Use case · Infrastructure, security and sysadmins
IP Threat Data for CDN & WAF Edge Rules
The canonical file use case: lists pushed into Cloudflare, Fastly, Akamai or an in-house proxy layer, evaluated in-process with no added latency, and updated through a permalink that never changes between releases.
Why edge decisions can't wait on a network call
Quick answer
IP Raccoon publishes category data as downloadable files at a stable URL, so CDNs and WAFs can evaluate every request in-process against an already-loaded ruleset — no external API call per request, no added latency.
Edge infrastructure sits in front of every request at volumes and latency budgets where a live network call per request simply isn't an option. That rules out API-based lookups for this specific layer, no matter how fast the API itself is — the constraint is architectural, not about raw speed.
What works instead is a file the edge already has loaded locally, refreshed on a schedule rather than looked up live. The customer points a cron job or a worker at a stable URL once, and every release lands in their stack automatically from then on.
How IP Raccoon helps
Category separation is what makes the data usable for edge rules, because edge policy is rarely one blocklist — it's usually a different rule per category:
| Category | Typical edge policy |
|---|---|
| Known bot | Block |
| Datacenter | Block or heavily rate-limit |
| Residential proxy | Challenge (CAPTCHA / JS check) |
| Known crawler (declared) | Allow |
| Abuse-list match | Log for review, don't block automatically |
What to look for in an edge IP threat feed
- Open formats you can actually load — a plain list of subnets for a rule import, a MaxMind binary for library integration — rather than a proprietary integration
- A stable permalink your automation can poll, rather than a manual download step
- Releases frequent enough that newly-spun-up datacenter ranges and proxy pools are caught while they still matter
- Category granularity, so policy can differ between "block" and "challenge" instead of one blunt list
$ curl -o anonymizers.mmdb \ "https://files.ipraccoon.com/download/anonymizers?authorization=$IP_RACCOON_TOKEN&format=mmdb" slugs: reputation · anonymizers · detected_bots · known_bots formats: csv (subnet) · csv_plus (subnet + subcategory) · mmdb note: the permalink never changes — every release lands through the same URL
Point your edge at real IP intelligence
Load IP Raccoon's datasets into your CDN or WAF once, and stop thinking about it.
FAQ