Your domain's on a blocklist. Which ones actually matter?
A blacklist checker lit up red and you're panicking. Most of those listings never touch your mail. Here's which blocklists actually gate delivery, and how to get delisted.
You ran a blocklist check, and it came back with a wall of red. Eight, ten, fifteen lists you've never heard of, all flagging your domain or your sending IP. Your stomach drops. You start googling delist forms for every one of them.
Stop. Most of that red is noise. The multirbl.valli.org registry tracks 892 zones. Only 304 still answer, and just 240 of those are blocklists rather than whitelists or informational feeds1. The number that meaningfully decide whether your mail reaches an inbox is closer to three. Being on a list nobody consults is not a problem. Being on one specific list is an emergency. Which blacklists actually matter is the only question worth asking, and a red row on a checker doesn't answer it on its own.
Short answer: if you're listed on Spamhaus, drop what you're doing and fix it. If you're listed on some list you had to look up to identify, and Spamhaus is clean, you can almost certainly ignore it. The rest of this post is how to tell those two situations apart, and what to actually do about the first one.
Why are you on a blocklist you've never heard of?
Because anyone can run a DNS blocklist, and plenty of them list aggressively to stay relevant.
The classic example is UCEPROTECT. Their Level 1 list is fair enough, it names the specific IP that misbehaved16. Level 2 escalates to the surrounding allocation. The block it picks is not a fixed size: anything smaller than a /27 goes on after a single impact, a /26 after two, a /25 after three, a /24 after four, and bigger blocks by a published formula whose own worked examples run all the way up to a /102. So "the neighbours" might mean 32 addresses or several million.
Level 3 goes further and lists the whole ASN. UCEPROTECT divides an AS's Level 1 impacts by its total IP count, multiplies by 100,000, and calls that a SPAMSCORE. At 50 or above the AS gets listed, provided its addresses racked up at least 50 Level 1 impacts in the past seven days3. Rent a VPS from a provider having a bad week and you can be listed on day one, having sent nothing.
There is a paid way out, with conditions. UCEPROTECT says a Level 1 listing expires seven days after the last detected abuse "and FREE of charge", and that the most common lie told about them is that you have to pay to be removed. The payment option only buys you the wait: it is "available for any listee that does not want to wait 7 days but needs to be de-listed immediately", and only when none of five disqualifying conditions apply. Two of those five are about exactly the situation that brought you here, an AS in the top five of the Level 3 charts, and Level 2 or 3 listings that are still growing4. So the escape hatch is shut precisely when the listing is worst.
That's the pattern to recognise. A list that flags you for your neighbour's behaviour is close to useless as a filtering signal, and a list the big receivers don't query has no effect on your delivery whatever it says. It just makes a checker look alarming.
Our take: the number of blocklists you're on is a meaningless metric. One listing on a list receivers trust outweighs a dozen on lists they ignore. Count the reputation of the lists, not the lists.
Which blocklists actually gate delivery?
A short list. The blocklists that gate real delivery are Spamhaus (via its combined Zen list), Barracuda's BRBL, and Invaluement. Monitor those and you've covered the ones that move mail. Everything else is largely background noise.
Spamhaus is the one that matters most, by a wide margin. It runs several lists, and each answers with its own return code so a receiver can tell them apart5:
- Spamhaus SBL (Block List): IP addresses of spam sources, which Spamhaus spells out as "known spammers, spam gangs, spam operations and spam support services"15. Returns
127.0.0.2. - Spamhaus CSS: published inside the SBL zone, and launched to catch snowshoe spam6. Spamhaus calls it "an automatically produced dataset" that "mostly targets static spam emitters but may also include other senders that display a risk to our users, such as compromised hosts"14. This is the one that catches people without warning, because it lists on sending behaviour rather than a manual report, and you often don't know why. Returns
127.0.0.3. - Spamhaus XBL: hijacked machines. Spamhaus describes them as addresses that are legitimate but "have been hijacked to use by third-party exploits"7. Returns
127.0.0.4. - Spamhaus PBL (Policy Block List): end-user IP ranges that should never send mail directly to the destination, like residential and dynamic address space8. Being on the PBL is normal for a home connection. It only bites if you're trying to send mail straight from an IP that was never meant to. Returns
127.0.0.10or127.0.0.11. - Spamhaus DBL (Domain Block List): the domain one. It lists domains and nothing else. Spamhaus is explicit: "No IP addresses are listed in the DBL"9. This is why a domain with a spotless sending IP can still get filtered.
