Skip to content

Blacklist Checker

Check whether an IP address or a domain's mail server is listed on DNS blocklists.

Runs on the XGM server. Nothing is stored.

An IPv4 or IPv6 address, or a domain (its name, A records and mail servers are checked). Press Enter to run. Try , , .

About this tool

Blacklist Checker asks 58 IP blocklists and 19 domain blocklists whether a target is listed, by sending one DNS query per list from the XGM server and reading the 127.0.0.x code that comes back, together with the TXT reason the list publishes. For a domain it checks the name itself on the domain lists, and up to five IPv4 addresses taken from its A records and its mail servers on the IP lists. Every list is first probed with the entries RFC 5782 says must never be listed, and a list that answers for those is reported as not checked instead of producing a false listing. A code in the 127.255.255.x range is likewise not a listing: it means the list declined the query, usually because it arrived through a public or high-volume resolver. It queries IPv6 only on the 27 lists that publish an IPv6 zone, it cannot see lists that are not queryable over DNS, and it does not request delisting for you.

XGM queries 58 IP blocklists and 19 domain blocklists (DNSBL, URIBL, SURBL) over DNS from the XGM server. Every zone in the catalogue answered the RFC 5782 test entry, and any zone that starts listing everything is reported as not checked instead of producing a false listing. For a domain it checks the name and up to five IPv4 addresses from its A and MX records. An IPv6 address can be typed in directly: it is queried in the RFC 5782 reverse-nibble form on the 27 lists that answer the IPv6 test entry, and the other 31 IP lists are marked "no IPv6 zone" for that address rather than reported as not listed. The addresses derived from a domain stay IPv4. 127.0.0.2 is the standard test address that every list reports as listed. Network context for a typed-in IP (reverse DNS, network owner, hosting network) comes from the XGM server and ipwho.is.

How to use it

  1. Open the Blacklist Checker tool.
  2. Enter the public domain, hostname or IP address you want to check.
  3. Run the check; XGM queries it from its server and lists the findings.
  4. Copy the output only after checking it looks correct.
  5. Use related XGM tools if you need a broader diagnostic view.

FAQ

What is the difference between “Refused” and “Not listed”?

Several lists - Spamhaus, URIBL, SURBL and Validity among them - refuse queries that arrive through public or high-volume resolvers and answer with a refusal code in the 127.255.255.x range instead of a real verdict. XGM shows that as “Refused” because nothing is known either way; treating it as “Not listed” would be wrong. Check those lists through their own lookup pages, which the result links to.

Why is a list reported as “Not checked”?

Either it did not answer within the query deadline, or it failed the RFC 5782 test: before each run XGM asks the list about 127.0.0.1 and, for domain lists, about the name “invalid”, which must never be listed. A list that answers for those has a wildcard on its zone, usually because it was abandoned, so every answer it gives would be a false positive and its results are discarded. The status means unknown, not clean - run the check again later.

When I enter a domain, what is actually checked?

The domain name goes to the 19 domain lists (DBL, URIBL and SURBL style), and separately its IPv4 addresses go to the 58 IP lists: up to two addresses from the A records and the first IPv4 address of up to three MX hosts, five addresses at most. The Checked column names each address and where it came from. Private or reserved addresses are skipped, because public blocklists do not cover them.

I am listed. What do I do first?

Fix the cause before you ask for removal: a compromised mailbox or web form, an open relay, a missing PTR record, or a list you bought or imported. Lists relist quickly, and some make repeat delisting harder. The finding shows the return code and the TXT reason the list published, and links to that list’s own delisting page.

Can I check an IPv6 address?

Yes for an address you type in: it is queried in the RFC 5782 reverse-nibble form on the 27 lists that publish an IPv6 zone, and the other 31 IP lists are reported as "no IPv6 zone" for it rather than as not listed. A domain is still checked on its IPv4 addresses only, so an IPv6-only mail server has to be entered by address. Private and reserved addresses are skipped, since they are not reachable from the internet.

Read the full Blacklist Checker guide

Further reading