Why this is not one lookup

There is no single blacklist. There are dozens of independent lists run by mailbox providers, security vendors, anti-spam projects and individuals, each with its own criteria and its own idea of what belongs on it. A lookup tool that answers “not listed” is answering for the lists it queries, and nothing else.

The form below returns the abuse observations from the commercial database this site queries. That field is evidence about an address, not a blocklist verdict, and the difference matters when the answer is going to decide what you do next.

The lists worth knowing about

The table records what each family of lists is for and how removal is requested. Anyone can publish a list, and a listing is not a ruling by an authority. Confirm the current process on the list’s own page before relying on any detail here, because the operators change their forms and their criteria.

List familyWhat it recordsScopePublished removal route
Spamhaus (SBL, XBL, PBL)Spam sources, exploited hosts, and ranges that should not send mail directlyAddress or netblock, depending on the listSelf-service lookup and request form; run by a non-profit
SpamCopAddresses reported through the SpamCop reporting serviceAddress, with an automatic expiryRemoval form; listings expire on their own once reports stop
Barracuda (BRBL)Spam sources observed by that vendor’s mail appliancesAddressWeb removal form, then a propagation wait across appliances
Microsoft (SNDS and JMRP)Traffic data and complaints for ranges sending to MicrosoftNetblock, tracked as sender reputationSNDS portal for the range owner, plus a support-based delisting route
Cisco TalosSender reputation from that vendor’s telemetryAddress or domainLookup and removal request through the vendor’s site
Proofpoint and CloudmarkSender reputation from their own sensors and feedback loopsAddress or domainRemoval request forms published by each vendor
Google (Gmail)No public list, and no lookup. Reputation is per sender and shown only in Postmaster ToolsSending domain or address, behind an accountNo delisting form; the position improves by sending accepted mail

Two properties of this table are more important than its contents. First, several of these are only visible to their operators, which means you cannot check yourself against them, only against the ones that publish a lookup. Second, the lists with the widest reach are the mailbox providers, and they tend to act on aggregate behaviour rather than on single events, which is why an address can be blocked without appearing on any public list at all.

Reading the abuse signal in the lookup above

The abuse field reports whether the queried database holds a report against the address. It does not report how many, from whom, or when. A soft security feed can carry a report from years ago that no current receiver consults, and that will look identical here to a report filed last week.

Treat the field as a pointer rather than a conclusion: when it is flagged, the next step is to find out which list and which scope, which the list’s own lookup answers and this page cannot. When it is not flagged, the address still needs to be checked against the lists that have their own lookups.

What an address being listed actually changes

For mail, a listing has a specific effect: receivers that consult that list will usually refuse or quarantine connections from the address until the listing clears. That is why a listing on one of the widely used lists is a deliverability incident rather than a warning, and why the deliverability test checks authentication records alongside it — a domain that fails SPF and DMARC on a listed address has two independent problems.

For web traffic, the effect is usually nothing at all. Most blocklists are consulted by mail and security appliances, not by websites, so an address listed for sending spam can browse the web normally. Confusing the two leads to changes that treat the wrong problem.

What this page cannot do

It cannot query the lists that do not publish a lookup. It cannot tell you which list produced a listing you have already seen elsewhere. It cannot predict whether a given receiver consults a list, because that routing decision is internal to each receiver. And it cannot remove anything: removal always happens through the list’s own process, which is described step by step in how to get off a blocklist.

Where a listing turns out to be justified, the reason is usually on your own network rather than in the database. The IP purity check page lists the observations that point at compromised or shared infrastructure, and the network diagnostics guide gives the order in which to check them. Network ownership, useful when a listing belongs to a range you rent rather than own, is covered by ASN lookup.