All posts

How to Get Removed From an Email Blacklist (Spamhaus and More)

··9 min read

To get off an email blacklist, first find out which list has you and why, then fix the cause. Only after that do you request removal through that list's own channel. SpamCop, Spamhaus CSS and UCEPROTECT Level 1 expire listings automatically once the problem stops. The Spamhaus SBL needs your ISP to ask, and Spamhaus never charges for removal.

Most people skip the first step. They see "listed" on a checker, panic, and file removal requests with lists that don't matter, or with lists that didn't actually list them. Before the delisting steps, here is a test we ran showing why a checker's answer can be wrong in both directions.

Check that the listing is real, because public DNS can lie

A blacklist (more properly a DNS blocklist, or DNSBL) is queried over DNS, and the DNS resolver you ask changes the answer. When we queried Spamhaus through popular public resolvers, we got answers that would mislead a checker.

Every DNSBL keeps a permanent test entry, 127.0.0.2, which always returns "listed", and 127.0.0.1, which never does. Spamhaus also lists dbltest.com on its domain list. On 2 October 2026 (UTC) we queried these through five resolvers from the same laptop. The raw output is saved with our research notes.

Resolver Spamhaus ZEN, test IP 127.0.0.2 Spamhaus DBL, dbltest.com Barracuda / SpamCop test IP
Our ISP's resolver 127.0.0.2, .4, .10 (correct) 127.0.1.2 (correct) 127.0.0.2 (correct)
OpenDNS 208.67.222.222 Correct Correct Correct
Cloudflare 1.1.1.1 127.255.255.254 (error code) 127.255.255.254 (error code) Correct
Quad9 9.9.9.9 127.255.255.254 (error code) 127.255.255.254 (error code) Correct
Google 8.8.8.8 NXDOMAIN in 9 of 10 attempts NXDOMAIN in 8 of 10 attempts Correct

Two different failure modes show up here.

Cloudflare and Quad9 returned an error code that looks like a listing. Spamhaus documents three error return codes: 127.255.255.252 means a typo in the DNSBL name, 127.255.255.254 means a "query via public/open resolver/generic unattributable rDNS", and 127.255.255.255 means too many queries. In Spamhaus's own words, "none of these return codes relate to the reputation of the query". A checker that treats any 127.x answer as a hit will report every IP as listed, including clean ones. We got 127.255.255.254 for 127.0.0.1, the address that is never listed.

Google returned "does not exist" for an address that is always listed. NXDOMAIN is what a DNSBL returns when you are not listed. So a checker running on Google's resolver would have told us the permanent Spamhaus test entry was clean, most of the time. That is the more dangerous of the two failures, because it hides a real listing.

Barracuda and SpamCop answered correctly through every resolver we tried.

The lesson: run a Spamhaus check through Spamhaus's own IP and Domain Reputation Checker, or from a server using its own recursive resolver. If you check by hand, test 127.0.0.2 first. If that doesn't come back listed, your resolver can't be trusted for this.

How to query a blocklist yourself

You query an IP by reversing its four octets and adding the list's zone. A domain is queried as-is, with the zone added. Here is the query for the test IP 127.0.0.2:

dig +short 2.0.0.127.zen.spamhaus.org
dig +short dbltest.com.dbl.spamhaus.org
dig +short 2.0.0.127.b.barracudacentral.org
dig +short 2.0.0.127.bl.spamcop.net

No answer (NXDOMAIN) means not listed. An answer in 127.0.0.x means listed, and on Spamhaus ZEN the last digit tells you which list. Spamhaus publishes the return codes:

ZEN return code List What it means for you
127.0.0.2 SBL Spamhaus has manually listed the IP or range
127.0.0.3 CSS Automated listing for low-reputation mail
127.0.0.4 XBL The IP shows signs of compromise
127.0.0.9 SBL (DROP) Hijacked or criminal network ranges
127.0.0.10 / .11 PBL Policy listing for IPs that shouldn't send direct-to-MX
127.0.1.2 (DBL) DBL The domain is listed as a spam domain

That last digit decides which removal process applies, so record it before you do anything else. If you'd rather not run dig, our blacklist check queries the common lists for an IP or domain in one go.

