Networking · Network & IP
How IP reputation works: DNSBLs and what makes an IP get listed
Email servers, fraud-detection APIs, and signup forms all check IP reputation before deciding whether to accept a connection. The check is fast — under 200 milliseconds — and runs against a handful of trusted DNSBL (DNS-based Blackhole List) providers. If your IP appears on too many of them, your emails land in spam, your signups get flagged, and your automation breaks.
TL;DR
IP reputation scores come from real-time DNS blacklists. Seven of them, plus heuristics. Here is how the check works and what to do if your IP is listed.
The seven DNSBLs that matter
Spamhaus is the largest and most influential — its SBL, XBL, and PBL lists together cover most spam-source IPs worldwide. Spamcop is second, run by Cisco. Barracuda and CBL focus on open relays and compromised hosts. UCEPROTECT is more aggressive (lists whole ranges for one bad actor). Mailspike and PSBL (inactive) round out the list. A clean IP returns no hits across all of them. A compromised IP appears on 2-5 lists, usually Spamhaus first.
Why an IP gets listed
Three common reasons: (1) the IP sent spam, either because a server on it is misconfigured as an open relay, or because a customer of the ISP got a malware infection and used the IP for spam; (2) the IP is part of a known residential or mobile block that shouldn't be sending mail directly (a common policy for major ISPs); (3) the IP belongs to a hosting provider that has a high concentration of bad actors (some cheap hosting ranges). All three result in the same listing, even though the underlying cause is different.
What to do if you are listed
First, identify which list and why. Spamhaus has a lookup tool that shows the reason category. If it is an open relay or compromised host, fix the underlying issue (close port 25, scan for malware) and request delisting. If it is a policy list (PBL, PSBL), you request delisting by following the provider's instructions and configuring your server to send mail through the ISP's relay. If it is a known-bad range you cannot escape, you need to switch hosting providers. The delisting process usually takes 24–72 hours once the underlying issue is fixed.
Why reputation checks are fast
DNSBL queries are DNS queries. A check against seven DNSBLs is seven DNS lookups against well-cached nameservers, which takes about 100–200 milliseconds total. This is why reputation can be checked synchronously on every signup or email send without adding noticeable latency. The DNSBL infrastructure is designed to be cheap and fast — it has to be, because mail servers query it billions of times a day.
Try it →
Run the IP reputation tool on sitetrace.it.com — paste a value and get an instant answer.
Open IP reputation