Guides ·

IP blacklists (DNSBL): what they are, how to check, and what to do if you're listed

An “IP blacklist” usually means a DNS-based blocklist (DNSBL): an organisation records IPs that sent spam, were compromised or scanned someone, and publishes the list over DNS so mail servers can query it. Being listed says something about that IP's email or abuse history. It is not the same as being blocked by an AI platform, and ChatGPT, Claude and Gemini have not said whether they use these lists at all. IP Judge queries five DNSBLs live; each hit costs 10 points, 30 at most.

At a glance: one DNSBL lookupReverse the four parts of the IP 192.0.2.99, append the list's zone to get 99.2.0.192.bl.spamcop.net, and send an ordinary DNS query. An answer of 127.0.0.x means listed, with each list defining what the number means; no record means not listed; a timeout or a 127.255.255.x error code is shown as unchecked by IP Judge. At a glance: one DNSBL lookup 1 Your IP192.0.2.99 2 Reverse the octets, append the list 99.2.0.192.bl.spamcop.net 3 Send an ordinary DNS query Ask the list's servers for that name 4 Read the answer Listed 127.0.0.x — meaning varies by list Not listed No record at all Unchecked Timeout, or a 127.255.255.x error RFC 5782: 127.0.0.2 must be listed, 127.0.0.1 never.
The lookup is an ordinary DNS query. The 127.x answer is a code, not a real address.

How a DNSBL lookup works

The mechanics are documented in RFC 5782 (February 2010, an Informational RFC rather than a standard):

  1. Reverse the four parts of the IPv4 address and append the list's zone. The RFC's example: to look up 192.0.2.99 in bad.example.com, query 99.2.0.192.bad.example.com.
  2. Send an ordinary DNS query. If the address is listed, you get an A record, conventionally 127.0.0.2; lists may use other 127.x values to mark sub-lists. The value must not be used as an IP address. If the address is not listed, there is no record at all.
  3. Optionally, read the TXT record. It usually explains why the address is listed and is often used as the text of a mail rejection.

The RFC also requires every IPv4 list to contain 127.0.0.2 as a test entry and never 127.0.0.1. IPv6 addresses are queried as 32 reversed hex nibbles.

One kind of answer needs care. Spamhaus explains that querying through a public resolver returns 127.255.255.254, too many queries return 127.255.255.255, and a mistyped zone returns 127.255.255.252. These are error codes, not reputation data, and must not be read as a listing.

To check by hand with dig, replace the address below with your exit IP, reversed:

dig +short 99.2.0.192.bl.spamcop.net
dig +short 2.0.0.127.bl.spamcop.net

The second line is the test entry and should return 127.0.0.2. If it returns something else (a proxy app in fake-IP mode, for example, answers with a 198.18.x address), your queries are being intercepted locally and the first result is meaningless too.

What the major lists contain

Each list has its own criteria, so a hit means different things. From each list's own documentation:

  • Spamhaus ZEN combines Spamhaus's SBL, CSS, XBL and PBL in one query. Per the documentation, 127.0.0.2 is SBL, 127.0.0.3 is CSS, 127.0.0.4 is XBL, and 127.0.0.10 / 127.0.0.11 are PBL entries maintained by the ISP / by Spamhaus.
    • SBL: IPs under the control of, or used by, spammers and abusers — spam hosting, botnet controllers, phishing and malware hosts.
    • CSS: generated automatically from IPs sending low-reputation mail, such as poor list hygiene or compromised accounts and CMS installs.
    • XBL: legitimate IPs showing signs of compromise — malware on a device, “free VPN” apps using customers' devices as proxies, brute-force attempts.
    • PBL: a policy list, not a record of bad behaviour. It covers end-user ranges, such as dynamic home broadband, that should never send mail directly to the destination. ISPs and Spamhaus maintain it.
  • Barracuda: its reputation system is a real-time database of IPs with a poor reputation for sending email, which Barracuda's mail firewall uses to block or allow messages by sender IP.
  • SpamCop: IPs that sent mail reported by SpamCop users, from user reports and spamtraps (addresses that were never used to sign up for anything). Its own FAQ calls it aggressive and recommends using it in a scoring system rather than to reject mail outright.
  • PSBL: an IP is added when it sends mail to a spamtrap, the mail is not identified as non-spam, and the IP is not a known mail server (psbl.org).
  • UCEPROTECT: Level 1 lists single IPs only, added automatically for hitting its spamtraps or for scans and attacks against its servers (policy). Levels 2 and 3 list whole allocations and ASNs; IP Judge does not query them.
  • DroneBL: IPs with a history of automated abuse, such as open proxies and malware-infected devices. Its FAQ notes that a listing can get you banned from a game or other service, or blocked from sending email, and that because most ISPs rotate addresses, it probably wasn't anything you did.
  • s5h: sources of spam and attacks of any kind against its own servers, served at all.s5h.net. It follows RFC 5782 and lists IPv6 too (about the list).

