they are not a fully offline function.

Do you want to identify which sources you actually need?

We configure reputation and feeds based on the risk and privacy required by your infrastructure.