Check a domain
How it works
Resolve the targets
A domain is expanded into its A record and MX host IPs, then each IP is checked.
Query each blocklist
The reversed IP is looked up against each DNSBL zone over DNS-over-HTTPS.
Weight the results
Spamhaus and SpamCop affect real delivery. Small aggregators mostly do not.
Fix the cause first
Delisting without fixing what caused the listing gets you relisted within days.
Read this before you panic about a listing
Not all lists matter. A hit on Spamhaus ZEN or SpamCop affects real delivery to real recipients. A hit on a small aggregator that no major receiver subscribes to affects nothing at all. Before spending a day on a delisting request, find out who actually consumes the list.
Some lists cannot be checked from a browser. Spamhaus, Barracuda and UCEPROTECT refuse queries that arrive via public resolvers like 1.1.1.1 and 8.8.8.8, which is all a browser-based tool can use. When that happens this tool reports resolver blocked rather than guessing. It will never report a blocked query as clean — check those at the vendor's own lookup page instead.
Shared IPs change the picture entirely
On Google Workspace or Microsoft 365 you do not control the sending IP. It is shared across enormous numbers of tenants, and an IP listing there is almost never yours to fix. Reputation on those platforms is tied to your domain and your sending behaviour, not to the IP.
IP blocklists matter most when you run your own SMTP or a dedicated relay, where the IP genuinely is yours. In that case a listing is both actionable and urgent.
Domain blocklists are the ones cold email senders should watch. Getting a sending domain onto Spamhaus DBL or SURBL is a serious problem, and it usually follows from the same causes: bad list data producing high bounce rates, volume ramped far too fast on fresh domains, or recipients marking mail as spam in numbers.
The fix is always the same order — stop sending from the affected domain, find and correct the cause, then request delisting. Delisting first simply resets the clock until the same behaviour lists you again.
Which lists actually affect delivery
| List | Type | How much it matters |
|---|---|---|
| Spamhaus ZEN | IP | High. Widely consumed by real receivers. |
| Spamhaus DBL | Domain | High. The one cold email senders should watch. |
| SURBL | Domain | High. Targets domains appearing in message bodies. |
| SpamCop | IP | Moderate. Listings expire automatically over time. |
| Barracuda | IP / domain | Moderate. Matters most where Barracuda gateways are in use. |
| UCEPROTECT L2 / L3 | IP range | Low. Lists entire ranges; few major receivers act on it. |
| Small aggregators | Mixed | Usually none. Check who consumes a list before reacting. |
Domain listings versus IP listings
The distinction decides whether a listing is even yours to fix. On Google Workspace or Microsoft 365 the sending IP is shared across an enormous number of tenants — you neither control it nor can meaningfully clean it, and reputation on those platforms attaches to your domain and your sending behaviour instead.
Domain listings are the ones that should worry a cold email sender, because they follow directly from what you did. Spamhaus DBL or SURBL almost always trace back to one of three things: bad list data producing high bounce rates, volume ramped far too quickly on fresh domains, or recipients marking mail as spam in numbers.
What to do about a listing that matters
If placement is poor but nothing is listed, the cause is usually authentication or content rather than reputation — start with the domain checker and the nine real causes of spam placement.
Frequently asked questions
How do I get delisted from Spamhaus?
Use the removal form at check.spamhaus.org, but only after you have fixed whatever caused the listing. Spamhaus lists on evidence of spam traffic, and self-removals are limited. Requesting removal while the underlying behaviour continues wastes a removal you may need later.
Why does the tool say "resolver blocked" instead of giving me an answer?
Spamhaus, Barracuda and UCEPROTECT block queries from public DNS resolvers to stop bulk automated lookups. A browser-based tool can only use public resolvers, so those lists cannot be reached. Reporting that honestly is better than silently calling them clean, which is what many free checkers do.
My sending domain is listed but the IP is clean. What does that mean?
