IP Reputation
IP Reputation helps you comprehensive ip reputation scoring, for reputation scoring, blocklist checks, and abuse investigations.
Advertisement · Anuncio
Advertisement · Anuncio
Technical Analysis & Guide
What It Does
IP Reputation decides whether you entered an IPv4 address or a domain and queries the matching DNS-based blocklists in real time. An IPv4 address is checked against twelve IP blocklists, including Spamhaus ZEN, SBL, XBL and PBL, SpamCop and Barracuda; a domain is checked against domain blocklists such as SURBL multi, three URIBL lists and the Spamhaus DBL. The result is an overall pass, warning or fail plus the list names that returned a hit and any reason text they publish.

Why It Matters
- →Mail deliverability: A single listing on Spamhaus SBL or XBL is enough for many receiving servers to reject SMTP connections outright, long before content filters see the message.
- →Inherited addresses: Cloud and VPS IPs are recycled between customers, so a freshly provisioned server can carry the listing of the previous tenant.
- →Compromised hosts: An XBL or CSS-style listing on an office IP is frequently the only visible symptom of a malware-infected workstation sending spam behind NAT.
- →Links in content: A domain on the DBL or URIBL can get newsletters filtered even when the sending IP is clean, because filters scan URLs in the body.
- →Vendor and partner vetting: Checking a supplier's mail server or landing domain before integration avoids inheriting their reputation problems in your own flows.
How to Read Results
- Overall status: FAIL when at least one list marked critical (Spamhaus ZEN, SBL or XBL, SpamCop, Barracuda) answers; WARNING when only advisory lists answer; PASS when no list returns a record.
- Type: Shows IP or domain, depending on whether the input matched the dotted-quad IPv4 pattern; IPv6 addresses are not checked as IPs.
- Listings: Each entry gives the list name, whether it is treated as critical, and the TXT reason when the list publishes one, often with a removal URL.
- Advisory lists: Spamhaus PBL, UCEPROTECT level 1, PSBL, Mailspike, the backscatter list and the others marked non-critical lower the result only to WARNING.
- Checked and errors: The number of lists queried and any that timed out or failed; a list that errored is not counted as listed, so it is not proof of a clean record.
Technical Background
DNS blocklists are documented in RFC 5782. To ask whether 192.0.2.25 is listed on a zone like zen.spamhaus.org, a client reverses the octets and sends an A query for 25.2.0.192.zen.spamhaus.org. NXDOMAIN means not listed; an answer in 127.0.0.0/8 means listed, and the specific address encodes the reason. Spamhaus ZEN, for instance, returns 127.0.0.2 for SBL, 127.0.0.3 for the CSS component, 127.0.0.4 to 127.0.0.7 for XBL and 127.0.0.10 or 127.0.0.11 for PBL. A TXT query on the same name usually returns a human-readable reason and a lookup URL. Every compliant list must answer for 127.0.0.2 as a test entry, which is a handy way to confirm that your resolver can reach the list at all. Domain lists work the same way with the domain name prepended instead of reversed octets.
Not all lists mean the same thing. SBL entries are manually curated spam sources and spam-support services. XBL lists hosts showing signs of compromise, such as bots and open proxies. PBL is a policy list: it contains end-user and dynamic ranges that ISPs say should not deliver mail directly to MX servers. Being on PBL is not an accusation, which is why this tool treats it as advisory; a home connection sending through its provider's smarthost is unaffected. SpamCop listings are driven by user reports and expire automatically roughly a day after reports stop. Domain lists such as the Spamhaus DBL, SURBL and URIBL target domains found in message bodies, so they affect a brand even when every sending IP is spotless.
Shared addresses complicate everything. Under carrier-grade NAT, using the RFC 6598 range 100.64.0.0/10 internally, hundreds of subscribers leave through one public IPv4, and a single infected phone or router can get that address onto XBL for all of them. This is common on mobile and fixed broadband networks across Latin America, where CGNAT became the norm after LACNIC exhausted its IPv4 pool. The same happens with cloud egress IPs, VPN exits and recycled VPS addresses.
