Use case · Infrastructure, security and sysadmins

IP Threat Data for CDN & WAF Edge Rules

The canonical file use case: lists pushed into Cloudflare, Fastly, Akamai or an in-house proxy layer, evaluated in-process with no added latency, and updated through a permalink that never changes between releases.

Start for freeSee how it works

Why edge decisions can't wait on a network call

Quick answer

IP Raccoon publishes category data as downloadable files at a stable URL, so CDNs and WAFs can evaluate every request in-process against an already-loaded ruleset — no external API call per request, no added latency.

Edge infrastructure sits in front of every request at volumes and latency budgets where a live network call per request simply isn't an option. That rules out API-based lookups for this specific layer, no matter how fast the API itself is — the constraint is architectural, not about raw speed.

What works instead is a file the edge already has loaded locally, refreshed on a schedule rather than looked up live. The customer points a cron job or a worker at a stable URL once, and every release lands in their stack automatically from then on.

How IP Raccoon helps

Category separation is what makes the data usable for edge rules, because edge policy is rarely one blocklist — it's usually a different rule per category:

CategoryTypical edge policy
Known botBlock
DatacenterBlock or heavily rate-limit
Residential proxyChallenge (CAPTCHA / JS check)
Known crawler (declared)Allow
Abuse-list matchLog for review, don't block automatically

What to look for in an edge IP threat feed

  • Open formats you can actually load — a plain list of subnets for a rule import, a MaxMind binary for library integration — rather than a proprietary integration
  • A stable permalink your automation can poll, rather than a manual download step
  • Releases frequent enough that newly-spun-up datacenter ranges and proxy pools are caught while they still matter
  • Category granularity, so policy can differ between "block" and "challenge" instead of one blunt list
$ curl -o anonymizers.mmdb \
  "https://files.ipraccoon.com/download/anonymizers?authorization=$IP_RACCOON_TOKEN&format=mmdb"

slugs:   reputation · anonymizers · detected_bots · known_bots
formats: csv (subnet) · csv_plus (subnet + subcategory) · mmdb

note:    the permalink never changes — every release lands through the same URL

Point your edge at real IP intelligence

Load IP Raccoon's datasets into your CDN or WAF once, and stop thinking about it.

Start for freeSee pricing

FAQ

Frequently asked questions

Related

More use cases

All use casesPre-bid filtering for DSPsCredential stuffing detectionGlossaryRead the docs