[Feature Request] DNSBL in Wildcard Format

Started by Wrigleys, September 11, 2026, 05:43:32 PM

Previous topic - Next topic
Hi all

I would like to ask, if your malware_domain feed is planned to support other formats like Domain Wildcard (Asterisk)?

In OPNsense Unbound, this malware_domain feed isn't parsing in the wildcard format and therefore only exact matches will gets blocked.

Export from Log File:
blocklist: https://api.qfeeds.com/api?feed_type=malware_domains&api_token=xxxxxxx (block: 121164 wildcard: 0)
Thanks for your awesome service.

Take care and all the best,
Wrigleys

currently a paid user.   I am not sure I am understanding.

my account says : 121,281
Current Count
As of Sep 12, 2026 3:00 PM

unbound logs:   2026-09-11T23:00:03-04:00Noticeunbound blocklist parsing done in 2.88 seconds (121269 records)

its set to sync every 12 hours so the numbers may be sightly off

so its syncing everything included with your account.  correct?
DEC740 > USW-Pro-8-PoE> U6-Enterprise
Dec670. Retired / backup device

September 12, 2026, 09:48:17 PM #2 Last Edit: September 13, 2026, 06:56:44 AM by Wrigleys
I'm using the community feeds. I would like to have those records in another format so that unbound will block those records in the wildcard format instead of host/domain format.

for exampe:

I'm not using the official Plugin. Because you can also feed those two community lists by URL. And my feeds are synchronizing every 6h.

Very sorry for the late reply... the reason we are not supporting wildcard formats is because it creates too much false positives. while some domains could be 'collapsed' in the feed, the benefit of wildcarding those will be very small. Or are we missing something?

Your Threat Intelligence Partner  qfeeds.com

Hi and thanks for your follow-up. The reason why I'm asking is to  make sure to cover relevant alternative subdomain URL combinations like www.baddomain[.]com, www2.baddomain[.]com or just baddomain[.]com

If I was an attacker I would change the subdomain more often to get rid of any static blocklist entries. A wildcard entry would block it in any way possible, but the chances to block false positive is a valid argument.

either way, many thanks for your feedback.

Many thanks and stay safe
Wrigleys