Blacklist removal guide
How to remove your IP from SpamRATS Auth
RATS-Auth flags IP addresses seen attacking authentication. Here is what a listing means, and how to get off it.
What it is
The list, in plain terms.
RATS-Auth is one of the IP blocklists published by SpamRATS (operated by mThreat Technology), in the DNS zone auth.spamrats.com. It collects addresses detected taking part in Business Email Compromise (BEC) attacks — hosts caught trying to break into accounts by guessing passwords against SMTP, IMAP, POP and other services that require a login.
The list holds static IPs and networks tied to that abusive behaviour, including legitimate servers that have been compromised. It deliberately avoids dynamic and CGNAT ranges, and an address is added only after abusive activity is actually observed. Because listings are evidence-based, RATS-Auth is aimed at protecting authentication endpoints rather than general inbound mail filtering.
RATS-Auth lists IP addresses, not domains — the server doing the connecting is flagged, not the domain in your message. A listing only matters if you run a mail server or another authenticated service on that IP. If you are an ordinary user whose mail is bouncing, the fix is almost always at your ISP, not here.
Why you get listed
What a listing on SpamRATS Auth means.
How to get removed
Delisting, in order.
Removal is free. Fix the cause first — a listing you clear without a fix comes straight back.
- 1 Confirm the listing. Look your IP up at spamrats.com/lookup.php. A RATS-Auth listing returns 127.0.0.43. Confirm it is RATS-Auth and not another SpamRATS list (Dyna, NoPtr or Spam), because the removal route differs for each.
- 2 Stop the abuse first. Find and clean the compromised host, close the breached account, patch the exploited application, or secure the credentials being abused. RATS-Auth is behaviour-based, so if you request removal before the source is gone you will simply be relisted.
- 3 Confirm you control the IP. RATS-Auth removal is not the automatic self-service flow. You must be able to prove you are the owner or operator of the IP, as shown in its rWHOIS or SWIP record. If you cannot — for example the IP belongs to your provider — your ISP or hosting provider has to request removal instead.
- 4 Submit the removal request. Use the contact form at spamrats.com/contact.php. Include the affected IP, evidence that you control it, an explanation of the activity, and the steps you have taken to make sure it does not happen again. Removal is reviewed by hand.
- 5 Re-check before you resume sending. Once removal is granted, allow a little time for DNS to update, then confirm the address is clear at spamrats.com/lookup.php before you ramp sending back up.
The official route
Straight to the source.
Removal happens on SpamRATS Auth's own tool — never through a paid service.
SpamRATS Auth removal tool ↗Return codes
How long it takes
RATS-Auth removals are handled manually after you submit the contact form, so there is no instant self-service delisting and SpamRATS publishes no fixed turnaround. Expect a review once you have proven ownership and explained the fix; the listing clears from DNS shortly after it is approved. Remove the address before the abuse has stopped and it will be listed again.
Common questions
About SpamRATS Auth, specifically.
Related
The bounce behind the listing.
Do not fix it blind.
See every list you are on and every authentication problem behind the listing in one 40-second check — then let monitoring tell you the day a listing comes back.