This IP blacklist check tests up to 256 addresses in one run (1,024 with srvScripts Pro): paste single IPv4 or IPv6 addresses, CIDR ranges from /24 to /32, hostnames or domains. Every IP is checked against 30 DNS blacklists, including Spamhaus ZEN, Spamcop, Barracuda, UCEPROTECT, PSBL, DroneBL, Mailspike, Hostkarma, InterServer, Blocklist.de and SpamEatingMonkey, with its reverse DNS record and whether it is forward-confirmed.
Domains are also checked against the Spamhaus DBL, URIBL and the Nordspam domain list. Results come back as one table, worst first, with the listing code, the reason where the list publishes one and a link to the operator’s delisting page.
Tick Show listed only for long ranges, switch on the colour-blind palette if red and green are hard to tell apart, and download everything as CSV.
IPs are checked in real time against 30 public DNS blacklists (Spamhaus ZEN, Spamcop, Barracuda, UCEPROTECT, PSBL, DroneBL, Mailspike, Hostkarma, InterServer, Blocklist.de, SpamEatingMonkey and more) with reverse DNS and forward-confirmed rDNS. Domains are checked against Spamhaus DBL, URIBL multi, Nordspam DBL. CIDR ranges from /24 to /32 are expanded in your browser. Nothing you enter is stored. Results are informational; confirm on the list operator's own lookup page before you request delisting.
Table of Contents
How to read the results
A listing on Spamhaus ZEN, Spamcop or Barracuda will cause rejections at large mailbox providers and should be treated as an incident: find the source of the spam first (a compromised mailbox or a hacked script), stop it, then request delisting — most operators re-list within hours if the traffic continues. UCEPROTECT Level 2 and 3 list whole provider ranges and are largely ignored by major receivers; do not pay for “express delisting”. Lists marked informational (backscatter, dynamic-IP, open-relay history) rarely block mail on their own but explain why a reputation score is low.
Some well-known lists are deliberately not queried here: SORBS shut down in 2024, and Proofpoint/Invaluement and Abusix only answer paying subscribers, so a free lookup against them returns false results. SURBL did not answer its own permanent test entry from this server, so it is left out rather than reported as clean. Spamhaus refuses queries that arrive through large public resolvers; if a Spamhaus row says the query was refused, check the address or domain directly at check.spamhaus.org.
Missing or unconfirmed reverse DNS is rejected outright by Outlook.com and many corporate gateways regardless of blacklists. Set a PTR record at your hosting provider that resolves to the server hostname, and make sure that hostname resolves back to the same IP.
Automate it
Hosting providers can run the same check from a server with the Exim mail queue report and a cron job against this page’s API endpoint: POST /wp-json/srvs/v1/dnsbl with {"ips": "1.2.3.4, 5.6.7.8, example.com"}. Each request takes up to 25 targets (IPs, hostnames or domains; expand CIDR ranges before sending), and each client may send 150 requests per 10 minutes.
To be told when a sending IP or domain gets listed, set up a free alert with the uptime, SSL and blacklist monitor, which re-checks every 12 hours. For root-cause work on a listed server, start with finding the source of outgoing spam on cPanel.
IP blacklist check at a glance



How to use this tool
- Paste what you want to check, one entry per line or separated by commas, semicolons or spaces. Accepted: IPv4 and IPv6 addresses, IPv4 ranges in CIDR notation from /24 to /32 (/22 with srvScripts Pro), hostnames such as mail.example.com, and domains. IPv6 ranges are not expanded; enter single IPv6 addresses.
- Leave Check domains on 3 domain/URI blacklists ticked to test the domains themselves. Untick it to check only the IP addresses a domain resolves to.
- Press Check against 33 blacklists. Ranges are expanded in your browser, duplicates removed, and the addresses sent in small batches; the progress bar shows how many batches are done and Stop ends the run after the current batch.
- Select any row to see the list codes, the reason text the list publishes and the delisting link for each listing.
- Use Download CSV to keep the full result, for example to attach to a ticket with your host.
A domain or hostname is checked twice: the name itself against the domain lists, and up to three of its A records against the 30 IP lists (the row then says from example.com). Each IP and domain result is cached for 30 minutes, so a re-check straight after delisting can still show the old answer.
Status labels and list weights
Each list has a weight that reflects how much damage a listing does. The row status comes from the heaviest list that has the target:
| Status | What it means |
|---|---|
| Clean | No list returned a listing. The badge does not show a count. |
| Listed | At least one high-impact list has the target: Spamhaus ZEN, Spamcop or Barracuda for IPs; Spamhaus DBL (spam, phishing, malware or botnet domains) or URIBL black/red for domains. Expect rejections at many receivers. |
| Listed (minor lists) | Only medium or low-impact lists have it, such as UCEPROTECT, PSBL, Mailspike, DroneBL, Blocklist.de or backscatter lists. Fix the cause, but these rarely block mail at the large mailbox providers on their own. |
| Not checked | Every list query for this target failed or was refused, so there is no verdict. Run it again later. |
2/30 next to the label | Number of lists that returned a listing, out of the lists checked for that kind of target. |
| rDNS / A column | For an IP: its PTR name and FCrDNS ok when that name resolves back to the same IP, no forward match when it does not, or no PTR. For a domain: up to three A records. |
The return code in the detail view tells you why a list has the address. For Spamhaus ZEN:
| Return code | Spamhaus list | What it usually means |
|---|---|---|
127.0.0.2 | SBL | Spamhaus has identified the address or its range as a source of spam or other malicious activity. Listings are made by Spamhaus staff and each has its own reference page. |
127.0.0.3 | CSS | The IP was detected sending spam. Common causes are a compromised mailbox, a hacked contact form or a newsletter sent to a poor list. |
127.0.0.4 | XBL | The IP looks compromised: traffic from it matches malware or bot behaviour. Look for an infected device or script, or a NAT gateway shared with an infected machine. |
127.0.0.9 | DROP | The whole network range is considered hijacked or criminal. |
127.0.0.10, 127.0.0.11 | PBL | Not an abuse listing: the range is marked as end-user space that should not send mail directly to other servers. |
Codes in the 127.255.255.x range are errors, not listings. 127.255.255.254 means the query came through a public resolver and was refused; the checker reports that as Not checked rather than as a listing. For Spamhaus DBL domain listings the detail shows the label instead: spam domain, phishing, malware, botnet C&C, or one of the abused legit codes, which mean a normally legitimate domain was abused (weighted lower).
Common problems and how to fix them
“554 5.7.1 Service unavailable; Client host [203.0.113.10] blocked using zen.spamhaus.org”
This is how Postfix-based receivers word a Spamhaus rejection; Exim and others use similar text. Run the IP here and read the return code. For SBL, CSS or XBL, stop the source first and then use the removal option on check.spamhaus.org. For a PBL listing on a real mail server with a static IP and working reverse DNS, Spamhaus offers self-removal; if the range owner does not allow that, send mail through your host’s relay or a smarthost instead.
“550 5.7.1 Unfortunately, messages from [203.0.113.10] weren’t sent … (S3150)”
Outlook.com and Hotmail block the IP on their own list, which no public DNS blacklist shows. These blocks often lift on their own after some days without problem traffic; otherwise open a request through Microsoft’s sender support at olcsupport.office.com. For Microsoft 365 business mailboxes the error is 550 5.7.606-649 Access denied, banned sending IP, and removal is done at sender.office.com.
Spamcop listing
Spamcop lists IPs that recipients report and spam traps catch. Listings expire on their own once reports stop for about 24 hours, so there is nothing to request: find what is sending the reported mail and wait.
Barracuda listing
Barracuda takes removal requests through its form (IP, email address, phone and a reason). It says valid requests are usually processed within 12 hours and that repeated requests are ignored, so submit once, after the cause is fixed.
UCEPROTECT Level 2 or 3
Level 1 is the single IP and expires 7 days after the last spam. Levels 2 and 3 list your provider’s ranges or whole network because of other customers; only the provider can act. Most large receivers do not use Levels 2 and 3, so a listing there alone rarely explains rejected mail.
The IP is listed again a day after delisting
The source was never stopped. On a cPanel server with Exim, these two commands show which mailbox logins and which script directories send the most mail:
grep -o 'A=dovecot_[a-z]*:[^ ]*' /var/log/exim_mainlog | sort | uniq -c | sort -rn | head
grep 'cwd=' /var/log/exim_mainlog | grep -v /var/spool | awk -F'cwd=' '{print $2}' | awk '{print $1}' | sort | uniq -c | sort -rn | head
A mailbox at the top with thousands of messages usually has a stolen password: change it and check its forwarders. A website directory at the top points at a contact form or a hacked script. The full walkthrough is in finding the source of outgoing spam on cPanel, and the order of work after a listing is in the IP blacklisted runbook.
“Not checked: Spamhaus ZEN (query refused by Spamhaus — use check.spamhaus.org)”
Spamhaus refused the query from our resolver, so the checker cannot say either way. Look up the address at check.spamhaus.org. If your own mail server logs the same refusal, it is querying Spamhaus through a public resolver such as 8.8.8.8; point it at a local caching resolver or use a free Spamhaus DQS key.
Official documentation: cPanel & WHM documentation, RFC 5321 (SMTP), AlmaLinux wiki.
Related guides: Warm up a new mail server IP or sending domain without landing in spam · MailBaby with Postfix on Ubuntu/Debian as an authenticated smarthost · Whitelisting MailBaby in cPanel greylisting, CSF and SpamAssassin.
Frequently asked questions
How long does a blacklist listing last?
It depends on the list. Spamcop expires about 24 hours after reports stop, UCEPROTECT Level 1 7 days after the last spam, while Spamhaus SBL and Barracuda stay until you request removal after fixing the cause.
Does a PBL listing mean my server sent spam?
No. The Spamhaus PBL marks ranges whose owners say they should not send mail directly to other servers, such as home and dynamic connections. A real mail server on a static IP with proper reverse DNS can usually be removed.
Why is my IP listed when I have not sent any email?
IPs are reused. A new server may inherit a listing from its previous user, and XBL listings come from bot-like traffic, not only email. Check the return code and request removal if the cause predates you.
Does this tool check Microsoft and Gmail blocks?
No. Outlook.com, Microsoft 365 and Gmail use their own internal reputation, which no public DNS blacklist shows. Their bounce messages, Microsoft SNDS and Google Postmaster Tools are the places to look.
Why does an IPv6 address come back clean on almost every list?
Many DNS blacklists only publish IPv4 data, so a clean IPv6 result carries less weight than a clean IPv4 result. Rely on the IPv4 results and on bounce messages for IPv6 senders.
Can I check a whole /16 network?
Not in one run. Split it into /24 blocks (256 addresses each) or use the API endpoint described above from a script, keeping within the rate limit.