Seeing your IP or domain on a blacklist feels like an emergency. Sometimes it is. Often it is a listing on an obscure list that almost no mailbox provider consults, and the right response is to note it and move on. The skill is knowing which is which, and then doing the work in the right order.
That order matters more than anything else in this guide: confirm, diagnose, fix, then request removal. Teams that skip straight to the removal form usually get relisted within days, and some lists treat repeat offenders more harshly each time.
IP Lists vs Domain Lists
Blacklists, also called blocklists or DNSBLs, come in two kinds, and they work differently.
- IP lists name the server addresses that send mail. A receiving server checks the connecting IP against the list during the SMTP conversation and can reject the message before it is even accepted.
- Domain lists name domains. Filters check the domains that appear in a message, such as the From domain and, especially, domains in links. A domain listing usually feeds a spam score rather than causing an outright block, though some systems reject on it.
The distinction tells you where to look. An IP listing points at something about the sending server or its traffic. A domain listing points at your domain showing up in mail that someone, often a filter or trap network, judged to be spam. It also tells you what changing infrastructure will and will not fix: moving to a new IP does nothing for a listed domain.
The Lists That Actually Move Placement
A handful of lists are used widely enough that a listing has real consequences.
| List | Lists | What it means | Removal |
|---|---|---|---|
| Spamhaus SBL | IPs | Manually researched spam sources and spam operations | Free, via Spamhaus, after the issue is resolved |
| Spamhaus CSS | IPs | Automated listing of low-reputation sending, often snowshoe patterns or poor list quality. Part of the SBL data | Free self-service request once the cause is fixed |
| Spamhaus XBL | IPs | Compromised machines, malware and exploited hosts | Free, after the infection or open relay is cleaned |
| Spamhaus PBL | IPs | Address ranges that should not send directly to mail servers, such as dynamic consumer IPs. Not a judgement of behaviour | Free self-removal for a properly configured mail server |
| Spamhaus DBL | Domains | Domains found in spam or associated with abuse | Free request via Spamhaus once fixed |
| Barracuda BRBL | IPs | Used by Barracuda appliances and services common at businesses | Free removal request form, usually reviewed within a day |
| SpamCop SCBL | IPs | Driven by spam reports from users and traps | Expires automatically about 24 hours after reports stop |
Spamhaus ZEN is a combined zone that bundles SBL, CSS, XBL and PBL into one lookup, so a mail server querying ZEN is checking all four. If you only remember one name, it is Spamhaus. Note that Gmail and Microsoft rely mainly on their own internal reputation data, so a public listing hits hardest at corporate gateways and providers that query these lists directly. For B2B cold email, that is a lot of your audience.
Lists That Rarely Matter
UCEPROTECT deserves its own warning. Level 1 lists individual IPs and expires on its own after a period without new hits. Levels 2 and 3 list whole network ranges and entire hosting providers based on the behaviour of other customers in that range. If you are on level 2 or 3, it is almost certainly not about you. UCEPROTECT offers paid express delisting. Do not pay it. Few major receivers block on these levels, and the listing will not tell you anything about your own sending.
Beyond that, checkers report dozens of small lists run by individuals or tiny projects. Some barely update. SORBS, once a commonly checked list, was shut down in 2024, so a tool still flagging it is working from stale data. If a list does not appear in your bounce messages and placement is fine, a listing there is rarely worth hours of your time.
Step 1: Confirm the Listing
Start with the evidence. Run your sending IPs and domains through the blacklist checker and note exactly which lists flag you. Then cross-check against reality:
- Do your bounce messages name a list? Rejections often quote the list and a lookup URL in the error text.
- Has placement actually dropped? A placement test with the inbox placement test shows whether the listing is costing you inboxes.
- Is it the IP or the domain? That decides which of the next steps applies.
Confirm on the list operator's own lookup page as well. Third-party checkers can lag or misreport.
Step 2: Find the Cause Before You Ask for Removal
Every listing has a reason, and the operator's lookup page often hints at it. The common causes for cold senders are:
- Spam trap hits from old, scraped or purchased lists. Recycled traps are addresses that were abandoned and then reactivated to catch senders who never clean their data.
- High bounce rates, a sign of unverified lists. The bounce rate calculator shows whether yours is in a danger zone.
- Volume spikes from a new IP or domain sending far more than its history supports.
- Complaints from untargeted campaigns.
- Compromise, for XBL listings: a hacked account, an open relay or malware on the server.
- Misconfiguration, for PBL listings: a server sending from a range that is marked as not intended for mail.
Step 3: Fix It, Then Request Removal
- Pause sending from the listed IP or domain.
- Fix the cause: verify and prune the list, cut volume back, secure compromised accounts, or correct PTR and server setup.
- Go to the list operator's own site and request removal. Major lists do not charge for it. Explain briefly and honestly what happened and what you changed.
- For auto-expiring lists like SpamCop, simply stop the cause and wait.
- Resume at a reduced volume and ramp back up gradually, checking the list and placement as you go.
Never use a service that promises to get you delisted for a fee. Legitimate lists remove for free, and paying does not fix the behaviour that caused the listing. For more on how listings fit with reputation damage generally, see IP, domain and mailbox reputation.
How Dedicated IPs Change the Picture
On a shared IP pool, an IP listing usually reflects somebody else's campaign. You cannot fix the cause, you often cannot even request removal, and you wait on the platform. On a dedicated IP, the listing is about your traffic only. That is harder on your pride and much easier to act on: you can see the cause, fix it, request removal and verify the result yourself. Sendbox monitors blacklists for every dedicated IP and sending domain, so a listing surfaces before it shows up as a mystery drop in replies.
Domain listings are the same either way. Your domain is yours, on any infrastructure.
Staying Off Lists Afterwards
Most listings trace back to list quality and volume discipline. Verify every list before it enters a sequence, keep per-mailbox volume conservative, ramp new domains slowly, and stop mailing anyone who has not engaged after a full sequence. Check your IPs and domains on a schedule rather than only when something breaks. A listing caught on day one is a minor fix. One caught three weeks later has usually done its damage.
