Blacklist Checker guide
How the XGM Blacklist Checker queries 77 DNS blocklists for an IP address or a domain and its mail servers, how to read the results and what to do next.
What the checker does
Mail servers use DNS blocklists (DNSBLs) to decide whether to accept a connection from an IP address. A list operator publishes addresses it considers sources of spam or abuse, and a receiver asks the list over DNS for every incoming connection. The Blacklist Checker runs the same queries from the XGM server, so you can see what a receiver would see.
Enter an IPv4 address to check it directly, or a domain. For a domain, XGM checks the name on 19 domain blocklists (Spamhaus DBL, SURBL, URIBL and others) and up to five IPv4 addresses on the IP lists: its A records and the first address of each of its three most preferred MX hosts. Results appear as each list answers. For mail problems, the address that matters is the one your mail is sent from, which is not always the address of your website.
How to use the Blacklist Checker
- Find the IP address your mail is sent from, in the bounce message or in the first
Receivedheader added by the receiving server. - Open the Blacklist Checker and enter that IPv4 address, or a domain to check its name, web and mail server addresses.
- Read the verdict and the result for each list: listed, not listed or query refused.
- For listings, open the delisting information and follow the list operator's process after fixing the cause.
An IPv4 address is checked on all 58 IP lists. An IPv6 address is checked on the 27 lists that publish an IPv6 zone; the other 31 are marked "no IPv6 zone" for that address rather than reported as not listed. Addresses taken from a domain are IPv4. The test address 127.0.0.2 is reported as listed by every DNSBL by convention; use it to see what a listing looks like, not as information about a real server.
Below the lists, the checker adds network context for the same address, which the former IP Reputation tool showed on its own: the reverse DNS name, the network that owns the address and whether it belongs to a hosting or cloud provider. A missing PTR record is a warning because receivers score it as a spam signal. The Full report tab adds a scored reputation report for a domain.
The lists that are checked
| Zone | Operator | Focus |
|---|---|---|
zen.spamhaus.org | Spamhaus | Combined list of spam sources, exploited hosts and address ranges that should not send mail directly |
dbl.spamhaus.org | Spamhaus | Domains found in spam, phishing and malware (domain list) |
bl.spamcop.net | SpamCop | IPs reported by users as recent spam sources; listings expire when reports stop |
b.barracudacentral.org | Barracuda | Reputation list used by Barracuda systems and other receivers |
psbl.surriel.com | PSBL | IPs that sent mail to spam traps |
dnsbl-1.uceprotect.net | UCEPROTECT | Single IPs that sent to spam traps; levels 2 and 3 list whole ranges and providers |
bl.mailspike.net | Mailspike | IP reputation built from spam trap and sender data |
multi.surbl.org | SURBL | Domains found in message bodies of spam and phishing (domain list) |
black.uribl.com | URIBL | Domains in spam message bodies (domain list) |
Receivers choose which lists they use, and many large mailbox providers rely mainly on their own reputation systems. A listing on a list your recipients' servers do not use may have no visible effect. A listing on Spamhaus usually matters because many receivers use its data.
Reading the results
| Result | Severity | Meaning |
|---|---|---|
| Not listed on … | Passed | The list has no entry for the address. |
| Listed on … | Critical | The list returned a listing code; receivers using it may reject your mail. |
| … query refused | Info | The list answered with a refusal code such as 127.255.255.254, typically because the query came through a resolver it does not serve. Not a listing. |
Spamhaus in particular refuses queries that arrive through large public DNS resolvers and returns special codes instead of real results. When that happens, the checker reports a refusal rather than a false listing. Your own mail server should query Spamhaus through its own resolver under Spamhaus's usage terms.
dig +short 25.2.0.192.zen.spamhaus.org A
# no output: not listed
# 127.0.0.x: listed (the code identifies the sub-list)
# 127.255.255.x: query refused or error, not a listingWhat to do when listed
- Confirm it is your sending address and note which lists report it.
- Find the cause: a compromised account, an infected machine, a vulnerable web form, an open relay or a poor-quality mailing list.
- Stop the abuse, remove queued spam and secure the system.
- Request removal through each list operator's own website, describing what you fixed.
- Recheck daily for a week and keep monitoring.
The blacklist removal playbook covers each list's process and what to write in a removal request. For a sending setup that stays off lists, the deliverability checklist covers authentication, reverse DNS and list hygiene.
Avoid paid delisting offers
Shared hosting, cloud and provider addresses
If your mail is sent by a hosted mailbox provider or an email service, the sending addresses belong to that provider and are shared with other customers. Listings of those addresses are handled by the provider, and there is little you can do directly beyond reporting it to them. Check the headers of a delivered message to see which addresses your mail actually uses.
Web hosting and cloud addresses are often listed on policy lists because they are not meant to send mail directly to the internet. Applications running there should send through an authenticated mail service instead. That avoids the listing problem entirely and gives you DKIM signing and bounce handling.
Domain reputation is separate from IP reputation. Even with a clean IP, mail can go to spam if the domain in links or the From address has a poor reputation, or if authentication fails. Use Domain Health and the Email Security alongside this check.
FAQ
Why does 127.0.0.2 show as listed?
It is the conventional test entry that DNSBLs list on purpose, so checkers and mail servers can verify their configuration.
What does query refused mean?
The list answered with a refusal or error code instead of a result, commonly because the query came from a public or high-volume resolver. It is not a listing, but that list could not be checked.
Does the checker support IPv6?
Partly. Enter an IPv6 address and XGM queries it in the RFC 5782 reverse-nibble form on the 27 lists that publish an IPv6 zone. The other 31 IP lists answer for IPv4 only and are reported as "no IPv6 zone" for that address, never as not listed. The addresses XGM derives from a domain are still IPv4.
My domain is not listed but mail goes to spam. Why?
Blocklists are one input. Receivers also use authentication results, domain reputation, complaint rates and content. Check SPF, DKIM and DMARC and the provider's postmaster data.
How long does a listing last?
It depends on the list. Some expire automatically once abuse stops, others need a removal request. Fixing the cause is always the first step.
Should I check my website's IP?
Only if mail is sent from it. For email problems, check the IP address in the Received headers of your outgoing mail.
Can a whole IP range be listed?
Yes. Some lists include ranges, for example address blocks that providers assign to home connections or networks with a history of abuse. A range listing affects every address in it, including yours, even if your server never sent spam.
Does a listing affect incoming mail?
No. Blocklists are used by receiving servers to judge senders. A listing of your server's address affects mail you send to receivers that use the list, not mail others send to you.
How often should I check?
After incidents, after changes to sending infrastructure, and on a regular schedule such as monthly for servers that send mail directly.