Zen is the combined IP list. Spamhaus calls it "the combination of all Spamhaus' free IP-based DNSBLs into one single powerful and comprehensive blocklist… It contains the SBL, CSS, XBL, and PBL blocklists"10. One query, four lists, which is why Spamhaus points operators at it: "to make querying faster and simpler". Two other lists carry real weight with specific receivers. Barracuda's BRBL matters wherever a Barracuda gateway is doing the filtering, though it is a setting an administrator switches on rather than an always-on default, which Barracuda "strongly recommended" they do11. Invaluement is a subscription list, sold as a supplement to Spamhaus and reached by rsync or direct query; they publish no price, only "The pricing is very affordable, and we offer a free 7-day trial"12. We can't source which receivers run it, so its place on this list is our judgement. And no free checker, ours included, can tell you whether you're on it.
SORBS used to appear on every checker. It was shut down by its owner Proofpoint in June 2024, "decommissioned on June 5, 2024", with its 18 zones "emptied of information"13. It lists nothing now. Ask dnsbl.sorbs.net or spam.sorbs.net for an SOA today and you get no answer at all. If a tool still shows you a SORBS result, the tool is out of date, not your domain.
How does a domain end up listed, not just an IP?
This is the part that catches self-hosters and lab setups off guard: the domain gets listed, the mail stops, and every IP check comes back green.
Most blocklists list IP addresses. The Spamhaus DBL lists domain names, and it can list yours without your domain ever having sent an email itself. Nobody outside Spamhaus can tell you why: "We do not discuss the specific criteria we use"9. They do publish the reputation guidance behind those criteria, and three lines of it explain most of the surprises. An unknown domain starts out bad, because "unknown reputations begin as 'poor' by default". Hosting counts, and "'Clean' includes a domain's NS, A, MX and website DNS records". And "domains which act like they are snowshoeing will get treated like snowshoers"9.
So a lab domain registered last week, sitting in a range with a bad neighbourhood, is already most of the way there. The DBL has a whole set of "abused legit" return codes for domains that aren't malicious but are being treated with suspicion. 127.0.1.102 is abused legit spam, 127.0.1.103 an abused spammed redirector, 127.0.1.104 abused legit phish, with two more for malware and botnet C&C9.
The point is that domain reputation and IP reputation are two separate ledgers. You can pass every blocklist check on your IP and still be filtered because your domain is listed, and a lot of people burn a day looking at the wrong ledger.
I'm on Spamhaus. How do I actually get off?
Fix the cause first, request removal second. Do it in that order or you'll be back on within a day.
A Spamhaus listing is a symptom. Something on your side sent spam, got compromised, or looked enough like a spammer to trip an automated list. If you request delisting without finding and fixing that, Spamhaus relists you, and repeated listings dig the hole deeper because the pattern itself becomes the reason.
- SBL / CSS (your IP): find what sent the spam. A compromised account, an open relay, a script blasting a stale list, a forwarded stream carrying spam through you. Shut it down, confirm it's actually stopped, then use the removal form at check.spamhaus.org. CSS listings expire on their own three days after the last detection, so a genuinely fixed problem clears itself; self-removals exist but are limited, and CSS relists immediately if the behaviour is still there14.
- PBL (your IP): this one's usually not a problem to solve, it's a signal you're sending from the wrong place. Spamhaus does allow it: "If the Policy for a particular network allows it, end users can have their IP excluded from PBL"8, through the same check.spamhaus.org page. But the better answer is often to relay through a proper smarthost instead of sending direct from an IP the internet expects to stay quiet.
- DBL (your domain): stop whatever got the domain listed, which usually means removing the spammy content or securing whatever was abused, then request removal through the same Spamhaus portal. A newly-registered domain sometimes just needs history: Spamhaus says that if domains "are used in legitimate traffic for enough time to establish a good reputation, DBL will notice that and remove the listing"9.
The delisting itself is free and fast on Spamhaus. They put it bluntly: "There is never any charge or fee associated with removing any Spamhaus listing. Any offer from anyone to remove any Spamhaus listing for a fee is a scam"9. So anyone selling you a guaranteed Spamhaus delisting is either lying or charging you for something Spamhaus does for nothing. (A deliverability consultant billing for the work of finding and fixing the root cause is a different thing, and can be worth it. Paying for the delisting click is not.) That's a useful line between the list that matters and the ones that monetise the panic.
