Ana içeriğe geç

Guides / concepts

What is DNS Blacklist

A DNS blacklist (DNSBL, or RBL, for Realtime Blackhole List) is a database of IP addresses flagged as spam sources, which mail servers query to reject or filter incoming mail. If your mail server's IP gets listed, your outgoing email starts bouncing or landing in spam, usually with no error message that points at the cause.

How DNSBL filtering works

When an email arrives at a receiving mail server, that server checks the sender's IP address against one or more DNSBL databases. If the IP is listed, the message is blocked or flagged before it reaches an inbox. Dozens of independent DNSBL databases operate at once, each maintained by a different organization with its own listing criteria, which is why the same IP can be clean on one blacklist and flagged on another at the same time.

How an IP gets blacklisted

Getting listed does not require sending spam yourself:

  • Genuine compromise. The most direct path. A server is compromised and used to send mass spam mailings, then reported and listed.
  • Shared IP contamination. If your mail or web server shares an IP address with other tenants, which is normal on budget shared hosting, another tenant's spam or phishing gets the shared IP listed with no fault or action on your part.
  • Targeted abuse. A competitor or bad actor can in some cases deliberately trigger a listing against a target's IP as a form of sabotage.
  • Misconfiguration. An open mail relay or a misconfigured server can be exploited by spammers without the owner noticing, which produces a listing that looks self-inflicted but was not intentional.

What being blacklisted costs you

A DNSBL listing does not take your website offline. It breaks email specifically. Transactional messages such as password resets, order confirmations and invoices stop arriving, and marketing sends land in spam in bulk, while the site itself shows no sign of a problem. Because there is no visible outage, a listing often goes unnoticed until customers start saying "I never got the email", well after the deliverability damage is done.

How to check if you are blacklisted

To see whether an IP or domain is currently listed, run it through the free DNSBL check, which queries multiple blacklist databases at once and returns results in seconds with no signup. If you are listed, the result names the database that flagged you, which is what you need in order to contact that organization and request removal. The removal process varies by list, but it generally starts with proving that the underlying problem, a compromised account or an open relay, is fixed. For the step-by-step version of the check, see how to check whether an IP or domain is blacklisted.

Monitor for blacklisting continuously

A listing can happen at any time, and on shared infrastructure it can happen without any change on your end, so a one-time check only tells you about right now. DNS blacklist monitoring checks your IP or domain against multiple DNSBL databases on a schedule and alerts you when a new listing appears, so the news comes from your own monitoring rather than from a drop in email deliverability with no obvious cause. The DNSBL check guide covers how to set that check up, and the rest of the monitoring concepts section covers the neighboring terms.

Reducing the risk of getting listed

  • Keep server software and mail infrastructure patched and up to date.
  • Run a firewall and keep antivirus and anti-malware protection active on any server that sends mail.
  • Avoid shared hosting for anything mail-sensitive where you can. An isolated IP removes the risk of being listed because of a neighbor.
  • Never send unsolicited bulk email. That is the surest way to get an IP listed deliberately rather than by accident.

Check it now

Run the free check against your own site - no account needed.

Blacklist check

Monitor this permanently

Get alerted the moment it breaks: HostTracker checks from 300+ locations and notifies you by email, SMS, Slack, Telegram and more.

HostTracker features