Domain list

Blacklist removal guide

How to remove your domain from Spamhaus DBL

The DBL flags domains, not IPs — the name in your links and From address. Here is what a listing means, and how to clear it.

What it is

The list, in plain terms.

The Spamhaus DBL (Domain Block List, zone dbl.spamhaus.org) is a real-time DNS blocklist of domain names with a poor reputation, run by The Spamhaus Project. Receivers query it against the domains that appear in a message — the sender domain, the URLs in the body, and the domains behind them — rather than the sending IP.

That makes the DBL different from Spamhaus's IP lists such as ZEN. A clean sending IP will not save a message whose links or From domain are on the DBL, and moving to a new server does not clear it. The listing follows the domain.

The DBL is widely consulted and covers spam, phishing, malware and botnet command-and-control domains, plus a separate class for legitimate domains that have been compromised or abused. The reason it lists you decides how you get off, so the first job is always to find out which one applies.

Why you get listed

What a listing on Spamhaus DBL means.

Spam domain The domain appears in spam — as the sender, in the message body, or as a redirector — or is otherwise tied to spam operations Spamhaus tracks. This is the most common reason a marketing or sending domain lands on the DBL.
Phishing, malware or botnet C&C The domain hosts or is used in phishing, distributes malware, or acts as botnet command-and-control infrastructure. These are evidence-based abuse listings and the most serious to resolve.
Abused legitimate domain A genuine domain that has been compromised — a hacked site, a hijacked subdomain, or an open redirector being exploited by spammers. It means your domain is being abused, not that you sent spam deliberately. These carry their own return codes.
Poor reputation signals Spamhaus does not publish exact criteria and states a domain must match several before it is listed. New domains sending in volume, or domains reusing infrastructure with a bad history, can accumulate enough signals to be flagged.

How to get removed

Delisting, in order.

Removal is free. Fix the cause first — a listing you clear without a fix comes straight back.

  1. 1 Look the domain up first. Check the domain at check.spamhaus.org. The lookup confirms whether it is really the DBL and shows the return code, which tells you the category — spam, phish, malware, botnet C&C or abused-legit. Do not act until you know which, because the fix differs.
  2. 2 Fix the cause before you request removal. For an abused-legit listing, find and remove the compromise — malicious pages, injected redirects, a hijacked subdomain — and close the hole. For a spam or abuse listing, stop the sending or hosting behaviour that triggered it and secure any abused account. Remove yourself before the cause is gone and the automated systems relist the domain.
  3. 3 Submit the removal request through the checker. The DBL removal is handled only through check.spamhaus.org. Look the domain up and follow the returned instructions, which include a removal form where you describe what you fixed. There is no separate email address or paid channel — the checker is the one official route.
  4. 4 If removal is refused, do not resubmit unchanged. A "cannot be removed at this time" response means Spamhaus still sees a listing reason or a recent abuse signal. Resubmitting the same request with stronger wording will not help. Resolve the outstanding issue, then request removal again.
  5. 5 Re-check before you resume sending. DBL listings also expire automatically once the domain stops matching the criteria. After an approved removal, allow a few minutes for DNS to propagate and confirm the domain is clear at check.spamhaus.org before ramping sending back up.

The official route

Straight to the source.

Removal happens on Spamhaus DBL's own tool — never through a paid service.

Spamhaus DBL removal tool ↗

Return codes

127.0.1.2 Spam domain
127.0.1.4 Phishing domain
127.0.1.5 Malware domain
127.0.1.6 Botnet command-and-control domain
127.0.1.102 Abused legitimate domain — spam
127.0.1.103 Abused spammed redirector domain
127.0.1.104 Abused legitimate domain — phishing
127.0.1.105 Abused legitimate domain — malware
127.0.1.106 Abused legitimate domain — botnet C&C

How long it takes

DBL listings expire on their own once the domain stops matching the criteria that caused them. If you request removal through the checker and it is approved, the change is processed immediately, with the domain typically clear within minutes to about 24 hours once DNS propagates. Delist without fixing the cause and the automated systems re-add the domain as soon as the behaviour reappears.

Common questions

About Spamhaus DBL, specifically.

Does Spamhaus charge to remove my domain from the DBL? No. DBL removal is always free, through check.spamhaus.org. Any service offering to remove a Spamhaus listing for a fee is a scam — no third party can influence or speed up a Spamhaus removal.
How long does DBL removal take? Listings expire automatically once the domain no longer matches the criteria. If you request removal and it is approved, it is processed immediately and the domain is usually clear within minutes to around 24 hours after DNS propagates.
What is the difference between the DBL and Spamhaus ZEN? The DBL lists domain names — the From domain and the domains in your links — while ZEN lists sending IP addresses. A clean IP does not clear a DBL listing, and changing servers does not either, because the listing follows the domain.
My domain was hacked and is now on the DBL — what do I do? That is an abused-legitimate listing (return codes 127.0.1.102 to .106). Remove the malicious content or redirect, close the vulnerability that let it in, then request removal through check.spamhaus.org describing what you fixed.
The removal form said my domain cannot be removed — why? It means Spamhaus still sees a listing reason or a recent abuse signal. Do not resubmit the same request with louder wording. Resolve the outstanding issue first, then request removal again.
How do I know why my domain is listed? Look it up at check.spamhaus.org. The DBL return code tells you the category: 127.0.1.2 is spam, .4 phishing, .5 malware, .6 botnet C&C, and .102 to .106 are abused-legitimate variants. Fix the cause that matches the code.

Do not fix it blind.

See every list you are on and every authentication problem behind the listing in one 40-second check — then let monitoring tell you the day a listing comes back.