How do I tell a real listing from noise?
Read which lists flagged you, not how many.
Run your domain and your sending IP through TamingDNS's blacklist checker. It tells you which specific list hit and what that list's return code means, so you can see at a glance whether Spamhaus is in the red or whether it's just a scatter of vanity lists. A clean Spamhaus result with three obscure lists lit up is a good day dressed up to look like a bad one. The /rbl directory is the companion reference: one page per list, with its return codes and its delisting process.
Run the lookup by hand and Spamhaus may refuse to answer you. Free use of its zones is conditional on the query "not being made from a public resolver or an IP with generic rDNS". Break that rule and the answer is 127.255.255.254, which Spamhaus glosses as "Query via public/open resolver" and files among the codes that "must not be taken to imply that the object of the query is 'listed'"5. It publishes 127.0.0.2 as a target known to be listed, so a healthy lookup answers 127.0.0.4, 127.0.0.2 and 127.0.0.105. As it resolved on 2026-09-06, from a Mac using whichever resolver its network handed it:
$ dig +short A 2.0.0.127.zen.spamhaus.org
127.255.255.254
$ dig +short txt whoami.fastly.net
"resolver: 104.22.165.36"
The second command is Spamhaus's own diagnostic, and it explains the first. That address belongs to Cloudflare, not to this network. The query is reaching Spamhaus through a public resolver even though nothing here was set to use one. Spamhaus declined to answer. A home-brew check that reads any answer as a hit calls that a listing; one that reads "not a listing code" as clean calls it clean. Both are wrong.
Run it more than once, too. Spamhaus warns that the path to a public resolver varies, and the answers vary with it. On the same morning @1.1.1.1 refused on all three runs, while @8.8.8.8 returned the real listing codes on three runs out of five and nothing at all on the other two5. An empty answer is indistinguishable from a clean IP, so a refusal reads as a pass. Every checker queries through some resolver and lives under the same terms, ours included. When Spamhaus declines, the honest row reads "unavailable", not a green tick.
Enter the sending IP itself, not just the domain. A domain scan checks the domain against the domain lists, but its IP-side checks use the domain's A record. For most domains that is the web server, not the machine that sends your mail.
If your IP is the problem, two more checks tell you why. The reverse-DNS lookup confirms your sending IP has a valid PTR record with matching forward and reverse DNS, which is the single most common reason a legitimate self-hosted server gets treated as suspicious. And IP info shows you the network and ASN your IP sits in, so you can see whether you've rented space in a bad neighbourhood before you invest a week warming it up.
Hundreds of blocklists exist and about three decide your mail's fate. The skill isn't checking more lists, it's knowing which red actually costs you delivery.
So what do I actually do about it?
When a checker lights up red, work it in this order:
- Check Spamhaus specifically, on both your domain and your sending IP. This is the yes/no that matters. Everything else is secondary.
- If Spamhaus is clean and only obscure lists are red, note it and move on. You don't have a delivery problem, you have an alarming-looking checker.
- If Spamhaus is red on your IP, find what sent the spam, shut it down, confirm it stopped, then submit the free removal at check.spamhaus.org.
- If Spamhaus is red on your domain (DBL) but your IP is clean, you're looking at the wrong ledger, fix the domain-side cause and delist the domain.
- Check your PTR / reverse DNS if you self-host. A missing or mismatched PTR gets you filtered with every blocklist green, and it's a five-minute fix with your host.
- Never pay to delist. The lists that matter remove you for free. The ones that charge are the ones you can ignore.
Being on a blocklist feels like an emergency because the tools present every listing with the same red. It isn't. Read the names, check Spamhaus, and most of that wall of red turns out to be nothing that was ever going to touch your mail.
If the red turns out to be real and mail is landing in spam even with Spamhaus clean, the problem is reputation rather than a listing, and our piece on why mail passes every check and still lands in spam is the next place to look. And if you're running your own mail server, the reverse-DNS and IP-neighbourhood traps above are only the start of the deliverability gauntlet, which is a post of its own, coming shortly.
Run a free blocklist check on your domain.
