Fraud and risk scores
How to Check if an IP Address Is Blacklisted (Step by Step)
A practical guide to finding out whether an IP is on a blacklist, what it means, and what to do about it.
- Author
- Mojahid Ul Haque
- Updated
- Reading time
- 5 min read
What IP blacklists are
An IP blacklist, sometimes called a denylist, is a list of addresses associated with spam, malware, abuse, open proxies, bot traffic, or policy violations. Email providers, firewalls, anti-fraud systems, and security products use these lists to decide when to reject or challenge traffic.
A listing does not always mean you personally did something wrong. Shared hosting, dynamic ISP assignments, compromised devices, public Wi-Fi, and old abuse history can all cause innocent users to inherit reputation problems.
Most blocklists are DNS zones, which is why they are called DNSBLs. A checker reverses the address's octets, appends the list's zone (1.2.3.4 becomes 4.3.2.1.zen.spamhaus.org) and asks DNS: an answer in 127.0.0.0/8 means listed, no answer means not listed on that zone. Every list runs its own zone with its own criteria, so an address can sit on one list and be absent from ten others, which is why multi-list checkers such as MXToolbox or MultiRBL query dozens of zones in one pass. Most of these zones cover IPv4 only; if your traffic leaves over IPv6, use a checker that also queries IPv6 lists.
Step-by-step checking process
First, find the exact public IP you want to test, then run it through Crafzo for location, network, and risk context. Next, check one or more blacklist lookup tools, record which lists show a hit, and note the timestamp because listings can change.
Which checker to use depends on the symptom. For email delivery problems, query Spamhaus directly at check.spamhaus.org: it tells you whether the address is on SBL (spam sources), XBL (compromised or infected hosts), PBL (end-user ranges that should not send mail directly) or CSS, and why. MXToolbox's blacklist check queries dozens of DNS-based lists in one pass and is the quickest way to see how widespread a listing is. Crafzo's own Blacklist signal reports the external lists its risk provider consults; it is a starting point, not a substitute for the list operators' own lookups.
If the issue affects email, inspect mail server logs and authentication records such as SPF, DKIM, and DMARC. If it affects website access, compare the blacklist result with WAF logs, fraud scores, and recent request patterns.
What to do after a listing
Fix the root cause before requesting delisting: remove malware, close open relays, stop spam, rotate compromised credentials, or reduce abusive traffic. Delisting without remediation often leads to relisting.
Most reputable lists publish a delisting process or contact path. Provide the IP, the fix performed, and evidence that the abuse has stopped.
A worked example: a small business finds its mail server address on Spamhaus XBL after a staff laptop was infected. Cleaning the laptop comes first; the listing exists because the infected machine was sending spam. Then the address is looked up again at check.spamhaus.org, which offers a self-service removal for XBL and CSS listings once the traffic has stopped. A PBL listing is different: it is a policy statement that the range is dynamic or residential, so the fix is to send through the ISP's or a provider's authenticated relay, or to request a PBL exception for a static mail server. Re-check a day later, because some lists refresh on a delay, and keep the timestamps of the listing, the fix and the removal request in case a customer asks.
Sources
Frequently asked questions
Keep reading
Related guides
- Fraud and risk scores9 min read
What Does It Mean When Your IP Is Blacklisted?
What an IP blocklist listing means for your email and web traffic, why addresses get listed, how to check your reputation, and how delisting works.
Updated
- Privacy and IP basics8 min read
IPv4 vs IPv6: What the Shift Means for Your Privacy
IPv6 gives every device a globally reachable address and rotates temporary ones. What that changes for tracking, geolocation and VPN checks compared with shared IPv4.
Updated
- IP location and accuracy6 min read
Practical Guide to IP Lookup for Security and Geolocation
What an IP lookup returns, how to read location, ISP, ASN and risk fields together, and how teams use lookups for fraud prevention and compliance.
Updated
- Fraud and risk scores2 min read
How to Find the Abuse Contact for an IP Address
A practical guide to finding the right abuse contact when an IP is involved in spam, scanning, fraud, or attacks.
Updated