Which list, how to delist, and how long it lasts

Each list has its own removal channel and timing. Use only the list's own channel, and only after the cause is fixed. Every expiry below comes from that list's own published policy. Where a list publishes no figure, the table says so.

List How listings happen How to delist Expiry, as published
Spamhaus SBL Manual listing by Spamhaus for spam, snowshoeing or malicious hosting Your ISP must request it: "Removal requests must be sent by the Internet Service Provider in charge of the listed IP address(es)" (SBL) No automatic expiry published
Spamhaus CSS Automated: low-reputation mail, poor list hygiene, bad HELO, missing or mismatched reverse DNS Self-service at check.spamhaus.org, after fixing the cause (CSS) "Normally, three days after last spam detection"
Spamhaus XBL Automated: compromised machines, malware, proxies, credential abuse check.spamhaus.org is "the only place where XBL removals are handled" (XBL) Expires "after a period of time" once the behaviour stops (no figure given)
Spamhaus PBL Policy: IP ranges that shouldn't send direct-to-MX, such as consumer broadband Only if you run a mail server on a static IP with proper DNS (PBL FAQ) Not a reputation listing, so no expiry
Spamhaus DBL Domains with signs of spam or malicious activity check.spamhaus.org; "using the form does not guarantee removal" (DBL) "Most listings will expire automatically after they cease to have associated activity"
Barracuda BRBL Automated reputation system Form needing IP, email and phone; "multiple requests will also be ignored" (removal request) "Typically investigated and processed within 12 hours" with a valid explanation
SpamCop Spam reports from users and traps No manual delisting. SpamCop asks you not to write in for early removal (FAQ) "Automatically delisted after 24 hours with no new spam reports"; up to 4 hours to propagate
UCEPROTECT L1 Single IPs hitting its spam traps Wait, or pay for optional express removal (L1 removal) "7 days after the last spam email from it hits our SPAMTRAPS"
UCEPROTECT L2 / L3 Whole allocations or ASNs, escalated from L1 hits by others Your provider has to clean up its network Not something you can fix alone

A few notes that change what you should do.

The PBL is not an accusation. Spamhaus says a PBL listing reflects how an IP range is classified, not anything you did. It also says PBL listings "do not prevent the sending of email unless the user's email program is not authenticating correctly". If you're on PBL from an office or home connection, the fix is to send through your provider's authenticated relay on port 587, not to delist. Spamhaus warns that "individuals that remove many IPs may find their removal access revoked."

CSS will relist you straight away if the problem continues. Spamhaus says CSS "will allow the removal of an IP, but it will also re-list it immediately if a problem continues to be detected", and that "self-removals are limited". Removing first and fixing later uses up a limited resource and gains nothing.

UCEPROTECT's paid option is optional. The Level 1 listing expires on its own after seven days without new trap hits. We couldn't read the express fee: the page renders it as an image, so we haven't quoted it. Levels 2 and 3 list whole provider ranges because of other customers' behaviour. UCEPROTECT itself warns anyone using Level 2 to "be prepared to lose a few mails too".

Spamhaus never charges. Its SBL page says: "There is never any charge or fee associated with removing any Spamhaus listing. Any offer from anyone to remove any Spamhaus listing for a fee is a scam."

Microsoft's own block is separate

Microsoft runs its own blocked senders list for Microsoft 365, separate from the public blocklists, with its own delisting process.

According to Microsoft's delisting documentation, a bounce from a Microsoft 365 recipient that reads:

550 5.7.606-649 Access denied, banned sending IP [IP address]

means you're on Microsoft's blocked senders list. To get off it:

  1. Go to the Office 365 Anti-Spam IP Delist Portal at sender.office.com.
  2. Enter the email address that received the bounce and the IP from the error. The portal takes one of each per visit.
  3. Click the confirmation link in the email it sends, then select Delist IP.