What this article was checked against
- How many DNSBL zones exist, and how many still answer. multirbl.valli.org zone list: the page's own section headings read "alive (304)" and "dead (588)", 892 in total, as it stood on 2026-09-06. Counting the type column on that page, the 892 break down as 775 blocklists, 63 whitelists, 36 informational and 18 combined/scoring zones; of the 304 live ones, 240 are blocklists. The article quotes the blocklist figure rather than the headline total, because the total counts whitelists too. ↩
- That UCEPROTECT Level 2 lists an allocation, not a fixed /24. UCEPROTECT Blacklist Policy Level 2, whose description line reads "Strict Level 2 escalates within allocation": "Allocations smaller than /27 are automatically listed immediately in level 2 if a single impact has occurred, a /26 network is listed for at least 2 impacts, and a /25 for at least 3 impacts", then "Based on the /24 network with 4 or more impacts, the further automatic escalation is calculated using the following formula", whose worked examples cover a /23 and a /10. ↩
- The Level 3 ASN listing threshold and the SPAMSCORE formula. UCEPROTECT Blacklist Policy Level 3: "automatically lists all IPs assigned to an AS number as soon as its SPAMSCORE is 50 or higher, and… at least 50 impacts of IPs which are assigned to the AS number have been listed in level 1 in the last 7 days." The formula is given on the same page as "(Level 1 impacts from this ASN / total IPs in this ASN) * 100000", rounded to one decimal place. UCEPROTECT counts impacts, not distinct addresses, so this article says impacts too. ↩
- The paid express-delisting terms, and the conditions that disqualify you from them. uceprotect.net front page, removal terms, read on 2026-09-05: "Every IP listed will expire 7 days after the LAST abuse is detected, and FREE of charge"; "Only if these 5 criteria do not apply, there is a payment option available for any listee that does not want to wait 7 days but needs to be de-listed immediately." Criterion 4 is "If an AS is listed in Level 3 and it is in the top 5 of the Level 3 charts" and criterion 5 "If the listings in Level 2 or 3 are still increasing". No price is published on their site, so none is quoted here, and their page does not say what an express delisting does to an ASN-level listing, so that is not asserted either. ↩
- Every Spamhaus return code quoted in this article, and the free-use condition on public resolvers. Spamhaus DNSBL usage FAQ. 127.0.0.2 SBL, .3 CSS, .4 XBL/CBL, .9 DROP, .10 PBL ISP-maintained, .11 PBL Spamhaus-maintained, plus the error codes 127.255.255.252/.254/.255, which "must not be taken to imply that the object of the query is 'listed'". The same page sets the free-use terms: the zones "can be used free of charge by querying 'zen.spamhaus.org', if: Use of the Spamhaus DNSBLs is non-commercial and 2. Queries are not being made from a public resolver or an IP with generic rDNS", and it glosses 127.255.255.254 as "Query via public/open resolver". The PBL page states the same two PBL codes without mapping which is which, so the mapping above is the FAQ's. The same page is the source for 127.0.0.2 being a known-listed target and for the expected answer: it prescribes "Command-line DNS queries for a target known to be listed in a Spamhaus zone (127.0.0.2)" and gives "The normal results you should see if everything is working are: 127.0.0.4 127.0.0.2 127.0.0.10". It supplies the
whoami.fastly.netdiagnostic verbatim, "Run this at the command line to find out which resolver is being used: $ dig txt whoami.fastly.net", and the advice to repeat the query: "Try the commands a few times to confirm the results stay the same. (Sometimes paths to public DNS resolvers are variable, and the results could differ depending on the path.)" The runs quoted in the article were made on 2026-09-06: 8.8.8.8 five times, 1.1.1.1 three times;whois 104.22.165.36returns OrgName "Cloudflare, Inc.". Note also that free use is limited to "low-volume non-commercial use", which is a question for whoever operates a checker rather than for the reader of one. ↩ ↩ ↩ ↩ - That CSS is published inside the SBL zone, its return code, and that it was launched against snowshoe spam. Announcing the Spamhaus CSS, October 2009: "The CSS will be included in sbl.spamhaus.org zone, and in the combined blocklist zones at sbl-xbl.spamhaus.org and zen.spamhaus.org as well. It will return a unique result code, 127.0.0.3". An earlier draft of this article also had CSS covering "static spam emitters the PBL and XBL don't cover"; that page says nothing of the sort, and describes the snowshoe problem as spam "not from compromised IP addresses or botnet ranges, but from static IP address ranges", so the claim was cut and the description re-sourced to the CSS FAQ. ↩
