IP Blacklists. Get Off, Stay Off
What gets you listed on Spamhaus, how to request delisting, and how to keep a clean sending reputation long-term.
What blacklists actually are
DNS-based blocklists (DNSBLs, also called RBLs) are databases of IP addresses with bad sending reputations. They're queried at SMTP time by receiving mail servers: "I see a connection from 198.51.100.42, is this IP listed on Spamhaus?" The answer comes back in milliseconds via DNS, and the receiver either accepts, defers, or rejects the connection based on the result.
They're called "DNS-based" because they use the DNS protocol to query, your IP reversed (so 198.51.100.42 becomes 42.100.51.198) gets prepended to the list's domain. 42.100.51.198.zen.spamhaus.org returning an A record means "listed"; NXDOMAIN means "clean."
Which lists actually matter in 2026
There are dozens of DNSBLs. Most of them are noise, used by nobody at scale, list IPs based on opaque criteria, and have no working removal process. The ones that genuinely affect deliverability:
- Spamhaus ZEN (
zen.spamhaus.org), the only universally significant blocklist. If you're listed here, expect Gmail, Microsoft, Yahoo, and most ISPs to bounce your mail outright. This is the one to watch. - Barracuda Central (
b.barracudacentral.org), used heavily by enterprise mail filters running Barracuda appliances. Important if you sell to enterprise. - SpamCop (
bl.spamcop.net), moderate influence. Auto-expires listings quickly. - SORBS (
dnsbl.sorbs.net,spam.dnsbl.sorbs.net), historically influential, somewhat declining. Still worth watching. - CBL / AbuseAt (
cbl.abuseat.org), actually run by Spamhaus now and feeds into ZEN. Listing here usually means imminent ZEN listing too.
The other 90+ DNSBLs out there are mostly used by individual mail admins on their personal servers. Don't lose sleep over a single listing on blacklist.someguy.net.
How IPs get listed
The mechanisms, ranked by frequency:
- Spam-trap hits. Blocklist operators seed inactive email addresses across the internet. If those addresses receive mail from your IP, it's strong evidence you're scraping or using bad list data. Spamhaus operates one of the largest spam-trap networks in the world.
- Volume spike. Your domain has historically sent 500 emails/day. Suddenly you send 50,000, a marketing campaign, a transactional bug, anything. Reputation systems treat this as anomalous and may flag the IP.
- Compromised account on your infrastructure. A weak SMTP password, an exposed mail-relay config, a single phished user, and your IP becomes a spammer for a few hours. Even one compromised account can land you on Spamhaus.
- Shared IP space. If you're on a budget VPS provider, your IP might have been used by a spammer last month. The reputation persists across owners. Always check a new IP before sending production traffic from it.
- Direct complaint. Some lists (SpamCop especially) accept user-submitted complaints. One legitimate user marking 10 of your messages as spam can trigger a listing.
- Honeypot domains in your list. Spamhaus also operates DBL (Domain Blocklist) where domains that appear in spam get listed. Different mechanism, same family of services.
Getting delisted, step by step
- Identify the cause first. Don't just submit a removal request, investigate. Check your sending logs for the past 7 days for: anomalous volume, mail to unfamiliar domains, queued mail buildup, login activity from unfamiliar IPs. If you can't explain why you're listed, the listing will recur.
- Fix the root cause. Reset SMTP credentials, suspend any account showing anomalous behavior, throttle marketing campaigns, audit your list-acquisition practices. The blacklist operators check whether you've actually fixed anything before approving removal.
- Use the official delisting form.
- Spamhaus: check.spamhaus.org, they accept self-service removal for first listings.
- Barracuda: barracudacentral.org/rbl/removal-request, manual review, usually 24-48h.
- SpamCop: typically auto-expires within 24h of clean behavior.
- SORBS: form-based, often slow (days to weeks).
- Wait and warm up. Once delisted, send conservatively for 2–4 weeks. Receivers' reputation systems are independent of the blacklists, your IP "feels" recently-bad to Gmail's internal model even after Spamhaus clears you.
Prevention is much cheaper than recovery
- Authenticate everything. Strong SPF, DKIM, DMARC make it harder for compromised accounts to send convincing spam at scale.
- Throttle outgoing volume per account. If a normal user sends 50 messages a day and one suddenly tries to send 5,000, alert and pause.
- Use list hygiene. Confirmed opt-in only. Suppress bounces immediately. Honor unsubscribes within 24 hours. Don't email lists older than ~12 months without re-confirmation.
- Monitor continuously. Listings happen fast, sometimes within an hour of an incident. The longer you're listed before noticing, the harder delisting becomes.
Monitoring blacklists at scale
Manual checks via the official websites are fine once. For continuous monitoring you need:
- Parallel queries across multiple lists (sequential is too slow when checking 10+).
- Alerting that distinguishes Spamhaus (critical) from minor lists (warning).
- History so you can correlate listings with specific outbound traffic spikes.
DomainsDoc queries 10 DNSBLs hourly against every IP your domain resolves to. Listings get a critical alert when on Spamhaus, a warning otherwise. We don't list domains that fix the underlying issue within a few hours, only sustained listings indicate real reputation damage.
Frequently asked questions
What is a DNSBL / RBL?
How does an IP end up on a blacklist?
Which blacklists actually matter?
How do I get off a blacklist?
Should I worry about being on UCEProtect Level 3?
I changed my IP and got a clean reputation. How long until receivers trust me?
We resolve your domain to its IPs and query the major blacklists in parallel, full result in under 15 seconds.
Continuous SPF, DKIM, DMARC, blacklist, SSL, and uptime checks. Alerts the moment something breaks.