Shodan — verifying the best-known internet scanner via reverse DNS
by shop owners for shop owners.
How the PARC feed for Shodan came about: distributed census nodes with no dedicated range, identified via authoritative reverse DNS *.census.shodan.io / *.scanf.shodan.io. Every IP confirmed individually.
Shodan is the best-known internet scanner (US) — the search engine for internet-connected devices. Not an SEO tool. Shodan runs distributed census nodes across several hosts, with no dedicated range. They identify themselves via reverse DNS *.census.shodan.io and *.scanf.shodan.io. We confirmed every IP individually by reverse DNS. Part of our PARC Security feed.
shodan.json — view feed shodan.io →
Verification via authoritative reverse DNS
The scan IPs reverse to named nodes (soda.census.shodan.io, waffles.scanf.shodan.io …). Only the IP operator can set the reverse PTR — i.e. Shodan. That is a non-spoofable ownership proof.
Strict FCrDNS (forward back to the same IP) only works partially here: Shodan repoints its census hostnames centrally — many names forward to a collector IP while the reverse stays on the actual scan node. So we use authoritative reverse DNS as the criterion (one direction, like Infrawatch): every IP whose PTR ends in *.shodan.io.
Source & status
Seeded from our CINS blacklist (actively scanning Shodan IPs) plus the documented census nodes; stale entries (reverse no longer shodan.io today) drop out on re-verification. The feed is kept current by regular reverse re-verification.
