ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Site Clusters & Multi-IP

IP Blacklist Check and Removal: Spamhaus, Barracuda and RBL Lookups for Site Clusters and Mail Servers

6 steps 12 min read 1 views 0
On this page

For site-cluster and mail servers, a blacklisted IP means mail landing in spam or being rejected, browsers showing red warnings and search rankings dropping. This guide covers the IP blacklist check (Spamhaus ZEN, Barracuda, MXToolbox multi-RBL lookup and Google Safe Browsing), the general delisting process and how to avoid future listings with rDNS, SPF/DKIM/DMARC and rate limits. Commands work on Debian/Ubuntu and CentOS/Rocky/AlmaLinux.

Step 1: How IP Blacklists (RBLs) Work

An RBL (real-time blackhole list) is queried over DNS: reverse the IP's four octets, append the list's zone and resolve it. Any answer means the IP is listed. Mail servers query these lists automatically on incoming mail. Site-cluster IPs can be affected if they were previously used for spam or malicious pages, or if the whole range is flagged.

Step 2: Query the Spamhaus ZEN Blacklist with dig

Spamhaus ZEN combines SBL, XBL, PBL and more, and is one of the most widely used lists:

# Install dig
apt install -y dnsutils     # Debian/Ubuntu
yum install -y bind-utils   # CentOS/Rocky/AlmaLinux

# Check 203.0.113.10: reverse the four octets and append zen.spamhaus.org
dig +short 10.113.0.203.zen.spamhaus.org
# No output = not listed; 127.0.0.x = listed

Common return codes: 127.0.0.2 = SBL (spam source), 127.0.0.3 = CSS, 127.0.0.4–127.0.0.7 = XBL (infected or exploited hosts), 127.0.0.10–127.0.0.11 = PBL (ranges that should not send mail directly).

Spamhaus refuses queries from public resolvers such as 8.8.8.8 or 1.1.1.1 and answers with error codes like 127.255.255.x — that does not mean you are listed. Use the server's own recursive resolver or the official website.

Step 3: Check Multiple RBLs and a Whole /24

Site clusters often have dozens or hundreds of IPs. This script checks several lists at once or scans a whole range:

#!/bin/bash
# rbl-check.sh  usage: bash rbl-check.sh 203.0.113.10
IP="$1"
REV=$(echo "$IP" | awk -F. '{print $4"."$3"."$2"."$1}')
for RBL in zen.spamhaus.org b.barracudacentral.org bl.spamcop.net psbl.surriel.com; do
  RES=$(dig +short "$REV.$RBL" A)
  if [ -n "$RES" ]; then echo "LISTED  $RBL  $RES"; else echo "ok      $RBL"; fi
done

# Site clusters: scan a whole /24 (203.0.113.0/24) against Spamhaus ZEN
for i in $(seq 1 254); do
  R=$(dig +short "$i.113.0.203.zen.spamhaus.org")
  [ -n "$R" ] && echo "203.0.113.$i $R"
done

Barracuda requires you to register your DNS server before DNS lookups work; if you get no answers, use their web lookup. Useful web tools: MXToolbox Blacklist Check (100+ RBLs at once), the Spamhaus IP and domain reputation checker, Barracuda Central lookup and Cisco Talos reputation lookup.

Step 4: Check Google Safe Browsing and the Transparency Report

Red browser warnings usually come from Google Safe Browsing. Enter your domain on the "Safe Browsing site status" page of Google's Transparency Report. If it is flagged, remove injected malware or phishing pages first, then request a review under "Security issues" in Google Search Console.

Step 5: General Delisting Procedure

  1. Find the root cause: look for compromised sites, stolen mailbox credentials, open relays or unusual outbound traffic. Fix it fully, or the IP will be listed again quickly.
  2. Submit a removal request on each list's website: most lists offer an online form where you confirm the issue is resolved; some expire listings automatically after a clean period.
  3. Range-level listings must be handled by the IP holder. Open a ticket with the lookup results and we will help.

Step 6: Prevent Your IP from Being Blacklisted Again

Give sending IPs an rDNS that matches your domain (see the "rDNS/PTR" tutorial) and publish SPF, DKIM and DMARC:

; Example DNS records (add them at your DNS provider)
example.com.                   TXT  "v=spf1 ip4:203.0.113.10 -all"
default._domainkey.example.com. TXT "v=DKIM1; k=rsa; p=(your public key)"
_dmarc.example.com.            TXT  "v=DMARC1; p=quarantine; rua=mailto:[email protected]"

# Verify rDNS and SPF
dig +short -x 203.0.113.10
dig +short TXT example.com

Rate-limit your mail server so it never sends large bursts:

# Postfix sending rate limits
postconf -e "smtpd_client_message_rate_limit = 100"
postconf -e "anvil_rate_time_unit = 3600s"
postconf -e "default_destination_rate_delay = 1s"
systemctl restart postfix

# Check the mail queue; investigate at once if it grows abnormally
mailq | tail -n 1

For site clusters: keep CMS and plugins updated, scan for malware regularly, never send bulk marketing mail from cluster IPs and avoid hosting dubious scraped content.

FAQ

Why is a brand-new IP already in the PBL?

The PBL is a policy list saying the range should not deliver mail directly; it is not a bad-reputation listing. If you need to send mail, set correct rDNS and request removal on the Spamhaus website, or open a ticket for help.

How long does delisting take?

From minutes to several days depending on the list. Always fix the root cause first — repeated listings get harder to remove.

What if the IP cannot be delisted?

Open a ticket to ask about a replacement IP; replacing or adding IPs is a paid service.

If you still need help, open a support ticket with the IP and lookup results, and the IMIDC 24/7 team will assist.

Was this answer helpful?

Related Tutorials