Field notes · Cold Email

    Email Blacklist Check: How to Find and Remove Your IP or Domain (2026 Guide).

    How to check if your IP or domain is on email blacklists like Spamhaus, SORBS, and Barracuda - plus the exact delisting process for each and how to prevent it from happening again.

    8 sections
    Cold Email
    10
    Email Blacklist Check: How to Find and Remove Your IP or Domain (2026 Guide)

    If your cold email reply rate just collapsed overnight, you are probably on a blacklist. Run your sending IP and domain through MXToolbox first - it checks 30+ blacklists in one pass. If you are listed on Spamhaus, SORBS, Barracuda, or any major DNSBL, stop sending from that IP or domain immediately, fix the root cause, then submit a delisting request through each blacklist's official form. Most reputable blacklists remove first-time offenders within 24-72 hours once the underlying issue is resolved.

    Quick answer: Use MXToolbox Blacklist Check (mxtoolbox.com/blacklists.aspx) to scan your IP and domain against 30+ major blacklists in one query. For each listing, follow the blacklist's specific delisting URL, fix the root cause (dirty list, spam complaints, compromised inbox, or volume spike), and submit a removal request. Never delist before fixing the cause - repeat listings get harder to recover from each time.

    What Is an Email Blacklist?

    An email blacklist (also called a DNSBL or RBL - DNS-based Blocklist or Real-time Blocklist) is a public database of IP addresses and domains flagged for sending spam, phishing, or malware. Mail servers query these lists in real time during the SMTP handshake. If your IP or domain appears on a list the recipient's server trusts, your email is either rejected outright or dumped into spam.

    There are two flavors of blacklist that matter for cold outreach:

    • IP-based blacklists - list the sending IP address. Affects you if you send from a dedicated IP or share an IP that gets flagged.
    • Domain-based blacklists - list the sending domain or any URL inside the email body. A clean IP cannot save you if your domain is listed.

    Some blacklists are operated by independent anti-spam organizations (Spamhaus, SpamCop). Others are run by ISPs or security vendors (Barracuda, Microsoft, Cloudmark). A handful are reputation-based and use machine signals rather than human complaints. They are not all equal in weight, and getting listed on Spamhaus is a different scale of problem than getting listed on a smaller regional blacklist.

    How to Check If You Are Blacklisted

    You do not need to check 30 blacklists one by one. Three free tools cover most of what you need:

    • MXToolbox Blacklist Check (mxtoolbox.com/blacklists.aspx) - the standard. Enter an IP or domain, get results across 30+ blacklists in under 10 seconds. Free for manual lookups, paid plans for monitoring and alerts.
    • MultiRBL.valli.org - checks 100+ blacklists, more thorough than MXToolbox but noisier. Useful as a second pass when MXToolbox comes back clean but your deliverability still looks broken.
    • HetrixTools Blacklist Monitor - free monitoring with alerts. Set it up once per sending IP and domain, get an email the moment you get listed.

    What to check:

    1. Your sending IP address (find it in your email provider's outbound headers or run a test send to mail-tester.com).
    2. Your sending domain (the domain in your From address).
    3. Your tracking domain (the custom subdomain you use for link tracking). This one gets missed constantly and is a top cause of "clean IP, still in spam" problems.
    4. Any URL you link to in your email body, including landing pages and calendar booking links.

    The 30+ Major Blacklists You Should Know

    Not all listings carry the same weight. Here is the breakdown of the blacklists that actually affect cold email deliverability in 2026.

    Tier 1 - The ones that will kill your campaign

    BlacklistTypeWhat Triggers a ListingDelisting Difficulty
    Spamhaus SBLIPConfirmed spam sources, snowshoe spammingHard - requires evidence of remediation
    Spamhaus CSSIPSnowshoe spam patterns, low-volume scattered spamModerate - auto-delisting if behavior stops
    Spamhaus XBLIPCompromised machines, exploited serversModerate - fix the compromise first
    Spamhaus DBLDomainDomains used in spam, phishing, or malwareHard - requires clear evidence
    Spamhaus ZENCompositeCombines SBL + XBL + PBL + CSSVaries by sub-list
    Barracuda BRBLIPSpam complaints, dirty lists, volume spikesModerate - online form, 12-48 hours
    SpamCop SCBLIPUser-reported spam complaintsEasy - auto-expires in 24 hours if reports stop
    SORBSIP and DomainMultiple sub-zones, varies by issueModerate to hard depending on zone
    UCEPROTECT Levels 1-3IP and ASNSpam from IP, neighbors, or ASNEasy for L1, painful for L2/L3
    Invaluement ivmSIPIPConfirmed spam, includes snowshoeHard - no public delisting form

