# Spamhaus 550 5.7.1 Blocked: Fix SBL, XBL, CSS, PBL and DBL

Source: https://srvscripts.com/guides/spamhaus-550-5-7-1-blocked/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** A `550 5.7.1` bounce that mentions Spamhaus means the receiver looked up your sending IP (or a domain in the message) in a Spamhaus list and found it. Look the IP and domain up at `check.spamhaus.org`, which tells you the exact list. XBL, CSS, PBL and DBL removals are self-service there once the cause is fixed. SBL listings can only be removed through the network or hosting provider that owns the IP. Fix the cause first (usually a compromised account, script or device), or the IP is listed again.

We ran the DNS queries and inspected the Exim RBL settings on our lab servers (AlmaLinux 9.8 with cPanel & WHM 11.138, and DirectAdmin 1.712, Exim 4.100.1) on 6 October 2026. Return codes and removal rules were checked against Spamhaus documentation (linked below) the same day.

## Read the rejection message

Each receiver words the bounce its own way, so search the text for the list name. Typical patterns:

- `blocked using zen.spamhaus.org` or `blocked using Spamhaus`: an IP list (SBL, CSS, XBL or PBL) through the combined ZEN zone.

- `dbl.spamhaus.org` or “domain listed”: a domain in the message (From, Return-Path or a link in the body) is on the Domain Blocklist.

- `550 OU-001` from Outlook.com: Microsoft’s postmaster page says this block relates to Spamhaus and points you to Spamhaus for removal.

- On a cPanel receiving server, Exim’s built-in Spamhaus RBL check rejects with `JunkMail rejected - ... is in an RBL` followed by the list text. We found that wording in the cPanel ACL files on our lab.

Keep the full bounce. Most rejection texts include the IP that was checked, which may not be the one you expect if the server has several addresses.

## Spamhaus lists and return codes

Spamhaus answers a DNS query with an address in `127.0.0.0/8`. The last octet tells you which list matched:

| Return code | List | What it means | Who can remove it |
| --- | --- | --- | --- |
| 127.0.0.2 | SBL | Manually listed spam source or spam-support service | Only the network owner (ISP/host) can request removal |
| 127.0.0.3 | CSS (part of SBL) | Automated listing of IPs sending low-reputation mail | Self-service at check.spamhaus.org, limited; expires about three days after the last detection |
| 127.0.0.9 | DROP (with SBL) | Whole network ranges considered hijacked or criminal | Not a single-IP problem; talk to the provider |
| 127.0.0.4 | XBL | Exploited or infected host, open proxy, botnet activity | Self-service at check.spamhaus.org after cleaning |
| 127.0.0.10, 127.0.0.11 | PBL | End-user IP range that should not send direct-to-MX mail (ISP-maintained or Spamhaus-maintained) | Self-service exclusion at check.spamhaus.org, if the network’s policy allows it |
| 127.0.1.2 to 127.0.1.106 | DBL | Domain with poor reputation, phishing, malware or abused legitimate domain | Self-service at check.spamhaus.org; most listings also expire automatically |
| 127.255.255.254 | Error | Query came through a public/open resolver | Not a listing: fix the resolver |
| 127.255.255.255 | Error | Excessive number of queries | Not a listing: fix the query volume |

ZEN (`zen.spamhaus.org`) is simply SBL, XBL and PBL combined, so a “ZEN” bounce still comes down to one of the lists above.

## Check the IP and domain

The reliable check is the Spamhaus IP and Domain Reputation Checker at `https://check.spamhaus.org/`. Spamhaus says it is the only place where XBL, CSS, PBL and DBL removals are handled, and it shows SBL listing details too. Our [IP Blacklist Check](/tools/ip-blacklist-check/) queries 33 lists at once, which is useful to see if other blocklists also list you.

You can query the DNS zone yourself by reversing the IP. For `203.0.113.10`:

```
dig +short 10.113.0.203.zen.spamhaus.org A
dig +short example.com.dbl.spamhaus.org A
```

No answer means not listed, but only if your resolver is allowed to query Spamhaus. On our cPanel lab we queried the Spamhaus test entry `2.0.0.127.zen.spamhaus.org`, which is always listed:

| Resolver used | Result for the always-listed test entry |
| --- | --- |
| The VPS provider’s default resolver | NXDOMAIN (looks “not listed”) |
| Google Public DNS (8.8.8.8) | NXDOMAIN |
| Cloudflare (1.1.1.1) | 127.255.255.254 (public resolver error) |

So a clean result from `dig` on a typical VPS proves nothing. Use check.spamhaus.org, or query through your own recursive resolver on an IP with proper reverse DNS, or through Spamhaus’s free Data Query Service (DQS) key.

## Find and fix the cause on the server

Delisting without fixing the cause does not last: Spamhaus says XBL and CSS re-list quickly when the problem is detected again. Match the list to the usual cause:

### XBL: something on or behind the IP is compromised

- Look for scripts sending mail directly: on cPanel, check `/var/log/exim_mainlog` for the `cwd=` of the sending process; our guide to [finding the source of outgoing spam on cPanel](/guides/find-source-of-outgoing-spam-cpanel/) walks through it.

- Check for processes connecting to port 25 that are not Exim: `ss -tnp state established '( dport = :25 )'`.

- If the IP is a NAT gateway, the infected device may be any machine behind it. Restrict outbound port 25 at the firewall to the real mail server only, which Spamhaus itself recommends.

