---
name: email-blacklist-check
description: Checks sending IPs and domains against the DNS blocklists that matter for email (Spamhaus ZEN and DBL, SURBL, URIBL and others), explains each return code, separates real listings from resolver errors, and gives a delisting and prevention plan ranked by impact. Use when the user asks whether an IP or domain is blacklisted, sees 5.7.1 blocks mentioning a blocklist, wants to vet a new domain or IP before sending, or asks what a listing means for cold email.
---

# Email blacklist check

You check IPs and domains against DNS blocklists (DNSBLs), read the return codes correctly, and tell the user which listings matter and what to do. You rank by impact: a Spamhaus listing is urgent, a small list almost nobody uses is not.

## Step 1. Collect the targets

Ask for:

- Sending IPs (from the `Received:` headers of a sent email, or from the provider).
- The sending domain (From domain), the Return-Path domain, and any domain that appears in the email body or signature (links, images, tracking host).

## Step 2. Query the lists

IP lists use the reversed IP. For 203.0.113.25:

```
dig +short 25.113.0.203.zen.spamhaus.org
dig +short 25.113.0.203.b.barracudacentral.org
dig +short 25.113.0.203.bl.spamcop.net
```

Domain lists use the domain as is:

```
dig +short example.com.dbl.spamhaus.org
dig +short example.com.multi.surbl.org
dig +short example.com.multi.uribl.com
```

No answer (NXDOMAIN) = not listed. An answer in 127.0.0.0/8 = listed or an error; read the code.

## Step 3. Read the return codes

Spamhaus ZEN (IP):

| Code | List | Meaning |
|---|---|---|
| 127.0.0.2 | SBL | spam source or operation, high impact |
| 127.0.0.3 | CSS | snowshoe or low-reputation sending, high impact |
| 127.0.0.4-7 | XBL | compromised host or bot |
| 127.0.0.10-11 | PBL | dynamic or end-user IP range, should not send direct to MX |

Spamhaus DBL (domain): 127.0.1.2 spam domain, 127.0.1.4 phishing, 127.0.1.5 malware, 127.0.1.102+ abused legit domain.

SURBL and URIBL return a bitmask (for example 127.0.0.64 on SURBL = listed in one of its sub-lists). Any non-error answer means the domain was seen in spam messages.

Errors, not listings:

- `127.255.255.252`, `.254`, `.255` from Spamhaus = query refused. The query came through a public or open resolver (8.8.8.8, 1.1.1.1 and similar). Re-run through your own resolver or the list's website lookup.
- URIBL `127.0.0.1` = query refused for the same reason.

Never report a refused query as a listing.

## Step 4. Judge impact

- High: Spamhaus SBL/CSS/XBL/DBL, Barracuda for business recipients. Many receivers block or spam-folder on these.
- Medium: SURBL, URIBL. They score domains that appear in the message. A listed domain in a link or signature hurts every email that contains it. Cold sending domains are often listed here, which is one more reason to keep links and bare domains out of cold email.
- Low: small or pay-to-delist lists. Note them, do not panic, do not pay for delisting.

## Step 5. Plan

For each listing:

1. Stop or cut volume from the listed IP or domain until the cause is fixed.
2. Find the cause: sudden volume, bad list (spam traps, many invalid addresses), complaints, compromised account, shared IP neighbours.
3. Fix the cause first, then request removal on the list's own site (Spamhaus and Barracuda have free lookup and removal forms). Repeat listings after removal get longer.
4. For PBL: send through a proper mail server or provider, not from a residential or dynamic IP.
5. For a listed domain in the body: remove the domain from links, signature and tracking.

## Output format

| Target | List | Result | Meaning | Impact | Action |
|---|---|---|---|---|---|

Then a short plan: what to stop now, what to fix, what to request, when to re-check.

## Rules

- Show the exact query and the exact answer for every listing you report.
- A clean blocklist check does not mean mail reaches the inbox. Big mailbox providers use their own reputation data. Suggest an inbox placement test for that.
- Do not recommend paid delisting services.

## Example

Input: IP 198.51.100.7, domain example.com.

Output (abridged):

| Target | List | Result | Impact | Action |
|---|---|---|---|---|
| 198.51.100.7 | Spamhaus ZEN | 127.255.255.254 | none, query refused | re-check via own resolver |
| example.com | SURBL | 127.0.0.64 | medium | remove the domain from signature and links |
