The lists, and why these
Every list here allows free use of this kind in its own terms, and each is asked within them: results are kept for ten minutes, and all visitors together can check at most 2,000 new addresses a day.
| List | What gets an address listed |
|---|---|
| SpamCop | Mail that SpamCop users reported as spam; entries expire on their own |
| PSBL | Mail to its spam traps from addresses that are not known mail servers; anyone can remove an address |
| UCEPROTECT Level 1 | Spam-trap hits from the single address (Levels 2 and 3, which list whole networks, are not asked) |
| Backscatterer | Bounces and auto-replies sent to forged sender addresses |
| DroneBL | Open proxies, botnet drones, DDoS sources and brute-force attackers |
| NordSpam | Spam sent to its traps and partners |
| blocklist.de | Attacks on its partners' servers (SSH, mail and web logins) in the last 48 hours |
| 0spam | Spam-trap hits and user reports |
Spamhaus and Barracuda are missing on purpose, because of their terms — the FAQ below says why.
How the check asks
A blocklist is a DNS zone. To ask whether 203.0.113.7 is listed, a server looks up the address with its parts reversed in front of the list’s zone; an answer in 127.0.0.0/8 means listed, “no such name” means not. Every list answers its test entry, 127.0.0.2, as listed — this check asks for it every hour and reports a list that stops answering as offline instead of as “not listed”.
dig +short 7.113.0.203.bl.spamcop.net # empty: not listed
dig +short 2.0.0.127.bl.spamcop.net # 127.0.0.2: the test entry
dig +short TXT 2.0.0.127.bl.spamcop.net # the list's reasonSome lists refuse questions that arrive through large public resolvers and answer them with a code of their own; this check asks each list’s name servers directly from our test server in Amsterdam, which also means the lists see the address being checked.
Getting an address off a list
- 1Find the cause
The reason a list gives points the way: spam traps and user reports mean mail went out from the address — a hacked mailbox, a website form or script, an open relay; attack lists mean something on the address scanned or tried passwords on other servers.
- 2Stop it, and close the hole
Change the passwords involved, remove the script or malware, and close what was open. Removing a listing while the cause is still there gets the address listed again within hours.
- 3Ask for removal, or wait
Follow each list’s removal link. Many lists expire entries by themselves once nothing new arrives; the results say which.
Most compromised servers started with a guessed password: securing SSH access closes the usual way in.
Frequently asked
What is a DNS blocklist (DNSBL)?
A list of IP addresses seen sending spam, attacking servers or acting as open proxies, published through DNS so that a mail server can ask about the address connecting to it in one quick lookup. Each list has its own rules for what gets an address listed and how it comes off again; the result for each list here says what that list contains.
My IP address is listed. What now?
Find and stop the cause first: a hacked mail account or website, a script sending mail, an open relay or proxy, malware on a machine behind the address. Then follow the removal link of each list — many expire entries on their own once nothing new arrives. A new server can inherit an address a previous user got listed, so check right after you receive one.
Why are Spamhaus and Barracuda not checked?
Their terms do not allow it here. Spamhaus offers free lookups only for non-commercial use with low volume, and Barracuda only answers DNS servers registered with it in advance. The results link both lists' own lookup pages, where you can check an address yourself.
Does a listing mean my mail is blocked?
Only by receivers that use that list. Large mailbox providers decide mostly with their own reputation data, while many company and self-hosted mail servers check one or more public lists. A listing on a list that targets attackers, such as blocklist.de, matters for logins and firewalls more than for mail.
What does checking a domain do?
It looks up the domain's mail servers and checks up to three addresses: the IPv4 addresses of the first three MX hosts, then their IPv6 addresses, and the domain's own address only when that gives fewer than three. The result names any address it left out, so you can check it on its own. If your mail goes out through a provider such as Google Workspace or Microsoft 365, the sending addresses are the provider's, and their reputation is the provider's to manage.
Related guides
How to secure SSH access on a public server
Port 22 gets brute-forced within minutes. Key-only auth plus fail2ban and a firewall removes almost all the risk. The practical, in-order setup.
UFW firewall setup: deny by default, open what you serve
Configure UFW the safe way: allow SSH first, open only the ports you serve, restrict sensitive ports by source, and rate-limit the noise.
Initial server setup: the first ten minutes on a new VPS
A repeatable checklist for a fresh Ubuntu or Debian server: non-root user, key-only SSH, firewall, automatic security updates, hostname, timezone and swap.