Deliverability skill
Email blacklist check for IPs and domains
The assistant queries the DNS blocklists that matter for email, reads each return code, separates real listings from refused queries, and tells you which listings to fix first.
What it does
What the skill checks
- Builds the right DNS queries for IP lists (reversed IP) and domain lists
- Reads Spamhaus ZEN and DBL, SURBL and URIBL return codes
- Flags refused queries from public resolvers so they are not reported as listings
- Ranks listings by impact: Spamhaus first, minor lists last
- Gives a fix-then-delist plan for each listing
- Checks domains used in links and signatures, not only the sender
Use it when
- When bounces mention a blocklist or a 5.7.1 policy block
- Before you send from a new domain or IP
- When placement drops and you need to rule out a listing
Example
What you paste and what you get back
Check IP 198.51.100.7 and domain example.com.198.51.100.7 on Spamhaus ZEN: 127.255.255.254, query refused by the public resolver. Not a listing. Re-check through your own resolver or the Spamhaus lookup page.
198.51.100.7 on Barracuda: not listed.
example.com on Spamhaus DBL: not listed.
example.com on SURBL: 127.0.0.64, listed. Impact medium: it scores emails that contain this domain. Remove it from the signature and links.
Next check: in 7 days.Install
Install it in your assistant
The same file works everywhere. Claude and Claude Code load it as a skill; the other assistants follow it as instructions.
Claude Code
- Run the command below. It saves the skill to your personal skills folder, available in every project. For one project only, use .claude/skills in the project instead.
- Start a new Claude Code session. Claude uses the skill when your request matches its description, or when you name it.
mkdir -p ~/.claude/skills/email-blacklist-check
curl -fsSL https://outreach2day.com/skills/email-blacklist-check/SKILL.md -o ~/.claude/skills/email-blacklist-check/SKILL.mdClaude (web and desktop)
- Download the ZIP file.
- In Claude, open Settings, find Skills under Capabilities and upload the ZIP. Skills need code execution to be turned on for your account.
- Ask for the task in any chat. Claude loads the skill when the request matches.
ChatGPT
- Download SKILL.md.
- Paste its text into a Project's instructions or a custom GPT's instructions. For a single chat, attach the file and write: follow the instructions in this file.
Gemini
- Download SKILL.md.
- Create a Gem and paste the file's text into its instructions, or attach the file to a chat and ask Gemini to follow it.
Grok
- Download SKILL.md.
- Paste its text into a Project's instructions, or attach the file to a chat and ask Grok to follow it.
Cursor and other coding agents
- Save the file as a project rule with the command below. Cursor reads the description to decide when to apply it.
- Agents that read AGENTS.md (Codex and others): paste the text into AGENTS.md or reference the file from it.
mkdir -p .cursor/rules
curl -fsSL https://outreach2day.com/skills/email-blacklist-check/SKILL.md -o .cursor/rules/email-blacklist-check.mdcSource
The full SKILL.md
Read it before you install it. Change the rules to match your own setup.
---
name: email-blacklist-check
description: Checks sending IPs and domains against the DNS blocklists that matter for email (Spamhaus ZEN and DBL, SURBL, URIBL and others), explains each return code, separates real listings from resolver errors, and gives a delisting and prevention plan ranked by impact. Use when the user asks whether an IP or domain is blacklisted, sees 5.7.1 blocks mentioning a blocklist, wants to vet a new domain or IP before sending, or asks what a listing means for cold email.
---
# Email blacklist check
You check IPs and domains against DNS blocklists (DNSBLs), read the return codes correctly, and tell the user which listings matter and what to do. You rank by impact: a Spamhaus listing is urgent, a small list almost nobody uses is not.
## Step 1. Collect the targets
Ask for:
- Sending IPs (from the `Received:` headers of a sent email, or from the provider).
- The sending domain (From domain), the Return-Path domain, and any domain that appears in the email body or signature (links, images, tracking host).
