Skip to content

Is your domain on
a blacklist?

One pass across 17 blocklists, Spamhaus and Barracuda and SpamCop among them, plus Google Safe Browsing. Works with a domain or an IP, and we find your mail server automatically, because that’s where listings actually hide.

Mail server found via MX Return codes decoded Verdict in seconds
Advanced domain or IP — either works MX auto-discovery — mail IPs included want this watched continuously? blacklist monitoring →
Four kinds of blacklist

Which blacklist is your problem?

“Blacklisted” means four different things depending on who holds the list. One check covers the public ones — and tells you how to read the private ones.

Mail blocklists

Spamhaus, Barracuda, SpamCop — DNSBLs that mail servers query live, mid-delivery. A listed sending IP means spam folders and 550 rejects.

the spam-folder one

Domain blocklists

DBL and SURBL list the name, not the IP. A listed domain poisons any email that so much as links to it — whoever sends it.

the poisoned-link one

Google Safe Browsing

The browser blacklist: Chrome’s full-screen red warning, plus a “this site may harm your computer” flag in Search results.

the red-screen one

Private reputation

Gmail, Microsoft and Apple keep internal lists nobody can query. You read them through bounce codes — we show you what to look for.

the silent one
How DNSBLs work

A blacklist is just a DNS zone

There’s no registry office and no phone call. A DNS blocklist is a DNS server that answers questions about IPs and names. That’s why checking one is instant, and why this page can run 23 of these queries in one pass:

  • To ask Spamhaus about 198.51.100.25, reverse the octets and resolve 25.100.51.198.zen.spamhaus.org. An answer means listed; NXDOMAIN means clean.
  • The answer is a code: 127.0.0.3 says “compromised sender”, 127.0.0.10 says “residential IP, policy only”. Same query — very different advice.
  • Domain lists work the same way, un-reversed: caldmont.com.dbl.spamhaus.org.
  • It’s plain, unauthenticated DNS — cheap enough that mail servers check every incoming connection this way, in real time.
Check my domain

Return codes, decoded

what the DNS answer means
NXDOMAINClean — the answer you want. Here, an error is good news.
127.0.0.2Spamhaus SBL — hand-curated spam source. Serious; investigate today.
127.0.0.3Spamhaus CSS — automated: spam-like traffic, usually a compromised box or form.
127.0.0.4–7Spamhaus XBL — the machine looks infected: botnet or open proxy behavior.
127.0.0.10–11Spamhaus PBL — policy, not accusation: a residential IP that shouldn’t send mail directly.
127.255.255.254Not a listing — you queried through a public resolver (8.8.8.8). Use your own.
Not all lists are equal

Who actually uses each list

Panic is optional. A Spamhaus listing is a today-problem; a UCEPROTECT listing is usually a nothing-problem. Weight every listing by who consults the list.

Spamhaus — ZEN · DBL

The one that matters most. Consulted by mail servers worldwide and weighed by the big providers. A listing here hits delivery within hours.

→ listed? fix the cause + delist today
Barracuda — BRBL

Ships inside Barracuda firewalls and appliances, common in front of corporate mail. A listing means hard 550 rejects at thousands of companies.

→ free removal form · no fee
SpamCop

Fed by user spam reports and spam traps. Real, but self-healing: listings expire on their own within 24–48 hours once the reports stop.

→ fix the cause, then wait it out
PSBL · DroneBL · SpamRats

Smaller lists with modest reach. Worth clearing for hygiene, but rarely the reason your mail is bouncing — check the big two first.

→ delist when convenient
UCEPROTECT — L1 · L3

Lists whole networks: Level 3 flags your host’s entire AS because of other customers. Almost nobody filters on it — and “express delisting” costs money by design.

→ never pay — it expires on its own
Gmail · Microsoft · Apple

Private reputation systems — not queryable by anyone. You read them via bounce codes (Gmail 5.7.28, Microsoft 5.7.606) and their postmaster dashboards.

→ read the bounce, use their portals
For terminal people

Check any blacklist with dig alone.

Every DNSBL answers plain DNS queries. This page runs 23 of them in one pass and decodes the return codes for you.

Is this IP on Spamhaus?dig +short 25.100.51.198.zen.spamhaus.org
Is the domain name listed?dig +short example.com.dbl.spamhaus.org
Find your mail server firstdig +short MX example.com
Sweep the big threefor bl in zen.spamhaus.org b.barracudacentral.org bl.spamcop.net; do dig +short 25.100.51.198.$bl; done
Your PTR record — receivers check itdig +short -x 198.51.100.25
Google’s verdict on your sitetransparencyreport.google.com/safe-browsing/search?url=example.com
Re-check after a delisting requestwatch -n 600 dig +short 25.100.51.198.zen.spamhaus.org
FAQ

Common questions

Type either above. For a domain we resolve the website's IP and find the mail server via its MX records. Then we check the domain name, both IPs and Google Safe Browsing: 25 queries in one pass. It's free and needs no sign-up. We query from a clean resolver, so public-resolver false positives (that 127.255.255.254 answer) never sneak in.

Almost certainly not. Home and office connections sit on the Spamhaus PBL and similar “dynamic IP” lists by design. That is policy, not an accusation: residential IPs aren't supposed to run mail servers, so receivers ignore mail sent from them directly. It only matters if you actually operate a mail server on that IP. Your normal email goes out through your provider's servers, and that is whose reputation counts.

Blacklists are one input among many. The usual suspects, in order: missing or broken authentication (SPF, DKIM and DMARC are all DNS records), a weak domain reputation, spammy content patterns, and sudden volume spikes. For your actual standing with Gmail, use Google Postmaster Tools. It is free, and it shows the reputation Google itself has assigned your domain.

The classics: a compromised contact form or WordPress plugin quietly relaying spam, a leaked SMTP password, malware on the server, or a purchased address list that hit spam traps. Sometimes it is just a bad neighbor on a shared hosting IP. Either way the fix starts with finding the source, not with the removal form.

Fix the cause first, or you'll be relisted within 48 hours. Then: Spamhaus has free self-service removal, Barracuda a free request form, and SpamCop expires on its own in 24–48 hours. And one rule holds throughout: never pay for delisting. Every list that matters removes you free; paid “express delisting” is a business model, not a service.

Google Safe Browsing — the database behind Chrome's full-screen red warning and the “this site may harm your computer” tag in Search. It flags malware, phishing and deceptive pages, and it's included in every check this page runs. If you're flagged: Google Search Console shows exactly which URLs tripped it, and you request a review there after cleaning up.

Because they're private — no public query interface exists, for anyone. You learn you're on them from bounce codes: 5.7.606 from Microsoft, 5.7.28 from Gmail. Microsoft has a sender-delisting portal and SNDS for IP standing; Gmail has Postmaster Tools. We check everything that's publicly checkable — and tell you which bounces to read for the rest.

Free tools are just the start.
Uptimia keeps your sites healthy.

Uptime, SSL, domain expiry, page speed, transactions — monitored from 171+ locations worldwide. Free for 30 days.

30 days free no credit card cancel anytime free plan after trial
100,000+ websites monitored · GDPR-compliant