Microsoft says it "might take up to 24 hours or longer". If the bounce says 5.7.511 Access denied, banned sender instead, the portal won't work. Microsoft says to forward the bounce to delist@microsoft.com with the full code and IP, and that it will reply within 48 hours. Outlook.com consumer addresses have a separate support form, linked from the same page. An Outlook.com bounce coded 550 OU-001 points you back to Spamhaus, so start with the ZEN check above. Our guide to why emails land in Outlook's Junk folder covers the other Outlook.com codes.

Fix the cause before you ask

A delisting request without a fix is wasted, because the same behaviour gets the same IP relisted. The lists' own listing reasons point to a short set of causes.

Mail server misconfiguration. Spamhaus's CSS page names these directly: an SMTP server announcing itself with a HELO such as localhost.localdomain, missing reverse DNS, and reverse DNS that doesn't match forward DNS. Set a proper hostname, a PTR record that resolves back, and a HELO that matches.

A compromised machine or account. XBL listings are about compromise: malware, open proxies, and mail relayed with stolen credentials. Find the infected device or the leaked SMTP password before you request anything.

Bad addresses and spam traps. CSS cites "poor list-hygiene", and UCEPROTECT and SpamCop are driven by traps and reports. Trap hits come from old, scraped, bought or typo-ridden addresses. Our post on how spam traps get onto your list covers the mechanics. The practical fix is to stop mailing addresses nobody has engaged with, and to verify the list so dead and invalid addresses never reach the send. Verification won't catch every trap, because a pristine trap is designed to look like a real mailbox. It does remove the invalid and long-dead addresses that recycled traps tend to sit among.

Volume from a cold IP or domain. Sudden volume from somewhere with no history looks like what these systems are built to catch. Slow down and ramp up gradually.

A delisting order that works

  1. Confirm the listing through check.spamhaus.org or a resolver that passes the 127.0.0.2 test. Note the exact return code.
  2. Ignore lists that don't matter to your recipients. Rejection messages often name the list that triggered them, which tells you which lists your recipients' servers actually use.
  3. Find the cause using the table above: configuration, compromise, list quality or volume.
  4. Fix it, then stop sending from the affected IP or domain until the fix is in place.
  5. Request removal once, through the list's own channel. For the SBL, that means your ISP.
  6. Wait out automatic expiry where the list has one, rather than filing repeat requests that the list ignores or holds against you.
  7. Watch for relisting for a couple of weeks. A relist means the cause is still there.

Getting delisted is usually quick. Staying delisted depends entirely on step 3. If the listing followed weeks of poor results rather than one incident, our 30-day reputation recovery plan is the longer version of this process.

Common questions

How long does it take to get off an email blacklist?

It depends on the list. SpamCop delists automatically 24 hours after the last spam report, Spamhaus CSS normally three days after the last detection, and UCEPROTECT Level 1 seven days after the last trap hit. Barracuda says removal requests are typically processed within 12 hours. The Spamhaus SBL has no published timer and needs your ISP to ask.

Should I pay to be removed from a blacklist?

Not for Spamhaus. It says there is never a fee for removing any of its listings, and that any offer to remove one for a fee is a scam. UCEPROTECT does sell optional paid express delisting from Level 1, but the same listing expires for free after seven days without new trap hits.

Why does a blacklist checker say I'm listed on Spamhaus with code 127.255.255.254?

That is not a listing. Spamhaus returns 127.255.255.254 when the query came through a public or open DNS resolver it doesn't allow, such as Cloudflare or Quad9. The checker is misreading an error code as a listing. Query through a resolver Spamhaus accepts, or use check.spamhaus.org.

Can I get my domain off a blacklist by changing IP address?

Only if the listing was for an IP. Domain lists such as the Spamhaus DBL list the domain itself, so it follows you to any IP. Changing IP without fixing the cause just moves the same behaviour to a new address, which the same traps and reports will catch again.

Verify unlimited addresses for $29.99/month

Real SMTP mailbox checks. No credits, no per-email fees.

Get Started