Skip to content

Ward opens soon: join the waitlist and we'll email you the day we open.

What Ward checks

Area: Reputation and impersonation

IPs attacking others

Whether any of your public IPs (up to 30) is in a network marked as hijacked or used for crime (DROP list), on the CINS list of addresses that have attacked other systems, or is a Tor exit node. The lists are downloaded every day and matched on our servers.

What it can report

Open each one to see what it means and how to fix it.

Address in a hijacked network (DROP)

What it means

The address 203.0.113.10 belongs to a network that appears on a list of networks hijacked or controlled by criminal groups, known as the DROP list. Many internet and mail providers block all traffic from those networks.

What could happen

Your website and email may not reach some customers, because their providers drop anything coming from that network. It can happen because the address range was stolen or reassigned to criminals, or because your provider rents addresses from a bad network. It doesn't mean your own computers are infected.

How an attacker would use it

Criminals take over a block of internet addresses that a company no longer uses and later rent it out. Your provider assigns you an address from that block without knowing, and from then on your messages are blocked by security services that distrust the whole network.

How to fix it

  1. Ask your hosting or internet provider whether that address range was hijacked or recently reassigned.
  2. Ask for an address from another network and move your website or mail server to it.
  3. If your email is the problem, send it through a reputable mail service instead of from that address.
  4. Check that no computer of yours is infected, just in case.
  5. Until it is fixed, expect some of your email and web traffic to be blocked, and warn customers who report problems.

How to check it's fixed

Ward checks the list again, which is refreshed daily. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your provider

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Address seen attacking other systems

What it means

The address 203.0.113.10 appears on CINS Army, a public list of addresses that have recently attacked other systems. When it happens with a company's address, it often means a computer or server behind it is infected or hacked and being used by criminals.

What could happen

Besides the risk of being compromised, that address can get your email and website blocked. It can also be a false positive if your provider shares the address with other customers, which is why it is medium severity, not high.

How an attacker would use it

A computer in your office or a forgotten server gets infected, for example through a poisoned attachment or a weak password. Criminals use it to attack other companies from your address without you noticing, and the address ends up on the list.

How to fix it

  1. Find out which computer or server uses that address.In an office it's usually the router's public address, so look at the computers and devices behind it.
  2. Ask your IT person to check it: unknown software, odd processes, strange connections.
  3. Change the administration passwords and update the system. If in doubt, reinstall it.
  4. Check routers, cameras and other connected devices: they are often the ones infected.
  5. If you are on shared hosting, tell your provider: another customer may be the cause.

How to check it's fixed

Ward checks the list again, which is refreshed daily. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Address is a Tor exit node

What it means

The address 203.0.113.10 is on the public list of Tor exit nodes. Tor is a network that hides who is browsing, and exit nodes are the computers where that anonymous traffic comes out onto the normal internet. It's the address of your main website or mail server.

What could happen

Many websites and mail services block Tor addresses, so some customers may not reach your site or receive your email. Unless you run a Tor relay on purpose, someone may have installed Tor on that server without permission.

How an attacker would use it

Someone with access to your server installs Tor on it and lets strangers send anonymous traffic through your address. Your address then takes the blame for what that traffic does, and mail services start rejecting your messages.

How to fix it

  1. Ask whoever manages that server whether it runs a Tor relay on purpose.
  2. If it doesn't, find out who installed it and remove it.
  3. Review the server's security: users, installed software and passwords. Change the passwords.
  4. If it's intentional, move your website and email to other addresses, so the Tor traffic doesn't affect them.

How to check it's fixed

Ward checks the list of exit nodes again, which is refreshed daily. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Abuse reports against the address

What it means

The address 203.0.113.10 has reports in AbuseIPDB, a shared database where administrators around the world report attacks.

What could happen

A reported address is often infected or compromised and used to attack others, and it can get your email or website blocked. If your site is on shared hosting, the cause can be another customer on the same server, so it needs checking before assuming it's you.

How an attacker would use it

A computer or server of yours is infected and silently used to try passwords on other companies' services. Their administrators report your address, and the reports pile up until services start refusing your traffic.

How to fix it

  1. Find out which server or computer uses that address.
  2. Ask your IT person to check it for unknown software, unusual connections and new accounts.
  3. Change the passwords, update the system and, if in doubt, reinstall it.
  4. If you are on shared hosting, ask your provider to check the server and to change you to another address if needed.
  5. Once it's fixed, ask AbuseIPDB to review the reports and let them age out.

How to check it's fixed

Ward reads the score again; it falls as the reports age. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.

Address seen scanning the internet

What it means

GreyNoise, a service that watches hostile traffic on the internet, has seen the address 203.0.113.10 scanning or attacking other networks and classifies it as malicious. When it happens with a company's address, a computer or server behind it is often infected or hacked.

What could happen

Besides the risk of being compromised, that address can get your email and website blocked by other companies. It can also be a false positive if your provider shares the address with other customers, which is why it is medium severity.

How an attacker would use it

A computer in your office or a forgotten server gets infected, for example through a poisoned attachment or a weak password. Criminals use it to probe other companies from your address without you noticing, and security services take note.

How to fix it

  1. Find out which computer or server uses that address.In an office it's usually the router's public address, so look at the computers and devices behind it.
  2. Ask your IT person to check it: unknown software, odd processes, strange connections.
  3. Change the administration passwords and update the system. If in doubt, reinstall it.
  4. Check routers, cameras and other connected devices: they are often the ones infected.
  5. If you are on shared hosting, tell your provider: another customer may be the cause.

How to check it's fixed

Ward asks again whether the address is still seen attacking others. Mark the finding as “Pending verification” and Ward will check it again within a minute or two. Once the problem is gone, it moves to “Resolved” on its own.

Who usually fixes it

Your IT person

Example with sample data. In your dashboard, the explanation uses your own domain and details.