Back to Tools
📧 Free Tool

Email Blacklist Checker

Live DNSBL plus cached phishing feeds. You get a score for the domain or IP you typed, not a Cloudflare anycast address.

Use the From domain, or the sending IP from the email headers. Website A records are not always the sending IP.

What this blacklist checker actually does

Mail servers still query DNS blocklists before they accept a message. The important ones for email are IP lists (the machine that sent the packet) and domain/URI lists (the name in the From header or in a link). This tool asks those lists, live, and tells you listed, not listed, or unknown.

Instant checkers that only return SURBL, OpenPhish, PhishTank, and URLhaus are matching a domain against cached phishing feeds. That is useful. It is not the same as checking the IP that actually sends your mail. This tool does the feed pass and the DNSBL pass, then scores only what belongs to you.

It does not measure Gmail inbox placement. It does not score your content. It does not mean a shared Klaviyo or Google IP listing is your fault. If you want the authentication side of the same setup, use the domain scanner.

IP lists vs domain lists

Paste an IP and you get IP lists only. Paste a domain and you get the domain lists plus a short set of IPs currently published for that name: exact ip4: terms in SPF, MX hosts, then website A records. include: trees are not flattened, because that would pretend Google’s or Klaviyo’s whole range is yours.

Unknown is a real status

Spamhaus ZEN and DBL refuse Cloudflare and Google public DNS. URIBL often does the same. Returning “clean” in that situation would be a lie, so the row stays unknown. That is the same limitation MXToolbox-style tools hit unless they run their own resolvers or pay for Spamhaus DQS.

What to do with a hit

Fix the cause first. A harvested list, a compromised form, an open relay, or a neighbour on a shared IP. Then use that list’s own removal form. Requesting delist while the abuse continues just gets you relisted. The longer walkthrough is the sender reputation guide.

Blacklist Checker FAQ

What is an email blacklist?

A DNS-based blocklist (DNSBL or RBL) is a published list of IPs or domains that some mail servers refuse or filter. Providers query it over DNS. Being listed can hurt delivery with receivers that consult that list. It is not a global “you cannot send email” switch.

Does a listing mean my emails go to spam?

Not by itself. Gmail and Microsoft use their own reputation systems first. A Spamhaus hit still matters because a lot of corporate filters consult it. A listing on a minor list may change nothing. Clean on every list here also does not mean inbox placement.

Why does Spamhaus show unknown?

Spamhaus blocks queries from public resolvers such as Cloudflare and Google. This tool uses Cloudflare DNS-over-HTTPS, same as the other Inbox Connect DNS tools. When Spamhaus refuses the query it returns 127.255.255.254, which we report as unknown — not listed, not clean. A Spamhaus DQS key is required for a real ZEN/DBL answer from this environment.

Should I check the domain or the sending IP?

Both, for different reasons. Domain lists (Spamhaus DBL, SURBL, URIBL) look at the name in From/links. IP lists look at the machine that sent the packet. For most Klaviyo, Google, or Microsoft senders, that IP is not your website A record. Paste the sending IP from the email headers or the ESP if you have a dedicated IP.

Why might a Google or Microsoft IP be listed?

Shared mail hosts put thousands of senders on one address. A listing there is usually the provider’s problem, or a neighbour on the same IP. This checker flags those MX IPs so you do not treat them as your dedicated sending reputation.

How do I get off a blacklist?

Stop whatever caused the listing first: spam complaints, harvested lists, an open relay, malware on a server. Then request removal on that list’s own form. Delisting while the abuse continues just puts you back on. Shared ESP IPs are delisted by the ESP, not by you.

How is the score calculated?

Start at 100. Each high-impact listing (Spamhaus, SURBL, URIBL, URLhaus, OpenPhish, SpamCop, Barracuda) subtracts 40. Each medium listing subtracts 12. The score only uses the domain you typed, phishing/malware feeds, dedicated SPF ip4 addresses, and mail-server IPs that are not a shared provider. Website A records, Cloudflare anycast IPs, and Google/Microsoft MX IPs are shown, not scored. Unknown is not treated as clean and is not treated as a listing.

Why are some checkers instant?

Tools that return in 0s are usually matching your domain against a cached phishing/malware feed (OpenPhish, URLhaus, PhishTank), plus one URI DNSBL like SURBL. That is a domain reputation check. It is not a live sweep of sending-IP lists such as Spamhaus ZEN or Barracuda. This checker does both: cached feeds for the fast domain pass, then live DNSBL queries for IPs.

What if the domain is on Cloudflare?

Then the website A record is a Cloudflare edge IP shared by thousands of sites. Listing that address does not mean your sending reputation is burned. The checker detects Cloudflare nameservers, labels those IPs, and keeps them out of the score. Domain lists and feeds still apply, because those look at the name, not the proxy.

Listed, or just guessing why mail died?

A DNSBL hit is one cause. Authentication, list quality, and complaints are the usual ones. A free audit maps which of those is actually costing you.

Get Your Free Audit →