Guide

IP Blacklists. Get Off, Stay Off

What gets you listed on Spamhaus, how to request delisting, and how to keep a clean sending reputation long-term.

9 min read·Updated May 25, 2026
TL;DR
Getting on a blacklist takes hours; getting off takes days. The mainstream lists that actually move deliverability are Spamhaus and Barracuda, the rest are mostly noise. Listings happen because spam-trap addresses received mail from your IP, your volume spiked, or a compromised account sent spam. Fix the cause, request delisting, then warm the IP back up slowly.

What blacklists actually are

DNS-based blocklists (DNSBLs, also called RBLs) are databases of IP addresses with bad sending reputations. They're queried at SMTP time by receiving mail servers: "I see a connection from 198.51.100.42, is this IP listed on Spamhaus?" The answer comes back in milliseconds via DNS, and the receiver either accepts, defers, or rejects the connection based on the result.

They're called "DNS-based" because they use the DNS protocol to query, your IP reversed (so 198.51.100.42 becomes 42.100.51.198) gets prepended to the list's domain. 42.100.51.198.zen.spamhaus.org returning an A record means "listed"; NXDOMAIN means "clean."

Which lists actually matter in 2026

There are dozens of DNSBLs. Most of them are noise, used by nobody at scale, list IPs based on opaque criteria, and have no working removal process. The ones that genuinely affect deliverability:

  • Spamhaus ZEN (zen.spamhaus.org), the only universally significant blocklist. If you're listed here, expect Gmail, Microsoft, Yahoo, and most ISPs to bounce your mail outright. This is the one to watch.
  • Barracuda Central (b.barracudacentral.org), used heavily by enterprise mail filters running Barracuda appliances. Important if you sell to enterprise.
  • SpamCop (bl.spamcop.net), moderate influence. Auto-expires listings quickly.
  • SORBS (dnsbl.sorbs.net, spam.dnsbl.sorbs.net), historically influential, somewhat declining. Still worth watching.
  • CBL / AbuseAt (cbl.abuseat.org), actually run by Spamhaus now and feeds into ZEN. Listing here usually means imminent ZEN listing too.

The other 90+ DNSBLs out there are mostly used by individual mail admins on their personal servers. Don't lose sleep over a single listing on blacklist.someguy.net.

Note
The DomainsDoc blacklist check queries 10 of the most-influential lists in parallel. A listing on Spamhaus alone is treated as a critical alert; listings on 1–2 minor lists are warnings; clean across all 10 is the pass condition.

How IPs get listed

The mechanisms, ranked by frequency:

  1. Spam-trap hits. Blocklist operators seed inactive email addresses across the internet. If those addresses receive mail from your IP, it's strong evidence you're scraping or using bad list data. Spamhaus operates one of the largest spam-trap networks in the world.
  2. Volume spike. Your domain has historically sent 500 emails/day. Suddenly you send 50,000, a marketing campaign, a transactional bug, anything. Reputation systems treat this as anomalous and may flag the IP.
  3. Compromised account on your infrastructure. A weak SMTP password, an exposed mail-relay config, a single phished user, and your IP becomes a spammer for a few hours. Even one compromised account can land you on Spamhaus.
  4. Shared IP space. If you're on a budget VPS provider, your IP might have been used by a spammer last month. The reputation persists across owners. Always check a new IP before sending production traffic from it.
  5. Direct complaint. Some lists (SpamCop especially) accept user-submitted complaints. One legitimate user marking 10 of your messages as spam can trigger a listing.
  6. Honeypot domains in your list. Spamhaus also operates DBL (Domain Blocklist) where domains that appear in spam get listed. Different mechanism, same family of services.