Two caveats about any live DNSBL check. Spamhaus refuses queries arriving through large public resolvers and answers them with codes in 127.255.255.0/24; a naive client, including any check that treats every A answer as a hit, will read that as a listing, so confirm the return code and TXT reason before acting. And IPv6 lists use nibble-reversed names, which this tool does not query.
Delisting always starts with fixing the cause: clean the infected host, close the open relay, or move outbound mail to an authenticated relay. Then use the list's self-service removal page; most refuse or quickly re-list an address whose cause persists.
Common Errors and How to Fix Them
- ProblemEvery IP appears listed on Spamhaus with an answer like 127.255.255.254.
- FixThat is an error code, not a listing: the query reached Spamhaus through a public or unregistered resolver. Query from your own recursive resolver or use a registered Data Query Service key.
- ProblemPanicking over a Spamhaus PBL listing on a home or office broadband IP.
- FixPBL only says the range should not send direct-to-MX. Relay outbound mail through your provider's or mail platform's authenticated submission service on port 587; remove the IP from PBL only if it is a static address that runs a real mail server.
- ProblemRequesting delisting while the infected machine is still sending.
- FixFind the source first: block outbound TCP 25 except from the mail server, check firewall logs for hosts opening SMTP connections, and clean them. Lists like XBL re-list within hours if the traffic continues.
- ProblemA new cloud server is listed on day one.
- FixThe address was used by a previous customer. Request delisting with a note that the instance is new, or release the IP and allocate another; many clouds also block outbound port 25 until you request an exception.
- ProblemUsing a domain in links that shares infrastructure with spammers or was recently registered and dropped.
- FixCheck the domain on DBL and URIBL before campaigns, use your own domain for tracking links rather than shared shorteners, and keep SPF, DKIM and DMARC aligned so filters can attribute the mail correctly.
Frequently Asked Questions
Why is my IP blacklisted if I never sent spam?
Most often the address is shared or recycled. Behind carrier-grade NAT, many customers use one public IP, and one infected device can get it listed. Cloud and VPS addresses carry history from previous tenants. Policy lists like Spamhaus PBL also include ranges simply because the ISP declared them dynamic. Check the TXT reason to see which case applies.
How long does it take to get removed from a blacklist?
It depends on the list. SpamCop listings expire automatically about 24 hours after reports stop. Spamhaus XBL and PBL removals through the self-service form usually take effect within an hour or so, plus DNS cache time. Manually curated lists like SBL require the operator to resolve the issue first and can take days. Removal is pointless if the cause is still active.
Does a blacklist listing affect my website ranking?
IP blocklists such as ZEN mainly affect email, not search ranking. Domain blocklists can have indirect effects: links to a listed domain may be stripped or flagged by mail and security filters, and browser warnings come from separate safe-browsing systems. Search engines do not consult DNSBLs directly, but a compromised server sending spam often also hosts injected content that does hurt rankings.
What is the difference between an IP blocklist and a domain blocklist?
An IP blocklist evaluates the address that connects to a mail server, so it is checked at SMTP connection time. A domain blocklist evaluates names found in the message, mainly links in the body and sometimes sender domains. You can be clean on one and listed on the other, which is why this tool switches list sets depending on whether you enter an IP or a domain.
Can I check an IPv6 address for blacklisting?
Not with this tool, which only treats dotted IPv4 input as an IP. IPv6 DNSBLs exist and use the 32 hexadecimal nibbles of the address in reverse order as the query name. Because IPv6 space is so large, many lists work at the /64 level instead of single addresses, so one listing can affect every host on a subnet.
Academic Documentation
Protocol context and primary references
REST API Documentation
v1.0GET /api/tools/reputation-check
curl -X POST https://epcybertools.com/api/tools/reputation-check \
-H "Content-Type: application/json" \
-d '{"domain":"google.com"}'
{
"success": true,
"results": [
{ "test": "Sample Check", "status": "pass", "message": "All clear" }
]
}
Usage Examples
# Test entry: every RFC 5782 list must answer for 127.0.0.2
dig +short 2.0.0.127.zen.spamhaus.org
# Check a real IP (198.51.100.7 reversed) and read the reason
dig +short 7.100.51.198.zen.spamhaus.org A 7.100.51.198.zen.spamhaus.org TXT