Reputation
DNS-based blocklists: the silent reason your emails land in spam.
Published 2026-06-21 · Last updated 2026-06-21 · Vantyris editorial
If your business emails started landing in your customers' spam folders without anything changing on your end, the most likely cause is that your domain or sending IP has ended up on one of the major DNS-based blocklists (RBLs). Mail servers worldwide consult these lists in real time, and a single listing can drop your deliverability from 99% to 30% within hours. Most listings are accidental. Delisting is short work once you know the steps.
What this means for your business
- An RBL is a DNS zone that returns a positive answer when an IP or domain is on the list. When a mail server receives a message, it queries the relevant RBL(s) and, depending on the answer, accepts, quarantines, or rejects it. The big lists, in rough order of impact: Spamhaus ZEN (IPs), Spamhaus DBL (domains), Barracuda Reputation Block List, SpamCop, SURBL, URIBL.
- Listings happen for three common reasons. (1) Your sending IP was reused from a previous customer who spammed. (2) A mailbox on your domain was compromised and used to send spam, even briefly. (3) A URL in your transactional email links to a domain that is itself listed, such as a tracking-link service you use. The third is the surprising one. Your domain gets blocked because of a third-party shortener.
- Listings are time-limited but persistent. ZEN auto-delists if the IP behaves for a few days. DBL listings often need a manual delisting request after you've cleaned up. Some lists are aggressive, others conservative.
How to fix
Find out which list flagged you and fix the underlying cause (compromised mailbox, malware, third-party domain). Then submit a delisting request to each list directly.
- Confirm the listings. Use mxtoolbox.com/blacklists.aspx to check your sending IP against ~80 RBLs in one go, or query directly with
dig <reversed-ip>.zen.spamhaus.org. Note which lists you're on. - Read each list's specific listing reason. For Spamhaus ZEN, that's spamhaus.org/lookup. Each list explains what triggered the listing (a compromised mailbox sending spam, IP reputation, a domain hosting malware-payload URLs), and the reason decides your cleanup path.
- Find and fix the source. The most common cause for SME listings is a compromised mailbox in your Google Workspace or Microsoft 365 tenant. The symptoms are spam in 'Sent items' that you didn't send, or unusual outbound volume in your usage reports. Reset the password, enable MFA on every mailbox, then audit OAuth apps. For domain listings (DBL), check whether any URL on your domain hosts content the list flagged. It's often a forgotten subdomain.
- Submit a delisting request. Each list has its own form. Spamhaus ZEN auto-delists after ~48 hours of clean behaviour. Spamhaus DBL needs a manual request at spamhaus.org/removal. Barracuda: barracudacentral.org/rbl/removal-request. SpamCop, SURBL, URIBL: each lists its delisting URL on the lookup page.
- Monitor your sender score after delisting. Use a free tool like Google Postmaster Tools (postmaster.google.com) for your domain reputation, plus your ESP's sending reputation dashboard if you have one. A listing that comes back quickly means the underlying issue isn't fully fixed.
Owner: Your email administrator (Google Workspace / Microsoft 365 admin) for compromised-mailbox cleanup. Your DNS administrator if the issue is a forgotten subdomain. · Time: 1-3 hours for cleanup, then 24-72 hours for delisting to propagate.
Common gotchas
- Don't submit a delisting request before the underlying issue is fixed. Most lists will refuse a repeat delisting if they re-detect the same issue within the same week.
- If you can't find a compromised mailbox, check OAuth apps. A token from an old SaaS tool can still send mail on your behalf after the user's password rotates. Revoke any OAuth app you don't recognise.
- Some lists never delist if you've been on them long enough. URIBL in particular treats long-history listings as evidence of pattern abuse.
How to verify the fix
Run a Vantyris scan. The Reputation category queries all six major RBLs and shows which (if any) currently list your IP or domain. mxtoolbox.com/blacklists.aspx gives you a one-shot view too.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Why don't my customers report seeing my emails as spam?
Most modern mail clients (Gmail, Outlook, Apple Mail) silently move suspicious mail to spam without alerting the recipient. Your customer just never sees the email. They don't tell you it went to spam because they don't know it was sent. The first signal is usually a customer asking why you didn't reply to their question.
Can I bypass RBLs by sending through an ESP like Mailgun or Postmark?
Partly. Reputable ESPs have clean sending IPs and a good reputation, so the IP-level listings (Spamhaus ZEN, Barracuda) won't bite. But domain-level lists (Spamhaus DBL, SURBL) check your domain regardless of who sent the email. Fix the domain issue, not the sending path.
Does HSTS or DMARC help with RBL listings?
Indirectly. DMARC closes the impersonation route that damages sending reputation. HSTS doesn't affect email. Both are upstream of the RBL question.
How often should I check my reputation?
Vantyris continuous monitoring queries the six major lists on every scheduled scan (weekly, biweekly, or monthly cadence). Or run a one-off Vantyris verified scan whenever you notice deliverability dropping.
References
- Spamhaus: removal guide Vendor
- Barracuda Reputation Block List Vendor
- MX Toolbox: blacklist check Vendor
- Google Postmaster Tools Vendor
Related explainers
- Google Safe Browsing: how it flags sites and how to clear yours.
- What is DMARC, and why every business with a domain needs one.
- SPF records, explained: the first line of defence against email spoofing.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris