VMHeaven

Free tool

IP and domain blacklist check

Check an IP address or a domain's mail servers against eight public DNS blocklists, with each list's reason and removal page — only lists whose terms allow it.

Check an address or a domain

Try:

A domain stands for its mail servers: up to three addresses, the MX hosts’ IPv4 addresses first.

Asked from our test server in Amsterdam, straight at each list’s own name servers. The lists see the address that is checked; results are kept for ten minutes.

The lists, and why these

Every list here allows free use of this kind in its own terms, and each is asked within them: results are kept for ten minutes, and all visitors together can check at most 2,000 new addresses a day.

ListWhat gets an address listed
SpamCopMail that SpamCop users reported as spam; entries expire on their own
PSBLMail to its spam traps from addresses that are not known mail servers; anyone can remove an address
UCEPROTECT Level 1Spam-trap hits from the single address (Levels 2 and 3, which list whole networks, are not asked)
BackscattererBounces and auto-replies sent to forged sender addresses
DroneBLOpen proxies, botnet drones, DDoS sources and brute-force attackers
NordSpamSpam sent to its traps and partners
blocklist.deAttacks on its partners' servers (SSH, mail and web logins) in the last 48 hours
0spamSpam-trap hits and user reports

Spamhaus and Barracuda are missing on purpose, because of their terms — the FAQ below says why.

How the check asks

A blocklist is a DNS zone. To ask whether 203.0.113.7 is listed, a server looks up the address with its parts reversed in front of the list’s zone; an answer in 127.0.0.0/8 means listed, “no such name” means not. Every list answers its test entry, 127.0.0.2, as listed — this check asks for it every hour and reports a list that stops answering as offline instead of as “not listed”.

Linux · macOS
dig +short 7.113.0.203.bl.spamcop.net     # empty: not listed
dig +short 2.0.0.127.bl.spamcop.net       # 127.0.0.2: the test entry
dig +short TXT 2.0.0.127.bl.spamcop.net   # the list's reason

Some lists refuse questions that arrive through large public resolvers and answer them with a code of their own; this check asks each list’s name servers directly from our test server in Amsterdam, which also means the lists see the address being checked.

Getting an address off a list

  1. 1Find the cause

    The reason a list gives points the way: spam traps and user reports mean mail went out from the address — a hacked mailbox, a website form or script, an open relay; attack lists mean something on the address scanned or tried passwords on other servers.

  2. 2Stop it, and close the hole

    Change the passwords involved, remove the script or malware, and close what was open. Removing a listing while the cause is still there gets the address listed again within hours.

  3. 3Ask for removal, or wait

    Follow each list’s removal link. Many lists expire entries by themselves once nothing new arrives; the results say which.

Most compromised servers started with a guessed password: securing SSH access closes the usual way in.

Frequently asked

What is a DNS blocklist (DNSBL)?

A list of IP addresses seen sending spam, attacking servers or acting as open proxies, published through DNS so that a mail server can ask about the address connecting to it in one quick lookup. Each list has its own rules for what gets an address listed and how it comes off again; the result for each list here says what that list contains.

My IP address is listed. What now?

Find and stop the cause first: a hacked mail account or website, a script sending mail, an open relay or proxy, malware on a machine behind the address. Then follow the removal link of each list — many expire entries on their own once nothing new arrives. A new server can inherit an address a previous user got listed, so check right after you receive one.

Why are Spamhaus and Barracuda not checked?

Their terms do not allow it here. Spamhaus offers free lookups only for non-commercial use with low volume, and Barracuda only answers DNS servers registered with it in advance. The results link both lists' own lookup pages, where you can check an address yourself.

Does a listing mean my mail is blocked?

Only by receivers that use that list. Large mailbox providers decide mostly with their own reputation data, while many company and self-hosted mail servers check one or more public lists. A listing on a list that targets attackers, such as blocklist.de, matters for logins and firewalls more than for mail.

What does checking a domain do?

It looks up the domain's mail servers and checks up to three addresses: the IPv4 addresses of the first three MX hosts, then their IPv6 addresses, and the domain's own address only when that gives fewer than three. The result names any address it left out, so you can check it on its own. If your mail goes out through a provider such as Google Workspace or Microsoft 365, the sending addresses are the provider's, and their reputation is the provider's to manage.

Related guides

More free tools

All tools