    Tier 2 - Common listings, less catastrophic but still bad

    BlacklistTypeNotes
    PSBL (Passive Spam Block List)IPSpam trap hits, auto-delisting after activity stops
    Cloudmark CSIIP and DomainUsed by major consumer mailbox providers
    Backscatterer.orgIPLists servers sending bounces to forged addresses
    MailspikeIPBot, behavioral, and reputation lists
    Truncate.gbudb.netIPConfirmed spam sources
    NoSolicitadoIPSpanish-language spam reports
    RATS-Dyna / RATS-NoPtrIPDynamic IPs and IPs without PTR records
    JustSpam.orgIPReported spam sources
    WPBL (Weighted Private Block List)IPAggregated user complaints
    0spam DNSBLIP and DomainSpam trap and complaint-based

    Tier 3 - Smaller or regional lists

    SEM Fresh, Lashback UBL, ImproWare, IBM DNS Blacklist, Hostkarma, S5H, KISA RBL, Suomispam, Spam Eating Monkey, Anonmails DNSBL, Drone BL, AbuseAt CBL, RBL Plus. These rarely affect deliverability on their own, but multiple Tier 3 listings often signal a Tier 1 listing is coming.

    Why You Got Blacklisted (The Real Causes)

    Blacklists do not list domains and IPs at random. There is always a triggering pattern. The most common in cold outreach:

    • Dirty lists. You bought a list, scraped emails without verification, or imported a list that contained spam traps. Spam traps are dormant email addresses planted by anti-spam organizations - one hit can land you on Spamhaus immediately.
    • High spam complaint rate. Above 0.3% complaint rate triggers active filtering at Gmail and Outlook. Above 0.5% gets you listed.
    • Volume spike from a cold domain. Sending 500 emails on day one from a new domain looks like a compromised account to mailbox providers. They report it, you get listed.
    • Snowshoe spamming patterns. Spreading low volumes across many domains or IPs to dodge filters. Spamhaus CSS and Invaluement specifically target this. Agencies running aggressive multi-domain setups get caught here.
    • Compromised mailbox. Weak password, leaked credentials, no 2FA - someone uses your inbox to send spam, you get listed for their behavior.
    • Bad neighbors on shared IPs. If you use a shared sending IP (most ESPs) and another sender on that IP gets flagged, you can get listed by association on UCEPROTECT Level 2 or 3.
    • Missing or broken authentication. No SPF, no DKIM, or DMARC policy mismatches. Modern blacklists feed on authentication failures.

    Cold email blacklist benchmark: in our experience, agencies running outreach across multiple domains without rotation see at least one domain hit a blacklist every 60-90 days. The cost is not the delisting itself - it is the 1-2 weeks of lost sending volume while reputation rebuilds. Source: aggregated from ACA agency campaigns.

    The Delisting Process (Step by Step)

    Delisting is not a magic button. Follow this sequence in order.

    1. Stop sending from the listed IP or domain immediately. Every additional spam complaint while listed makes recovery harder.
    2. Identify the root cause. Check Google Postmaster Tools for spam rate. Check your list for trap-style addresses (admin@, info@, role accounts, unusually old domains). Check for unauthorized sending from a compromised mailbox.
    3. Fix the cause before requesting delisting. Clean the list with a verification service (NeverBounce, ZeroBounce). Reset mailbox passwords. Tighten SPF/DKIM/DMARC. Pause campaigns that triggered complaints.
    4. Visit the specific blacklist's removal page. Each blacklist has its own form. MXToolbox links to most of them directly from the results page. Common URLs:
      • Spamhaus: spamhaus.org/lookup
      • Barracuda: barracudacentral.org/rbl/removal-request
      • SpamCop: spamcop.net/bl.shtml
      • SORBS: sorbs.net/cgi-bin/support (uses a ticket system)
      • UCEPROTECT: uceprotect.net (use lookup, follow per-level instructions)
    5. Fill out the delisting form honestly. Explain what triggered the listing and what you fixed. Vague or deceptive responses get rejected. Spamhaus and Invaluement have human reviewers who will check your story.
    6. Wait. SpamCop auto-delists in 24 hours if complaints stop. Barracuda typically delists within 12-48 hours. Spamhaus can take 24-72 hours for first-time listings, longer for repeat offenses. UCEPROTECT Level 1 takes 7 days minimum, Level 2/3 may require ASN changes that are outside your control.
    7. Re-test before resuming sending. Run MXToolbox again. Confirm all listings cleared. Send test emails to mail-tester.com to verify inbox placement.
    8. Restart sending at 20% of previous volume. Ramp back up over 1-2 weeks. Going straight back to full volume often re-triggers the listing.

    Delist immediately when: the listing is on a Tier 1 blacklist (Spamhaus, Barracuda, SORBS) and you have identified and fixed the cause.

    Wait and let it auto-expire when: the listing is on SpamCop, PSBL, or UCEPROTECT Level 1 and the underlying complaints have already stopped - these clear on their own within days.

    Abandon the domain when: you have been re-listed on Spamhaus SBL or DBL multiple times. The domain's reputation is unrecoverable. Cheaper to register a new domain and warm it from scratch.