A domain listing follows your sending behaviour, not your infrastructure — usually high bounce rates from poor list data, spam complaints, or volume ramped too fast. Because it is attached to the domain, changing IPs or providers will not shake it. That domain likely needs retiring and the sending practice behind it needs changing.
How often should I check my sending fleet?
Monthly for a healthy fleet, and immediately whenever reply rates drop without an obvious explanation. A domain listing is one of the few deliverability failures with a clear binary answer, which makes it worth ruling out early when you are diagnosing a drop.
How do I check if my domain or IP is blacklisted?
Enter either above. A domain has its A and MX hosts resolved and checked as well, since a domain can be clean while the infrastructure behind it is listed. Each result is weighted by whether the list is actually consumed by receivers that matter, rather than presenting every hit as equally serious.
Why does the checker say "resolver blocked" instead of an answer?
Spamhaus, Barracuda and UCEPROTECT refuse queries arriving through public resolvers such as 1.1.1.1 and 8.8.8.8, which is all a browser-based tool can use. Rather than guess, the tool reports the query as blocked — it will never show a blocked lookup as clean. Check those directly at the list operator's own lookup page.
How do I get delisted from Spamhaus?
Fix the cause first, then submit a removal request through the Spamhaus Blocklist Removal Center. Requests that arrive with nothing changed tend to be refused or quickly re-listed. For DBL listings on a sending domain, expect to demonstrate that list quality and volume practices have actually changed.
My domain is listed but the IP is clean. What does that mean?
It means the problem is your sending behaviour rather than your infrastructure — which is the common case on shared platforms like Google Workspace and Microsoft 365, where the IP belongs to the provider. Domain listings follow from bounce rates, complaint rates and volume ramps, all of which are yours to control.
Does a blacklist listing always mean my email goes to spam?
No. It depends entirely on which list, and whether the receivers you are sending to consume it. A Spamhaus ZEN or DBL listing affects real delivery; a hit on a small aggregator that nobody subscribes to affects nothing. Identify who consumes the list before spending a day on a delisting request.
How often should I check a sending fleet?
Monthly is reasonable as a baseline, and immediately whenever reply rates drop without an obvious explanation. Checking after any significant volume increase is worthwhile too, since a fast ramp on fresh domains is one of the most reliable ways to earn a listing in the first place.
Last reviewed
What to run next
The checks that most often follow this one.
More in this category
Guides that go deeper
When the tools tell you something is wrong
The diagnostics here are free and always will be. When the fix is bigger than a DNS record, this is the work I do.
Deliverability rescue
Mail landing in spam, replies gone quiet, or a domain suddenly blocked. I find the actual cause rather than guessing, and fix it.
- Authentication and alignment failures
- Blocklist delistings and reputation repair
- Gateway and filter-level blocks
- A written report on what broke and why
Email & sending infrastructure
Sending domains, inboxes, authentication and warmup, built to survive volume instead of burning down in a month.
- Domain and inbox fleets at any scale
- SPF, DKIM, DMARC and tracking domains
- Google Workspace and Microsoft 365 inboxes
- Handover documentation you actually own
Domain, DNS & migration
Changing registrar, mail provider or host without a day of downtime or a week of mail silently failing.
- Registrar and nameserver moves
- Workspace and Microsoft 365 migrations
- MX, SSL and subdomain cutover
- Staged rollout with rollback at every step
Monitoring & retainer
Infrastructure drifts. Records get edited, certificates expire, domains get listed. Ongoing eyes on the fleet.
- Scheduled checks across every domain
- Alerts before your clients notice
- Monthly reporting
- Priority response when something breaks
Start with a call
Bring a domain and the symptom. I will tell you what is actually wrong and whether you need me at all — plenty of people leave that call able to fix it themselves.
Thirty minutes, no pitch
We will run the checks together on your actual domains, and you will leave knowing what is broken, what it takes to fix, and what it should cost. If that is a job you can do in-house, I will say so.