Bounce messages mentioning "blocked", "listed" or a name like Spamhaus usually mean one thing: the IP address or domain you are sending from appears on a blocklist that the recipient's server consults. An email blacklist check tells you whether that is the case and which list is involved. This guide explains how blocklists work, how to check them yourself, and how to get removed, which almost always starts with fixing what caused the listing.
What email blacklists are
Email blacklists, now usually called blocklists or DNSBLs (DNS-based blocklists), are databases of IP addresses and domains associated with spam, malware or abuse. Receiving mail servers query them during delivery and may reject, filter or score mail from listed sources. There are two broad kinds:
- IP blocklists list the address of the server that connected to send the message.
- Domain blocklists (sometimes called URI or RHSBL lists) list domains that appear in the message, in the sender address or in links.
Lists differ greatly in how they add and remove entries, and in how widely they are used. A listing on a widely used list operated by an established organisation such as Spamhaus can stop mail to many recipients. A listing on an obscure list that few servers consult may have no visible effect.
First: which IP do you actually send from?
Before you check anything, be sure you are checking the right address. It is the public IP of the server that hands your mail to the recipient's server:
- Google Workspace, Microsoft 365 and other hosted providers: their shared sending IPs. You do not manage these, and listings are rare and handled by the provider. Check your domain instead.
- Your own mail server: its public IP. If it sits behind a NAT router, that is the router's public address, which you can find with What is my IP from the same network.
- A bulk or transactional email service: shared or dedicated IPs owned by that service. For dedicated IPs, the service's dashboard usually shows listings.
The easiest way to be certain is to read the Received: headers of a message you sent, looking for the first hop outside your own systems.
How to run an email blacklist check
Use a multi-list checker
Online blocklist checkers query dozens of DNSBLs at once and show any listings, often with links to each list's lookup page. They are the quickest starting point.
Query a DNSBL directly
Because DNSBLs work over DNS, you can check one yourself. Reverse the octets of the IP and append the list's zone. For 203.0.113.25 and Spamhaus's ZEN list:
dig 25.113.0.203.zen.spamhaus.org A +short
- No answer (NXDOMAIN) means not listed.
- An answer in
127.0.0.xmeans listed; the last number indicates which sub-list or reason.
A caveat: some large lists refuse or give misleading answers to queries arriving via big public resolvers such as 8.8.8.8, because of query volume. If you get unexpected results, use the list's own web lookup page, which also explains the reason for a listing.
Check the bounce message
Rejections usually name the list and include a URL. That URL is the most reliable pointer to what is blocking you and why.
Fix the cause before requesting removal
Requesting delisting without fixing the cause typically leads to relisting, and some lists make the second removal slower or impossible to self-serve. Common causes:
| Cause | What to check |
|---|---|
| Compromised email account | Unusual volumes in sent logs; reset passwords and enable multi-factor authentication |
| Malware on an office PC | Outbound connections on port 25 from desktops; block them at the firewall and clean the machine |
| Abused web form or script | Contact forms or old CMS plugins sending mail; add rate limits and update or remove the code |
| Open relay | A mail server accepting and relaying mail without authentication; reconfigure to require it |
| Poor list practices | Old or purchased lists hitting spam traps; clean the list and use confirmed opt-in |
| Missing or generic reverse DNS | Set a proper PTR record on the sending IP |
| Dynamic or residential IP | Some lists include these ranges by policy; send through a proper mail service instead |
The port checker can help confirm whether your server is exposing mail ports you did not expect.
Requesting removal
- Go to the specific list's website and use its lookup tool to see the listing reason and removal process.
- Confirm you have fixed the cause, and be ready to say briefly what you changed.
- Submit the removal request. Many lists offer self-service removal; others expire listings automatically after the abuse stops; a few require contacting them.
- Be honest and concise. Delisting teams handle many requests and respond best to clear facts.
- Recheck after the stated processing time, and monitor for relisting over the following weeks.
Be wary of anyone who charges a fee to remove you from a list. Reputable lists do not require payment for removal, and paying a third party to "delist" you does not fix anything.
If your domain is listed
Domain listings usually stem from the domain appearing in spam, either because your own mail was spammy or because someone abused your domain in links or as a fake sender. Fix the source, then strengthen your defences: publish SPF, DKIM and DMARC at enforcement so spoofed mail is rejected. The SPF, DKIM and DMARC checker confirms your setup.
Preventing future listings
- Block outbound port 25 from everything except your mail servers.
- Require authentication for all mail submission, on ports 587 or 465.
- Enforce multi-factor authentication on email accounts.
- Monitor blocklist status of sending IPs regularly, not only when mail bounces.
- Keep lists clean and honour unsubscribes promptly.
Key takeaways
- Check the IP that actually delivers your mail, and your domain, against major blocklists.
- DNSBLs can be queried with a reversed-IP DNS lookup, but use each list's own site for reliable results and reasons.
- Fix the root cause before requesting removal, or you will be relisted.
- Legitimate lists do not charge for removal.