Which lists IP Judge checks, and how it scores them

On an IP Judge result, the “Blocklist · …” items under Risk checks are DNSBLs, queried exactly as above:

  • Which five: SpamCop, PSBL, UCEPROTECT L1, DroneBL and s5h, queried live over DNS for each check. Spamhaus and Barracuda are not queried; use their own lookup pages, check.spamhaus.org and barracudacentral.org/lookups.
  • What counts as a hit: any 127.x answer. No record is a miss. A 127.255.255.x error code, or no answer within 3 seconds, is shown as unchecked, not as a hit. IPv6 addresses are not checked against DNSBLs yet and also show as unchecked.
  • Scoring: each hit takes 10 points off the purity score, capped at 30 — four or five hits still cost 30.

The other risk checks are not DNSBLs but public lists plus an IP intelligence database:

  • Abuse record (−25): the IP is in FireHOL level1 or flagged as an abuser by ipapi.is. The FireHOL level1 file header describes it as built from dshield, feodo, fullbogons and spamhaus_drop, aiming for maximum protection with minimum false positives. ipapi.is says its abuser flag draws on several open-source and proprietary blocklists and threat feeds, without saying which kind of abuse.
  • Tor exit (−50): the IP is in the Tor Project's bulk exit list or flagged as a Tor exit by ipapi.is. The Tor Project explains that the list comes from its own active measurements of exit relays.
  • VPN (−30): the IP is in X4BNet's VPN ranges or flagged as a VPN exit by ipapi.is. X4BNet says its list covers the vast majority of common VPNs, not all of them.
  • Datacenter: X4BNet's datacenter list (“anything that is not an eyeball network”) is one input to the datacenter verdict; a datacenter IP costs 25 points. See residential vs datacenter IPs for the rules.

These local lists are refreshed weekly, and a result for the same IP is kept for 24 hours. The full deduction table is on the Method page; how to read the total is in What is an IP purity score?

What IP Judge checks, and the costFive DNS blocklists are queried live: SpamCop, PSBL, UCEPROTECT L1, DroneBL and s5h; each hit costs 10 points, 30 at most. A FireHOL level1 or ipapi.is abuse hit counts as an abuse record, −25; the Tor Project exit list or ipapi.is counts as a Tor exit, −50; X4BNet VPN ranges or ipapi.is count as VPN, −30; X4BNet datacenter ranges are one piece of evidence for a datacenter IP, −25. What IP Judge checks, and the cost DNS blocklists · live−10 each SpamCop · PSBL · UCEPROTECT L1 DroneBL · s5h−30 at most Abuse record−25 FireHOL level1 or ipapi.is abuse flag Tor exit−50 Tor Project exit list or ipapi.is VPN−30 X4BNet VPN ranges or ipapi.is Datacenter IP−25 X4BNet datacenter ranges are one input Local lists update weekly; results are kept for 24 hours.
DNS blocklists cost 30 points at most. Abuse, Tor and VPN come from other lists and are scored separately.

What a hit means for ChatGPT, Claude and Gemini

There is no public answer: none of the three says whether it consults DNSBLs. What we can say:

  • These lists exist mainly to fight email spam. RFC 5782 and the lists' own pages describe almost entirely how receiving mail servers use them to reject or score mail.
  • A hit says this IP — or the shared exit it belongs to — has a record of spam, compromise or scanning. It does not say you did it. DroneBL's FAQ makes the same point about rotated addresses.
  • IP Judge's availability verdict for ChatGPT, Claude and Gemini looks only at whether the region is on each platform's official list and at the IP type (proxy, datacenter). Blocklists play no part in it.

If AI platforms are what you care about, first confirm your exit region is on the platform's published list of supported regions, the one condition each of them states openly. If you plan to send email from the IP, blocklists are the first thing to fix.

