our website traveltraeger(dot)de is currently blocked by Norton. We have verified ownership via Safe Web. The site is a legitimate online shop with no malware or phishing. Could you please manually re-evaluate and clear the rating?
We already did everything we can and our IT-department does not see any deviation from the best-practices. The categorization appeared 3 weeks ago. Unfortunately there is no information attached to norton blocking us.
@philipp412 As the site owner I suggest you submit a request for re-evaluation at this link. The detection ID shown on the detection notification is also good to add as it will help Norton determine why the site is being blocked.
https://www.abuseipdb.com/check/23.227.38.65
We resolved the domain traveltraeger.de to IP address 23.227.38.65
IP Abuse Reports for 23.227.38.65:
This IP address has been reported a total of 257 times from 54 distinct sources. 23.227.38.65 was first reported on November 20th 2025, and the most recent report was 1 day ago.
Recent Reports: We have received reports of abusive activity from this IP address within the last week. It is potentially still actively engaged in abusive activities.
what can be the reason for that? We have a pretty straightforward IT with not a lot of systems. We don’t even send newsletters out. Our transactional mails are send out via mail(dot)traveltraeger(dot)de – so I cannot believe how this result occurs – except that (idk if that can be a case) that someone is trying to harm us. As we are reaching pole position on the market we do have many competitors trying to harm us in many ways?
Thanks for all the further information you posted!
When you resolve a domain to an IP, you are finding the location of the hosting server, not the website itself. A single server (one IP) can host many different websites, and the server uses the domain name you requested to decide which website’s files to send back to you.
When you look up an IP address in GreyNoise, you are analyzing the server hardware (the host), not the website content it serves.
Websites are Passive: A website (e.g., example.com ) is content hosted on a server. It sits and waits for users to visit it; it does not actively reach out to probe other IPs across the internet.
Scanners are Active Actors: The “scanning” detected by GreyNoise is performed by active software (bots, scripts, security tools, or hackers) running on specific IP addresses. These actors systematically send packets to millions of IPs to find open ports, vulnerabilities, or services.
The Confusion: You may see website traffic in logs, but that is users visiting you. GreyNoise tracks IPs that are initiating connections to others across the entire internet, which is behavior typical of bots or attackers, not a standard website.
An “Unknown” classification means an active scanner (not a website) hit GreyNoise sensors, but its intent hasn’t been verified yet.
Passive vs. Active: Most IPs belong to end-user devices (laptops, phones, smart TVs) or servers hosting content . These are passive ; they only initiate connections to specific, intended destinations (like loading a webpage or checking email) and do not systematically probe the entire internet.
Scanners are Rare: Internet scanning is a specialized, high-volume activity where an IP sends packets to millions of other addresses to map the network or find vulnerabilities. This is typically done by:
Search Engines (e.g., Googlebot, Bingbot).
Security Companies (e.g., GreyNoise, Shodan, Censys) mapping the attack surface.
Malicious Actors (botnets, hackers) looking for exploits.
The “Unknown” Context : If an IP is labeled Unknown by GreyNoise, it means it is actively scanning (unlike your home IP), but GreyNoise hasn’t yet identified who is doing it or why. If your IP were scanning the internet indiscriminately, it would likely appear in these datasets too.
IP = The Server: An IP address identifies a specific network interface on a physical or virtual machine. This machine hosts the website, but the IP itself represents the connection point, not the domain name (like google.com) or the web pages.
One IP, Many Websites : A single IP address often hosts hundreds or thousands of different websites (via virtual hosting). GreyNoise sees the IP’s behavior across all those sites and any other services running on that server (like email or database ports).
Why This Matters for “Unknown”: If that server IP is flagged as Unknown, it means the server itself is actively scanning other parts of the internet. This could indicate:
The server is compromised and part of a botnet.
The hosting provider is running security scans from that IP.
It is a cloud instance performing legitimate but unverified network mapping.
The website content is irrelevant to the scan; GreyNoise is tracking the outbound behavior of the host machine identified by that IP.
OMG! I would much appreciate not being berated with AI about valid results, When I use GreyNoise the results are against MY IP, not my ISP IP structure nor its hardware. Not even the domain I use for DNS. In the instance of the OP the IP we are using **IS the IP for the website and machine as its hosted on **. Please do your homework.