- What the XBL actually lists. Spamhaus Exploits Blocklist: "individual IPv4 and IPv6 addresses exhibiting signs of compromise i.e. IPs that are legitimate but have been hijacked to use by third-party exploits." An earlier draft of this article also credited the XBL with open proxies; Spamhaus's current description does not, so it was cut. ↩
- What the PBL lists, and that end users can self-remove. Spamhaus Policy Blocklist: "a dataset containing end-user IP address ranges from which email should never be sent directly to the final destination", and "If the Policy for a particular network allows it, end users can have their IP excluded from PBL." ↩ ↩
- That the DBL lists domains only, its abused-legit codes, and that Spamhaus never charges for removal. Spamhaus Domain Blocklist: "It ONLY lists domains. No IP addresses are listed in the DBL"; return codes 127.0.1.102 through 127.0.1.106 for the abused-legit categories; and on fees, "There is never any charge or fee associated with removing any Spamhaus listing." The same page names
dbltest.comas the permanent DBL test entry. On why a domain gets listed it says "We do not discuss the specific criteria we use", and its general-observations section supplies the three lines quoted here: "unknown reputations begin as 'poor' by default"; "'Clean' includes a domain's NS, A, MX and website DNS records"; "Domains which act like they are snowshoeing will get treated like snowshoers"; and on ageing out, "If domains are used in legitimate traffic for enough time to establish a good reputation, DBL will notice that and remove the listing." ↩ ↩ ↩ ↩ ↩ ↩ - What ZEN combines. Spamhaus ZEN: "ZEN is the combination of all Spamhaus' free IP-based DNSBLs into one single powerful and comprehensive blocklist to make querying faster and simpler. It contains the SBL, CSS, XBL, and PBL blocklists." ↩
- Where a BRBL listing actually applies, and that the zone is live. Barracuda Email Gateway Defense documentation: Barracuda Reputation is "a database maintained by Barracuda Central [that] includes a list of IP addresses of known good senders as well as known spammers, or IP addresses with a 'poor' reputation", and on the Inbound Settings page "it is strongly recommended that you select Use Barracuda Reputation Block List (BRBL)". It is a recommended setting with per-IP exemptions, not an always-on default, which is why the effect depends on the receiver. Zone confirmed live on 2026-09-05:
dig +short A 2.0.0.127.b.barracudacentral.orgreturns127.0.0.2. barracudacentral.org itself returns 403 to automated requests, so nothing here rests on that page. ↩ - That Invaluement is a paid list, and what it does not say about its users. invaluement.com, read on 2026-09-05: "The pricing is very affordable, and we offer a free 7-day trial", access is by "rsync or direct query", and the IP lists are pitched as "an especially excellent supplement to Spamhaus". No figure is published, so none is quoted. The page carries individual testimonials but names no receiver, ISP or filtering vendor that runs the list, so this article no longer claims one. ↩
- That SORBS shut down in June 2024 under Proofpoint, and that its zones are dead. The Register, 7 June 2024: "SORBS was decommissioned on June 5, 2024, and the service no longer contains reputation data", its zones "emptied of information". Confirmed live on 2026-09-05:
dig +short SOA dnsbl.sorbs.netanddig +short SOA spam.sorbs.netboth return nothing. ↩ - What CSS actually targets, that its listings expire on their own, and how self-removal behaves. Spamhaus CSS FAQ: "The Spamhaus CSS list is an automatically produced dataset of IP addresses that are involved in sending low-reputation email. CSS mostly targets static spam emitters but may also include other senders that display a risk to our users, such as compromised hosts"; "CSS listings generally expire three (3) days after the last detection. In some cases of chronic abuse, the listings can last longer"; and that "Self-removals are limited" and CSS "will also re-list it immediately if a problem continues to be detected". ↩ ↩
- What the SBL lists. Spamhaus Blocklist (SBL): "The Spamhaus Block List (SBL) is a realtime database of IP addresses of spam sources, including known spammers, spam gangs, spam operations and spam support services." ↩
- That UCEPROTECT Level 1 lists the individual offending IP, not a block. UCEPROTECT Blacklist Policy Level 1, description line "Conservative Level 1 lists single IP's only", and in the body "our Level 1 policy only contains single IP addresses [ /32], which were used by spammers / abusers". Read on 2026-09-06. ↩