If your sending IP ends up on a DNS-based blacklist (DNSBL/RBL), mail from that address is rejected or filed as spam no matter how correct your SPF, DKIM, DMARC and rDNS are. This guide covers reading the bounce message, confirming the listing, getting delisted at each major blacklist, and not landing back on the list a week later.
Start Here: Read the Bounce, Not the Symptom
A blacklisting almost always announces itself in the SMTP rejection text. The receiving server names the list that blocked you, and often the exact URL to check. Find the bounce in your mail log before doing anything else:
# Postfix
sudo grep -iE "blocked using|spamhaus|blacklist|rbl" /var/log/mail.log | tail -20
# Exim
sudo grep -iE "blocked using|spamhaus|blacklist|rbl" /var/log/exim_mainlog | tail -20
What the Rejection Actually Looks Like
These are the messages senders most often paste into a search box. The list named after blocked using is the one you need to act on:
550 5.7.1 Service unavailable; Client host [203.0.113.10] blocked
using zen.spamhaus.org; https://check.spamhaus.org/returnc/...
554 5.7.1 Service unavailable; Client host [203.0.113.10] blocked
using bl.spamcop.net
Microsoft (Outlook.com, Hotmail, Live):
550 5.7.606 Access denied, banned sending IP [203.0.113.10]
451 4.7.650 The mail server [203.0.113.10] has been temporarily
rate limited due to IP reputation
Yahoo / AOL:
553 5.7.1 [BL21] Connections not accepted from IP addresses
on Spamhaus PBL
421 4.7.0 [TSS04] Messages from 203.0.113.10 temporarily deferred
Some webmail clients and control panels paraphrase this as "an RBL has blocked the sender's IP address" without naming the list. That wording is not a specific blacklist — treat it as a prompt to run the lookup below and find out which one.
Note the first digit. A 5xx code is a permanent rejection: that message is gone and will not retry. A 4xx code is a temporary deferral: the message is still queued and will retry, so you have hours rather than minutes to react.
Confirm the Listing
Check the IP against the major lists at once with our free IP blacklist checker — enter the public IPv4 address of the VPS, not your home or office IP.
To query one zone yourself, reverse the four octets of the IP and append the blacklist's zone. For 203.0.113.10 the reversed form is 10.113.0.203:
dig +short 10.113.0.203.zen.spamhaus.org
dig +short 10.113.0.203.bl.spamcop.net
dig +short 10.113.0.203.b.barracudacentral.org
An answer in the 127.0.0.x range means listed. Empty output (NXDOMAIN) means clean. The last octet of the answer identifies which sub-list matched — for Spamhaus ZEN, 127.0.0.2 is SBL, 127.0.0.4 to 127.0.0.7 is XBL, and 127.0.0.10 or 127.0.0.11 is PBL.
Ask for the reason text at the same time:
dig +short -t TXT 10.113.0.203.zen.spamhaus.org
Which List You Are On Changes What You Do
Spamhaus SBL — a human decision that your IP sent spam. Fix the cause, then request removal; Spamhaus reviews manually.
Spamhaus XBL — the IP looks compromised or is running an open proxy or relay. Assume a security incident until proven otherwise. Self-removal is available once the machine is clean.
Spamhaus PBL — the address range is registered as one that should not send mail directly. On a VPS this is a provider registration issue, not a reputation problem, and it is worth raising a ticket with your host rather than self-removing.
SpamCop — driven by spam reports and expires automatically. Listings clear roughly 24 hours after the last report, so the work is stopping the reports, not filing paperwork.
Barracuda — affects a meaningful share of business mail. Manual removal form.
UCEPROTECT — read the level before you panic. Level 1 is your IP. Level 2 lists whole ranges and Level 3 lists entire networks because of a neighbour's behaviour, which means a Level 2 or 3 entry usually says nothing about you. Most receivers do not use Levels 2 and 3, and UCEPROTECT asks for payment to remove entries early. Confirm real delivery damage before spending anything.
SORBS — retired in mid-2024 and no longer publishes listings. If a checker still shows a SORBS result, the checker is out of date, not your IP.
Where to Request Removal
Do not send anything from the address until the underlying cause is fixed — a re-listing minutes after delisting is much harder to clear than the first one.