What to do if you're listed

Start with whose IP it is; the answer changes everything:

  1. Find out which list and why. The IP Judge result page (/en/ip/your-IP/) shows which lists matched; each list's site explains its reason. A policy listing like PBL means something very different from “reported for spam”.
  2. Your own server: find and fix the cause first — a compromised machine, an open proxy, a misconfigured mailer — then follow the list's process. Spamhaus's XBL and CSS pages both warn that an IP removed before the problem is fixed is re-listed the next time it is detected. SBL removals go through the ISP that manages the IP, after it has solved the problem.
  3. A dynamic home address in the PBL: nothing to fix, and it cannot be removed. Spamhaus says dynamic addresses should not send mail directly; use your ISP's or mail provider's outgoing server instead.
  4. A shared exit (proxy, VPN, office gateway, public Wi-Fi): you are not the user of that IP, so you cannot, and should not, request its removal. DroneBL's FAQ is explicit: only request removal for addresses you are the primary user of; on a VPN (including services like Private Relay) or public Wi-Fi, talk to whoever runs it. Even if the listing is removed, it returns as long as someone on that exit keeps abusing it. What you can do is contact the exit's operator, or switch exits and check again.
Listed: how each list removes youSpamCop drops an address 24 hours after reports stop; UCEPROTECT L1 expires 7 days after the last spamtrap hit; PSBL lets anyone remove an address instantly; s5h removes it when you visit its removal page from the listed IP; DroneBL reviews requests made on its lookup page; Spamhaus handles removals at check.spamhaus.org and never charges; Barracuda reviews a form, usually within 12 hours. A shared exit is not yours: if abuse continues, it gets listed again. Listed: how each list removes you SpamCop Expires No new reports: gone within 24 hours UCEPROTECT L1 Expires 7 days after the last spamtrap hit PSBL Self-serve Anyone can remove an IP, instantly s5h Self-serve Open its removal page from the listed IP DroneBL Reviewed Request on its lookup page Spamhaus Per list Via check.spamhaus.org; never a fee Barracuda Reviewed A form, usually handled within 12 hours A shared exit isn't yours If the abuse continues, it gets listed again From each list's official pages, checked 2026-10-01.
Some lists expire on their own, others need a request. Either way, stop whatever caused the listing first, or it comes straight back.

How each list handles removal, per its official pages:

  • SpamCop: no request needed. Without new reports, an address stays listed for only 24 hours (FAQ).
  • UCEPROTECT L1: expires automatically 7 days after the last spam hits its spamtraps. A per-IP paid express removal also exists, described as optional (removal page).
  • PSBL: anyone can remove an IP on psbl.org. Removal is instant, though it takes time to propagate to nameservers.
  • s5h: visit its removal page from the listed IP itself; if that fails, a form lets you explain what you fixed (about the list).
  • DroneBL: submit a request on its lookup page, ideally from the affected device; volunteers review it before removal.
  • Spamhaus: everything goes through check.spamhaus.org, with rules that differ per sub-list (see above). Spamhaus states that removing any Spamhaus listing is always free.
  • Barracuda: the removal request form asks for the mail server IP, an email address, a phone number and a reason; requests with a valid explanation are typically processed within 12 hours, and repeated requests are ignored.

FAQ

I'm on just one list. Does it matter?

It costs 10 purity points. Check which list: SpamCop lists and delists automatically, and an address disappears 24 hours after reports stop; PBL is a policy list, not a sign of abuse. If you don't send email, the impact depends on whether the service you use checks that list — DroneBL notes that a listing can get you banned from games and other services.

Someone offers to remove my IP from a blacklist for a fee. Legit?

Check what the list itself says. Spamhaus states that removal is never charged, that any offer to remove a Spamhaus listing for a fee is a scam, and that no third party can influence or speed up removals. UCEPROTECT's paid express removal is the list's own optional service; without paying, the listing still expires after 7 days.

Another site shows a Spamhaus listing. Why doesn't IP Judge?

IP Judge doesn't query Spamhaus; verify at check.spamhaus.org. Also, some tools query Spamhaus through public resolvers, and the 127.255.255.254 they get back is an error code, not a listing.

I was delisted. Why does IP Judge still show the hit?

Results for the same IP are kept for 24 hours before the lists are queried again, and a removal takes time to propagate through DNS.

Does switching to an IPv6 exit avoid blocklists?

No. IP Judge only checks DNSBLs for IPv4 addresses for now, so IPv6 shows as unchecked, which is not the same as clean. RFC 5782 defines IPv6 lookups too, and lists such as s5h include IPv6 addresses.

Which kind of IP do you have?

Check my IP for free