IP list

Blacklist removal guide

How to remove your IP from Mailspike BL

Mailspike BL flags IPs caught in spam waves or carrying a poor reputation. Here is what a listing means, and how to get off it.

What it is

The list, in plain terms.

Mailspike BL is an IP blocklist published in the DNS zone bl.mailspike.net. It is run by Mailspike Technologies, part of AnubisNetworks, which has provided email threat intelligence since 2008. Receivers query the zone to reject or defer mail from IPs Mailspike considers a risk.

BL is a combined zone. It bundles z.mailspike.net — IPs seen participating in a live, distributed spam wave — together with the worst reputation levels (L3 to L5) from rep.mailspike.net, Mailspike's reputation data. So a BL listing means either your IP was caught in a spam outbreak, or it has accumulated a consistently bad sending reputation.

Mailspike lists IP addresses, not domains — it is your sending server that is flagged, not the domain in your message. Removal is free and self-service through Mailspike's own lookup page; no third party can influence or speed it up.

Why you get listed

What a listing on Mailspike BL means.

Caught in a spam wave (z) Your IP was observed sending as part of a real-time, distributed spam outbreak. This is the z.mailspike.net component and returns 127.0.0.2. It often signals a compromised host, a hijacked account, or a botnet infection on the sending machine.
Poor accumulated reputation (L3-L5) Mailspike assigns every observed IP a temporary reputation level from L5 (worst) to H5 (excellent). BL includes the three worst bands — L3, L4 and L5 — so a listing here means your IP has behaved badly enough over time to fall into the blocking range.
A shared or new IP with no history Reputation is calculated per IP. If you have just started sending from a fresh address, or share an IP with other senders on the same range, poor behaviour that is not yours can still push the reputation into the L3-L5 band.

How to get removed

Delisting, in order.

Removal is free. Fix the cause first — a listing you clear without a fix comes straight back.

  1. 1 Fix the cause first. Find and resolve why the IP was flagged before you ask for removal: clean any malware or compromised account behind a spam-wave listing, stop the spam, and tighten authentication (SPF, DKIM, DMARC) and sending rate. Delist without fixing the cause and Mailspike will relist the IP once the behaviour reappears.
  2. 2 Look your IP up. Go to the Mailspike lookup page at mailspike.io/ip_verify, enter the listed IP address and run the check. It shows whether the IP is on BL and which component — spam wave or reputation level — triggered it.
  3. 3 Submit the delist request. If the IP is listed, a delist request form appears on the results page. Complete the captcha and submit it to register the request. This is the only removal channel and it is free.
  4. 4 Wait for automatic removal. Mailspike delists requested IPs automatically, usually within 6 to 36 hours. For spam-wave or botnet listings, removal only completes once Mailspike's systems collect network evidence that the threat has been mitigated, so a persisting infection will hold up the delist.
  5. 5 Re-check before you resume. Once the window has passed, look the IP up again at mailspike.io/ip_verify to confirm it has cleared before you ramp sending back up. Keep authentication and volume in check so the reputation recovers rather than dropping straight back into the blocking range.

The official route

Straight to the source.

Removal happens on Mailspike BL's own tool — never through a paid service.

Mailspike BL removal tool ↗

Return codes

127.0.0.2 z — IP seen in a distributed spam wave
127.0.0.10 L5 reputation — worst possible
127.0.0.11 L4 reputation — very bad
127.0.0.12 L3 reputation — bad

How long it takes

After you submit the delist request, Mailspike removes the IP automatically, usually within 6 to 36 hours. Spam-wave and botnet listings clear only once Mailspike collects network evidence that the threat is mitigated, so an unresolved compromise will delay removal. Allow a short window for DNS to propagate before you re-check.

Common questions

About Mailspike BL, specifically.

Does Mailspike charge to remove my IP? No. Removal is free through the self-service delist form at mailspike.io/ip_verify. Any service offering to remove a Mailspike listing for a fee is a scam — no third party can influence or speed up the process.
How long does Mailspike delisting take? Mailspike removes requested IPs automatically, usually within 6 to 36 hours. Spam-wave and botnet listings take longer because removal waits on network evidence that the underlying threat has been mitigated.
What is the difference between Mailspike BL and Mailspike Z? Z (z.mailspike.net) lists only IPs caught in a live spam wave. BL (bl.mailspike.net) is broader: it combines the Z data with the worst reputation levels (L3 to L5) from rep.mailspike.net. If you are on BL, check which component triggered it.
What do the Mailspike return codes mean? For BL, 127.0.0.2 means your IP was seen in a distributed spam wave, while 127.0.0.10, .11 and .12 map to the L5, L4 and L3 reputation levels — the three worst bands, from worst to least bad. The reputation scale runs from L5 (worst) up to H5 (excellent).
Why was I listed if I never sent spam? A spam-wave listing often means a machine on your IP is compromised or an account has been hijacked and is sending without your knowledge. A reputation listing can also come from sharing an IP range with poor senders. Clean the host, secure your accounts, then request removal.
I delisted but got relisted — why? Because the cause was still there. Mailspike relists an IP as soon as the spam behaviour or poor reputation returns. Removal is not a fix: resolve the compromise, stop the spam and improve your sending practice before you delist.

Do not fix it blind.

See every list you are on and every authentication problem behind the listing in one 40-second check — then let monitoring tell you the day a listing comes back.