- Spamhaus (SBL, XBL, PBL) — check.spamhaus.org. Look up the IP; the result page carries the removal link for that specific listing.
- Barracuda Reputation Block List — barracudacentral.org/rbl/removal-request
- SpamCop — spamcop.net/bl.shtml. Lookup only; entries expire on their own.
- UCEPROTECT — uceprotect.net/en/rblcheck.php
- Microsoft / Outlook.com — sender.office.com. Microsoft runs its own reputation system rather than a public RBL, so a clean public lookup and an Outlook block can be true at once.
- SpamRATS — spamrats.com/lookup.php
- Proofpoint / Cloudmark — support.proofpoint.com/dnsbl-lookup.cgi
Google does not operate a public blacklist. If Gmail is the problem, the signal you need is in Google Postmaster Tools, which reports domain and IP reputation for your sending.
What to Fix Before You Submit
Removal forms ask what changed. Have a real answer:
- Stop outbound mail from the IP so the evidence stops accumulating.
- Look for a compromise. An XBL listing in particular usually means something on the server is sending without your knowledge. Check the queue size and who is injecting mail:
mailq | tail -1 sudo grep "sasl_username" /var/log/mail.log | awk '{print $NF}' | sort | uniq -c | sort -rn | head - Confirm you are not an open relay. In Postfix,
mynetworksshould not contain0.0.0.0/0, andsmtpd_relay_restrictionsshould end inreject_unauth_destination:postconf mynetworks smtpd_relay_restrictions - Verify authentication and rDNS. SPF, DKIM and DMARC published, and the PTR record for the IP matching the hostname your MTA announces in HELO.
- Purge the bad addresses that generated the bounces and complaints in the first place.
How Long Removal Takes
SpamCop clears itself within about a day of the last report. Spamhaus self-removals for XBL and PBL take effect in minutes to a few hours once submitted, while an SBL entry waits on manual review and can take a day or more. Barracuda is typically same-day. What none of these restore is reputation at the mailbox providers — Gmail and Outlook keep their own history, and that recovers over weeks of clean sending, not the moment the RBL entry disappears.
Resuming Safely
Treat the address as new. Go back to a fraction of your previous volume and build up, sending first to the recipients most likely to open, and watch the logs each day rather than at the end of the campaign. The 30-day IP warm-up schedule gives the daily figures.
Staying Off the Lists
- Use a dedicated IPv4 address, so no other tenant's sending can list you. Every VPS For Life plan includes one.
- Check the IP on a schedule rather than after delivery drops — you want to find a listing before your recipients do.
- Register for feedback loops where providers offer them, and act on the complaints.
- Send only to addresses that opted in. A purchased list can list a new IP inside a single campaign.
- Keep the server patched and the mail submission ports authenticated, so it is never the compromise that lists you.
Common Errors
Delisting, then immediately sending the same campaign — the behaviour that caused the listing is still there, and the second listing is treated far less generously than the first.
Checking the wrong IP — run the lookup against the address the mail actually leaves from. Behind a relay, NAT or proxy that is not the address you see in the client area. curl -s ifconfig.me from the server settles it.
Reading a Level 2 or 3 UCEPROTECT entry as your problem — those list your neighbours or your provider's whole network, and most receivers ignore them.
Assuming a clean lookup means clean delivery — Microsoft and Google filter on private reputation data that no public RBL check can see.
FAQ
Will a blacklisting permanently damage my domain?
No. Public blacklists here list IP addresses, not domains, and clean sending after delisting restores standing. Domain-level reputation at the large providers takes longer to recover than the RBL entry does to clear.
Can I just move to a new IP address?
It works and it is usually the wrong first move. A fresh IP has no reputation at all, so it needs a full warm-up, and if the cause was a compromise or a bad list the new address will be listed just as fast.
How often should I be checking?
Weekly for a low-volume sender, daily while a campaign is running.
Continue Reading
- IP Warm-Up: A Safe 30-Day Schedule for New Sending IPs
- How to Monitor Email Deliverability and Sender Reputation
- VPS Security Checklist for Beginners
Free tools: IP Blacklist Checker · SPF, DKIM & DMARC Checker · PTR / rDNS Lookup.
Browse more articles in Email Hosting & Deliverability.