IP list

Blacklist removal guide

How to remove your IP from Mailspike Z

Z is Mailspike's zero-hour list: IPs caught mid spam-wave. Here is what a listing means and how to clear it.

What it is

The list, in plain terms.

Mailspike Z is the zero-hour zone of the Mailspike blocklist, published at z.mailspike.net. It lists IP addresses observed participating in a distributed spam wave right now, rather than scoring long-term reputation the way the separate rep.mailspike.net zone does. Mailspike is a free, community-oriented service run by Mailspike Technologies under the AnubisNetworks brand.

Because Z reacts to live spam activity, a listing is usually a symptom: a compromised mailbox, an exploited server, or a botnet is sending through your IP. The combined bl.mailspike.net zone that many receivers query folds in the Z data, so a Z listing can get your mail deferred or rejected while the wave is active.

Z lists IP addresses, not domains — it is your sending server that is flagged, not the domain in your message. Clear the abuse and the listing is straightforward to remove.

Why you get listed

What a listing on Mailspike Z means.

Caught in a distributed spam wave Your IP was seen sending as part of a coordinated burst of spam, malware or phishing that Mailspike detected across many hosts at once. This is the core reason Z exists.
A compromised mailbox A hijacked email account on your server is being used to send spam. Mailspike names compromised accounts as a leading cause of listings.
An exploited or botnet-controlled server A machine on the IP has been compromised and is under the control of a spam operation. Removal is deliberately held back for these until the threat is confirmed mitigated.

How to get removed

Delisting, in order.

Removal is free. Fix the cause first — a listing you clear without a fix comes straight back.

  1. 1 Confirm the listing. Look your IP up at mailspike.io/ip_verify. The check covers the Mailspike zones and shows whether you are on the zero-hour (Z) list; a Z listing returns 127.0.0.2 on a DNS query to z.mailspike.net.
  2. 2 Find and stop the sending. A Z listing means live spam left your IP. Identify the source: reset the compromised mailbox, clean the exploited host, close any open relay, and stop the outbound flow. Delist before the abuse is gone and the wave detection simply re-lists you.
  3. 3 Request delisting on the form. On mailspike.io/ip_verify, use the delist control next to the observed IP. Mailspike delists automatically once requested — no account or fee is involved. They only handle their own zones; other blocklists must be contacted separately.
  4. 4 Wait out the automatic window. An automatic delist takes effect within roughly 6 to 36 hours. If the listing is tied to a known spam botnet, removal is held until network records confirm the malware threat is mitigated, so it can take longer.
  5. 5 Re-check before resuming. Confirm the IP is clear at mailspike.io/ip_verify before you ramp sending back up. Keep the compromised account secured and monitor outbound volume so the wave detection does not trigger again.

The official route

Straight to the source.

Removal happens on Mailspike Z's own tool — never through a paid service.

Mailspike Z removal tool ↗

Return codes

127.0.0.2 Z — IP currently listed on the zero-hour zone (z.mailspike.net)

How long it takes

A self-service delist request is processed automatically, typically within 6 to 36 hours. Listings linked to a known spam botnet are held back until Mailspike's network records confirm the threat is mitigated, so they can take longer. As a free service, Mailspike notes its response resources are limited.

Common questions

About Mailspike Z, specifically.

What does a Mailspike Z listing mean? Z is the zero-hour zone, z.mailspike.net. Your IP was seen participating in a distributed spam wave — an active burst of spam, malware or phishing — rather than being scored on long-term reputation. It usually points to a compromised account or an exploited server.
Does Mailspike charge to delist my IP? No. Mailspike is a free, community-oriented service and delisting is handled automatically through the form at mailspike.io/ip_verify. Any third party charging to remove a Mailspike listing is a scam — no one outside Mailspike can influence its removal.
How long does Mailspike Z removal take? An automatic delist request usually clears within 6 to 36 hours. If the listing is tied to a known spam botnet, removal is held until Mailspike's network records confirm the threat is mitigated, which can take longer.
What return code does z.mailspike.net give? A DNS query to z.mailspike.net returns 127.0.0.2 when the IP is currently listed. The Z zone publishes only this one code; the graded 127.0.0.10 to 127.0.0.20 codes belong to the separate reputation zone, rep.mailspike.net.
I delisted but got listed again — why? Because the spam was still leaving your IP. Z reacts to live activity, so if the compromised mailbox or exploited host keeps sending, the wave detection re-lists you. Stop the source first, then delist.
What is the difference between Mailspike Z and BL? Z (z.mailspike.net) is the zero-hour list of IPs caught in a spam wave. BL (bl.mailspike.net) is a combined query zone that folds in the Z data plus the worst reputation levels (L3 to L5) from rep.mailspike.net. Clearing the underlying cause resolves both.

Do not fix it blind.

See every list you are on and every authentication problem behind the listing in one 40-second check — then let monitoring tell you the day a listing comes back.