Getting delisted, step by step

  1. Identify the cause first. Don't just submit a removal request, investigate. Check your sending logs for the past 7 days for: anomalous volume, mail to unfamiliar domains, queued mail buildup, login activity from unfamiliar IPs. If you can't explain why you're listed, the listing will recur.
  2. Fix the root cause. Reset SMTP credentials, suspend any account showing anomalous behavior, throttle marketing campaigns, audit your list-acquisition practices. The blacklist operators check whether you've actually fixed anything before approving removal.
  3. Use the official delisting form.
  4. Wait and warm up. Once delisted, send conservatively for 2–4 weeks. Receivers' reputation systems are independent of the blacklists, your IP "feels" recently-bad to Gmail's internal model even after Spamhaus clears you.
Watch out
Repeat offenders get tagged. Spamhaus tracks history, getting delisted three times in six months may result in permanent listing. Fix the underlying issue properly the first time.

Prevention is much cheaper than recovery

  • Authenticate everything. Strong SPF, DKIM, DMARC make it harder for compromised accounts to send convincing spam at scale.
  • Throttle outgoing volume per account. If a normal user sends 50 messages a day and one suddenly tries to send 5,000, alert and pause.
  • Use list hygiene. Confirmed opt-in only. Suppress bounces immediately. Honor unsubscribes within 24 hours. Don't email lists older than ~12 months without re-confirmation.
  • Monitor continuously. Listings happen fast, sometimes within an hour of an incident. The longer you're listed before noticing, the harder delisting becomes.

Monitoring blacklists at scale

Manual checks via the official websites are fine once. For continuous monitoring you need:

  • Parallel queries across multiple lists (sequential is too slow when checking 10+).
  • Alerting that distinguishes Spamhaus (critical) from minor lists (warning).
  • History so you can correlate listings with specific outbound traffic spikes.

DomainsDoc queries 10 DNSBLs hourly against every IP your domain resolves to. Listings get a critical alert when on Spamhaus, a warning otherwise. We don't list domains that fix the underlying issue within a few hours, only sustained listings indicate real reputation damage.

Frequently asked questions

What is a DNSBL / RBL?
A DNSBL (DNS-based Blocklist), also called an RBL (Realtime Blackhole List), is a database of IPs known for sending spam, hosting malware, or having other reputation issues. Mail receivers query these lists in real time during SMTP handshake to decide whether to accept mail from a connecting IP.
How does an IP end up on a blacklist?
Most listings come from: (1) a spam trap address received mail from your IP; (2) your IP volume spiked above historical baseline (common with marketing campaigns); (3) a compromised account on your server sent spam; (4) you share IP space with a previous owner who burned the reputation; (5) someone reported you via the blacklist's submission form.
Which blacklists actually matter?
Spamhaus (zen.spamhaus.org) is the only one that genuinely matters at scale, major receivers query it. Barracuda (b.barracudacentral.org) matters for enterprise mail. SORBS, SpamCop, and UCEProtect have varying influence. Many small lists are basically noise. Use coverage of the 10–15 mainstream lists as a leading indicator.
How do I get off a blacklist?
Different lists have different processes: (1) Spamhaus has a self-service removal form for first-time listings; repeat offenders need to explain what was fixed. (2) Most others provide a removal request form on their website. (3) Some lists auto-expire listings after 24h–7d of clean behavior. Identify the cause before requesting removal, getting relisted in a week destroys your reputation.
Should I worry about being on UCEProtect Level 3?
Mostly no. UCEProtect publishes three lists; Level 3 lists entire ASNs (i.e. your hosting provider, not you specifically). Almost no mainstream receiver uses Level 3 because it has too many false positives. Level 1 (your specific IP) is the one to actually fix.
I changed my IP and got a clean reputation. How long until receivers trust me?
New IP "warm-up" takes 2–6 weeks of low volume, gradually ramping. Sudden high volume from a fresh IP looks identical to a spammer rotating IPs. If you can use a sub-IP with established reputation (most ESPs provide this), you skip the warm-up entirely.
Try it now
Check any domain against 10+ DNSBLs

We resolve your domain to its IPs and query the major blacklists in parallel, full result in under 15 seconds.

Open tool
Stop reading. Start monitoring.

Continuous SPF, DKIM, DMARC, blacklist, SSL, and uptime checks. Alerts the moment something breaks.

Start free
Keep reading