### CSS: low-reputation mail from your IP

- A compromised mailbox password sending through authenticated SMTP is the usual cause on shared hosting. Look for one sender with a sudden spike in the Exim log and reset that password.

- Bulk mail to old or purchased lists. Spamhaus names poor list hygiene and unsolicited mail as listing factors.

- Set per-domain and per-account sending limits so one account cannot burn the IP: see [Exim outbound mail limits in WHM](/guides/exim-outbound-mail-limits-whm/).

### PBL: the IP is in an end-user range

A server on a residential or dynamic range should send through an authenticated relay (smarthost), not directly to MX hosts. If it is a real server on a static IP with matching forward and reverse DNS, request an exclusion through check.spamhaus.org; the network owner’s PBL policy decides whether that is allowed.

### SBL: manual listing

Open the listing from check.spamhaus.org and read the evidence. Spamhaus notifies the network owner; as a server admin you fix the problem and then ask your hosting provider or ISP to request removal. Spamhaus will not process removal requests from end users for SBL.

### DBL: a domain in your mail

Check every domain in the message: From, Return-Path, link domains and image hosts. A hacked WordPress site whose pages are used in phishing links can get the customer’s domain listed. Clean the site, then use the removal option for the domain at check.spamhaus.org. Most DBL listings expire on their own once the activity stops.

## Check that it worked

- Look the IP and domain up again at check.spamhaus.org. It should show no current listing.

- Allow for caches: Spamhaus says some networks take up to 24 hours to pick up removals.

- Retry the failed mail from the queue (`exim -qff` forces a delivery attempt for all queued messages, frozen ones included; review the queue first with `exim -bp` so you do not resend spam).

- Send a test to the receiver that bounced and confirm acceptance in the Exim log.

- Set up monitoring so you hear about the next listing before customers do: our [Uptime, SSL and Blacklist Monitor](/tools/uptime-ssl-blacklist-monitor/) emails you when an IP appears on a list.

Before forcing a queue run, delete any spam still sitting in the queue, or the server will deliver it the moment the block lifts and get relisted.

## Common problems

- **Your own server rejects everyone as “listed”.** If your inbound RBL checks query Spamhaus through a public resolver, an MTA that does not treat `127.255.255.254` as an error counts it as a hit. DirectAdmin’s Exim on our lab avoids this with `zen.spamhaus.org!&0.255.0.0`, which ignores answers in the 127.255.x.x error range. Check your own RBL configuration for the same.

- **Your inbound RBL check never matches anything.** The opposite problem: an NXDOMAIN from a blocked resolver looks like “not listed”, so the check does nothing. Our lab’s default resolver behaved this way. Use a local recursive resolver or DQS.

- **Listed again a day after removal.** The cause was not fixed. For XBL, look behind NAT; for CSS, look for a compromised mailbox.

- **Delisted but one provider still rejects.** Some providers keep their own reputation data. For Outlook.com, check SNDS and contact Microsoft sender support after the Spamhaus listing is gone.

**Official documentation:** [Spamhaus: available zones and return codes](https://docs.spamhaus.com/datasets/docs/source/10-data-type-documentation/datasets/040-zones.html) · [Spamhaus IP and Domain Reputation Checker](https://check.spamhaus.org/) · [Spamhaus: help for Public Mirror users (127.255.255.254/255)](https://www.spamhaus.com/product/help-for-spamhaus-public-mirror-users/) · [Outlook.com postmaster: SMTP error codes](https://substrate.office.com/ip-domain-management-snds/Postmaster/Troubleshooting)

**Related:** [Mail server IP blacklisted: delisting runbook](/guides/runbook-ip-blacklisted/) · [IP Blacklist Check: Bulk IPs, CIDR Ranges and Domains (33 Lists)](/tools/ip-blacklist-check/) · [Outgoing Spam cPanel: Find the Source and Stop It](/guides/find-source-of-outgoing-spam-cpanel/) · [Exim Outbound Mail Limits WHM: Stop Spam Runs Fast](/guides/exim-outbound-mail-limits-whm/) · [MailBaby Compromised Account Detection: 2026 Delisting Without Problems](/guides/mailbaby-compromised-account-delisting/)

**See also:** [cPanel Exim Queue Stuck: Flush, Thaw and Delete Frozen Mail](/guides/cpanel-exim-queue-stuck/) · [SMTP Bounce Explainer: What Your Bounce Message Means](/tools/smtp-bounce-explainer/)

## Frequently asked questions

### How do I find out which Spamhaus list I am on?

Look the IP or domain up at check.spamhaus.org. If you query DNS yourself, the return code tells you: 127.0.0.2 SBL, .3 CSS, .4 XBL, .10 or .11 PBL, and 127.0.1.x for the DBL.

### Can I remove my IP from the SBL myself?

No. Spamhaus only accepts SBL removal requests from the network or hosting provider responsible for the IP, after the problem is fixed.

### How long does a CSS listing last?

Spamhaus says CSS listings normally expire about three days after the last detection. Self-removal is allowed within limits, but the IP is relisted if the problem continues.

### What does 127.255.255.254 mean?

It is an error code, not a listing. Spamhaus returns it when the query comes through a public or open resolver that its free mirrors do not serve.

### Is there a fee for Spamhaus delisting?

No. Spamhaus says there is never a fee for removing any of its listings, and that anyone offering paid removal is running a scam.