    How to Prevent Blacklisting in the First Place

    Recovery takes weeks. Prevention is a few operational disciplines:

    • Verify every list before sending. Run lists through NeverBounce, ZeroBounce, or Million Verifier. Remove every invalid, risky, or role-based address. Expect to drop 10-25% of any list.
    • Warm every domain and inbox for 4+ weeks before real outreach. Use a warm-up service that simulates engagement from a pool of at least 10,000 real mailboxes.
    • Keep volume per inbox under 50 emails per day. Higher volumes scale linearly with risk.
    • Use 2-3 inboxes per domain, maximum. Stacking 10 inboxes on one domain amplifies blast radius if that domain gets flagged.
    • Rotate sending across multiple domains. If one domain hits an issue, the campaign continues from the others while you fix it.
    • Use a custom tracking subdomain, never a shared one. Shared tracking domains get listed constantly and drag your emails down with them.
    • Monitor with HetrixTools or MXToolbox Monitoring. Get alerts within minutes of a listing, not days later when reply rates have already collapsed.
    • Honor unsubscribes within 24 hours. Every recipient who marks you as spam instead of unsubscribing costs you reputation points that take weeks to rebuild.

    How Sender Rotation Prevents Single-IP Blacklist Disasters

    The fundamental flaw in single-channel, single-domain email outreach is that one blacklist event takes down your entire pipeline. If you are sending 300 emails per day from one domain and that domain gets listed on Spamhaus, your campaign stops dead until delisting completes. That is 1-2 weeks of lost meetings.

    ACA's multi-channel architecture changes the math. Each campaign runs across LinkedIn, email, WhatsApp, Instagram, Telegram, and SMS simultaneously. Email is one channel of six - not the entire pipeline. When an email inbox shows deliverability signals trending in the wrong direction, you rotate it out and swap a fresh warmed inbox in without pausing the campaign. The sequence engine routes affected prospects through alternative channels while the email side recovers.

    For agencies running outreach for multiple clients, ACA isolates sending accounts per client workspace. A blacklist event on Client A's domain cannot contaminate Client B's deliverability. Each workspace tracks its own reputation independently.

    The other operational advantage: because multi-channel sequences get responses earlier (LinkedIn replies often come before email follow-up 2 even fires), you can run lower email volumes per prospect. Fewer follow-up emails per contact means lower spam complaint rates, which means lower blacklist risk in the first place.

    You cannot blacklist-proof a single-channel email campaign. You can only delay the inevitable. Multi-channel outreach is not a content strategy - it is operational insurance.

    Frequently Asked Questions

    How long does it take to get off a blacklist?

    SpamCop and PSBL auto-delist within 24 hours once spam reports stop. Barracuda typically responds to manual delisting requests within 12-48 hours. Spamhaus takes 24-72 hours for first-time listings. UCEPROTECT Level 1 requires a minimum 7-day waiting period. Repeat listings on the same blacklist take longer each time - some refuse to delist serial offenders at all.

    Can my domain be blacklisted even if my IP is clean?

    Yes. Domain-based blacklists like Spamhaus DBL and SURBL list the sending domain, the tracking domain, and any URLs in the email body. A clean IP cannot rescue you if your domain is flagged. This is why "clean IP, still in spam" happens so often - the problem is usually the domain or tracking subdomain, not the IP.

    Should I use a paid blacklist monitoring service?

    For serious outbound operations, yes. MXToolbox Monitoring and HetrixTools both offer paid plans that alert you within minutes of a new listing. Manual monthly checks are too slow - by the time you notice reply rates dropping, you have already lost a week of meetings. The monitoring cost is trivial relative to one delayed week of outreach.

    What if I am on UCEPROTECT Level 2 or 3?

    UCEPROTECT Level 2 lists IP ranges. Level 3 lists entire ASNs. If you are on Level 2 or 3, the listing is usually not about your IP specifically - it is about your hosting provider's broader network. You cannot delist these on your own. Options: migrate to a different sending infrastructure (different ESP or different IP block), or accept that some recipients using UCEPROTECT Level 2/3 will not receive your mail. Most reputable mailbox providers do not use Level 2 or 3 in their filtering, so the practical impact is limited.

    Is being on a blacklist illegal or just a deliverability problem?

    Just a deliverability problem. Blacklists are private databases operated by anti-spam organizations and ISPs. They have no legal force. But they shape whether your email lands in inboxes at major providers, which means in practice they determine whether your outreach generates pipeline or wastes your team's time.

    Does ACA prevent my domains from getting blacklisted?

    No platform can prevent blacklisting if you send dirty lists or trigger spam complaints. What ACA does is contain the damage: multi-channel sequences mean email is one channel of six, so a blacklist event does not halt your campaign. Per-workspace isolation keeps blacklisting from spreading across clients. And lower per-inbox volumes (because LinkedIn, WhatsApp, and other channels share the load) reduce the probability of getting listed in the first place.