## Step 2. Query the lists
IP lists use the reversed IP. For 203.0.113.25:
```
dig +short 25.113.0.203.zen.spamhaus.org
dig +short 25.113.0.203.b.barracudacentral.org
dig +short 25.113.0.203.bl.spamcop.net
```
Domain lists use the domain as is:
```
dig +short example.com.dbl.spamhaus.org
dig +short example.com.multi.surbl.org
dig +short example.com.multi.uribl.com
```
No answer (NXDOMAIN) = not listed. An answer in 127.0.0.0/8 = listed or an error; read the code.
## Step 3. Read the return codes
Spamhaus ZEN (IP):
| Code | List | Meaning |
|---|---|---|
| 127.0.0.2 | SBL | spam source or operation, high impact |
| 127.0.0.3 | CSS | snowshoe or low-reputation sending, high impact |
| 127.0.0.4-7 | XBL | compromised host or bot |
| 127.0.0.10-11 | PBL | dynamic or end-user IP range, should not send direct to MX |
Spamhaus DBL (domain): 127.0.1.2 spam domain, 127.0.1.4 phishing, 127.0.1.5 malware, 127.0.1.102+ abused legit domain.
SURBL and URIBL return a bitmask (for example 127.0.0.64 on SURBL = listed in one of its sub-lists). Any non-error answer means the domain was seen in spam messages.
Errors, not listings:
- `127.255.255.252`, `.254`, `.255` from Spamhaus = query refused. The query came through a public or open resolver (8.8.8.8, 1.1.1.1 and similar). Re-run through your own resolver or the list's website lookup.
- URIBL `127.0.0.1` = query refused for the same reason.
Never report a refused query as a listing.
## Step 4. Judge impact
- High: Spamhaus SBL/CSS/XBL/DBL, Barracuda for business recipients. Many receivers block or spam-folder on these.
- Medium: SURBL, URIBL. They score domains that appear in the message. A listed domain in a link or signature hurts every email that contains it. Cold sending domains are often listed here, which is one more reason to keep links and bare domains out of cold email.
- Low: small or pay-to-delist lists. Note them, do not panic, do not pay for delisting.
## Step 5. Plan
For each listing:
1. Stop or cut volume from the listed IP or domain until the cause is fixed.
2. Find the cause: sudden volume, bad list (spam traps, many invalid addresses), complaints, compromised account, shared IP neighbours.
3. Fix the cause first, then request removal on the list's own site (Spamhaus and Barracuda have free lookup and removal forms). Repeat listings after removal get longer.
4. For PBL: send through a proper mail server or provider, not from a residential or dynamic IP.
5. For a listed domain in the body: remove the domain from links, signature and tracking.
## Output format
| Target | List | Result | Meaning | Impact | Action |
|---|---|---|---|---|---|
Then a short plan: what to stop now, what to fix, what to request, when to re-check.
## Rules
- Show the exact query and the exact answer for every listing you report.
- A clean blocklist check does not mean mail reaches the inbox. Big mailbox providers use their own reputation data. Suggest an inbox placement test for that.
- Do not recommend paid delisting services.
## Example
Input: IP 198.51.100.7, domain example.com.
Output (abridged):
| Target | List | Result | Impact | Action |
|---|---|---|---|---|
| 198.51.100.7 | Spamhaus ZEN | 127.255.255.254 | none, query refused | re-check via own resolver |
| example.com | SURBL | 127.0.0.64 | medium | remove the domain from signature and links |
FAQ
Questions
What does 127.255.255.254 mean in a Spamhaus lookup?
The query was refused, usually because it went through a public resolver such as 8.8.8.8 or 1.1.1.1. It is not a listing. Query through your own resolver or use the Spamhaus website lookup.
Which blacklists matter most for cold email?
Spamhaus (ZEN for IPs, DBL for domains) and Barracuda block the most mail. SURBL and URIBL matter for any domain that appears inside the email. Small lists that charge for removal rarely affect delivery.
My domain is not blacklisted but mail still goes to spam. Why?
Gmail and Microsoft mostly use their own reputation data, not public blocklists. Check authentication with an SPF, DKIM and DMARC checker, then run an inbox placement test with a neutral control email.
Mailboxes, warm-up and sending in one place
$2.50 a mailbox a month. DNS records are set for you, and every mailbox shows its warm-up numbers from day one.