Blacklists and DNSBLs: how blocklists work
How a DNSBL works, a sample query and reply, the well-known lists (Spamhaus, SpamCop, Barracuda, SURBL, URIBL), how to check a listing and how to get removed.
Aktualisiert am 01/10/2026
A DNSBL (DNS-based Blocklist, often simply called a blacklist or RBL) is a list of IP addresses or domains published as a DNS zone, which receiving servers query in real time to decide whether to accept, flag or refuse a connection. It is one of the oldest anti-spam mechanisms and still one of the most widely used.
How a DNSBL works
The whole mechanism is a single DNS query. To find out whether 203.0.113.10 is on a list published under zen.spamhaus.org, the server reverses the octets and looks up the resulting name:
$ dig +short 10.113.0.203.zen.spamhaus.org
Two outcomes are possible:
- NXDOMAIN (no answer): the address is not listed.
- An A record in
127.0.0.0/8: the address is listed, and the returned value tells why. At Spamhaus,127.0.0.2means a known spam source (SBL),127.0.0.4to127.0.0.7a compromised machine or open proxy (XBL), and127.0.0.10or127.0.0.11an address range that should not be sending mail directly (PBL).
A TXT record usually accompanies the reply with a lookup URL. Domain lists (URIBL, SURBL) work the same way, except that the key being queried is a domain name found in the message body rather than an IP address.
The receiving MTA performs this lookup at connection time, before it has even read the message. Depending on the list and its own policy, it rejects with a 5xx code, adds points to the spam score, or simply logs the result.
The lists that matter most
The lists below are the ones that appear most often in SMTP rejections and in lookup tools.
- Spamhaus ZEN (spamhaus.org): a combination of the SBL (spam sources), XBL (compromised machines) and PBL (ranges not meant for direct sending). It is the list with the broadest impact, used by a large share of the world's MTAs. Spamhaus also publishes the DBL, a domain list.
- SpamCop (spamcop.net): fed by user reports and spam traps. Listings are automatic and expire on their own within 24 to 48 hours if no new reports come in.
- Barracuda Reputation Block List (barracudacentral.org): operated by Barracuda Networks and very present in corporate gateways running its products.
- SURBL (surbl.org): a list of domains and hostnames seen in unsolicited mail, queried against the links in the message body.
- URIBL (uribl.com): same principle, with several severity levels (black, grey, red).
Other lists exist, some very aggressive or poorly maintained. Being on a marginal list often has no measurable effect; being on Spamhaus ZEN blocks a large share of traffic within minutes.
Why an address gets listed
The most common causes, roughly in order of frequency:
- sending to spam traps (addresses that never subscribed, often recycled from abandoned mailboxes), which reveals a purchased or uncleaned list;
- a compromised machine on the network, emitting spam without the administrator's knowledge;
- an open relay or a web form abused by third parties;
- an IP address inherited from a previous tenant, already listed before it went into service;
- a high volume of complaints forwarded by users.
What to check
- Query the main lists regularly for every sending IP and every domain present in links (main domain, click-tracking domain, image domain). One
digper list is enough, and it is easy to automate. - Read the text of
5xxrejections in the MTA logs: it almost always names the list responsible and gives the URL to consult. - Before putting an IP into production, check that it is not already listed.
- Distinguish an IP listing (the problem lies in the infrastructure or the traffic) from a domain listing (the problem lies in the content or in how the domain is used).
Getting delisted
Each list has its own procedure, described on its website. Three rules apply everywhere:
- Fix the cause before requesting removal. A delisting without a fix is followed by a relisting, usually harder to lift.
- Use the list's official form; no paid intermediary speeds up the process.
- For self-expiring lists (SpamCop, XBL), waiting is enough once the emission has stopped.
Spamhaus handles SBL removal requests manually and expects an explanation of the measures taken. The PBL is not "delisted": it states that the network operator declared the range as not intended for direct sending, and the fix is to send through a legitimate relay or to ask the operator for an exception.
Common mistakes
- Querying DNSBLs through a public DNS resolver: several lists, Spamhaus among them, refuse such queries and return error codes that can be misread as a listing.
- Confusing a DNSBL with a mailbox provider's internal filtering: Google and Microsoft do not expose a queryable list, and a rejection from them is not a public listing.
- Requesting delisting repeatedly without changing anything, which eventually gets requests blocked.
- Ignoring domain lists after checking only the IP.
- Overlooking IPv6: the blocks are vast and some providers apply stricter rules there, including mandatory authentication.