Skip to content
Mail servers and blacklists

Get a mail server off a blacklist

What a DNS blacklist listing means, when it matters, how to find and stop the cause, and how to request removal without paying anyone.

By the Domain Health Hub team · Updated

In short
  • A DNS blacklist (DNSBL) lists IP addresses seen sending spam. Receivers use them to reject or filter email.
  • We check the domain's mail servers and the sending servers in its DMARC reports, daily, on PSBL, SpamCop, Mailspike and Barracuda.
  • Stop the cause first, then request removal on the list's own site. Never pay for delisting.

What this means

A DNS blacklist is a list of IP addresses that have recently sent spam or shown other abuse. Receiving mail servers look up the connecting address, and a listed one may have its email rejected or sent to spam. We check two sets of addresses daily: the domain's own mail servers, and the servers that send as the domain according to its DMARC reports.

PSBL
Passive Spam Block List. Self-service removal.
SpamCop
Listings expire by themselves within a day or so of the spam stopping.
Mailspike
Reputation-based list with a removal request page.
Barracuda
Used by Barracuda's filters. Removal request form on its site.

Shared provider servers

If the listed address belongs to a big provider such as Microsoft 365 or Google, it is shared by thousands of customers. The provider handles delisting; there is nothing the domain owner can do, and we show it as information that doesn't affect the grade.

Finding the cause

Removal without fixing the cause just means being listed again. Common causes for a small organisation:

  • A compromised email account sending spam. Reset its password, sign out all sessions, turn on two-factor sign-in, and check for forwarding rules the attacker added.
  • A website form abused to send spam, such as a contact form that emails a copy to whatever address is typed in. Add a captcha or stop sending copies.
  • An infected computer or device on the office network sending directly. Check the firewall for outbound port 25 traffic.
  • A shared web host where another customer is sending spam. Ask the host, or send email through your email provider instead of the web server.

Requesting removal

Once the cause is fixed, look the address up on the list's own website and follow its removal process. PSBL, Mailspike and Barracuda have removal requests; SpamCop listings drop off by themselves 24 hours after the last spam report. Removal usually takes from a few hours to a day and a half. Ignore anyone offering paid delisting.

Domain Health Hub re-checks every listed address daily, alerts you when a domain is newly listed, and lets you mark a listing as ignored if you've reviewed it and it doesn't matter.

How a list is queried (for 203.0.113.10)
10.113.0.203.bl.spamcop.net  A  ?
# An answer such as 127.0.0.2 means listed; no answer means not listed.

Questions

Why don't you check Spamhaus?

Spamhaus's free service is for non-commercial, low-volume use only, so a commercial service like ours can't use it without a paid licence.

A list wants payment to remove us. Should we pay?

Not for any list we check: they all offer free removal or expire listings on their own. We leave out lists that charge for delisting. If one of those has listed you, fix the cause first; listings there usually lapse once the problem stops.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial