IP list

Blacklist removal guide

How to remove your IP from SpamRATS Auth

RATS-Auth flags IP addresses seen attacking authentication. Here is what a listing means, and how to get off it.

What it is

The list, in plain terms.

RATS-Auth is one of the IP blocklists published by SpamRATS (operated by mThreat Technology), in the DNS zone auth.spamrats.com. It collects addresses detected taking part in Business Email Compromise (BEC) attacks — hosts caught trying to break into accounts by guessing passwords against SMTP, IMAP, POP and other services that require a login.

The list holds static IPs and networks tied to that abusive behaviour, including legitimate servers that have been compromised. It deliberately avoids dynamic and CGNAT ranges, and an address is added only after abusive activity is actually observed. Because listings are evidence-based, RATS-Auth is aimed at protecting authentication endpoints rather than general inbound mail filtering.

RATS-Auth lists IP addresses, not domains — the server doing the connecting is flagged, not the domain in your message. A listing only matters if you run a mail server or another authenticated service on that IP. If you are an ordinary user whose mail is bouncing, the fix is almost always at your ISP, not here.

Why you get listed

What a listing on SpamRATS Auth means.

Password-guessing and brute force Your IP was seen making abusive authentication attempts — repeatedly guessing credentials against SMTP, IMAP, POP, SSH or similar services. This is the core trigger for a RATS-Auth listing.
Business Email Compromise activity The address was detected as part of a BEC operation: attempts to break into or take over mail accounts. RATS-Auth is built specifically to catch this behaviour.
A compromised server A legitimate host that has been hijacked and is now attacking login endpoints on its owner's behalf without their knowledge. The listing reflects the abuse, not intent — but you still have to clean the machine.
Criminal or static abuse networks Ranges operated by parties SpamRATS tracks as engaged in criminal behaviour. RATS-Auth avoids dynamic and CGNAT space, so a listing here points at a fixed, controllable host.

How to get removed

Delisting, in order.

Removal is free. Fix the cause first — a listing you clear without a fix comes straight back.

  1. 1 Confirm the listing. Look your IP up at spamrats.com/lookup.php. A RATS-Auth listing returns 127.0.0.43. Confirm it is RATS-Auth and not another SpamRATS list (Dyna, NoPtr or Spam), because the removal route differs for each.
  2. 2 Stop the abuse first. Find and clean the compromised host, close the breached account, patch the exploited application, or secure the credentials being abused. RATS-Auth is behaviour-based, so if you request removal before the source is gone you will simply be relisted.
  3. 3 Confirm you control the IP. RATS-Auth removal is not the automatic self-service flow. You must be able to prove you are the owner or operator of the IP, as shown in its rWHOIS or SWIP record. If you cannot — for example the IP belongs to your provider — your ISP or hosting provider has to request removal instead.
  4. 4 Submit the removal request. Use the contact form at spamrats.com/contact.php. Include the affected IP, evidence that you control it, an explanation of the activity, and the steps you have taken to make sure it does not happen again. Removal is reviewed by hand.
  5. 5 Re-check before you resume sending. Once removal is granted, allow a little time for DNS to update, then confirm the address is clear at spamrats.com/lookup.php before you ramp sending back up.

The official route

Straight to the source.

Removal happens on SpamRATS Auth's own tool — never through a paid service.

SpamRATS Auth removal tool ↗

Return codes

127.0.0.36 RATS-Dyna — dynamic or generic-looking IP space
127.0.0.37 RATS-NoPtr — no valid reverse DNS (PTR) record
127.0.0.38 RATS-Spam — IP tied to sending spam
127.0.0.43 RATS-Auth — authentication abuse / Business Email Compromise

How long it takes

RATS-Auth removals are handled manually after you submit the contact form, so there is no instant self-service delisting and SpamRATS publishes no fixed turnaround. Expect a review once you have proven ownership and explained the fix; the listing clears from DNS shortly after it is approved. Remove the address before the abuse has stopped and it will be listed again.

Common questions

About SpamRATS Auth, specifically.

Is SpamRATS RATS-Auth removal free? Yes. Requesting removal costs nothing — you submit it through the SpamRATS contact form. Any service charging a fee to remove a SpamRATS listing is a scam, as no third party can influence or speed up a SpamRATS decision. Querying the list in volume needs an API key or subscription, but removing your own IP does not.
Why is my IP on RATS-Auth? Because SpamRATS detected your IP making abusive login attempts — typically password-guessing against SMTP, IMAP, POP or similar services, often from a compromised server. An address is added only after that activity is observed, so a listing means the behaviour was seen coming from your IP.
How do I remove my IP from auth.spamrats.com? Stop the abusive traffic first, then use the contact form at spamrats.com/contact.php. You must prove you own or operate the IP via its rWHOIS or SWIP record and explain what you have done to prevent a recurrence. There is no one-click self-removal for this list.
My mail bounces but I do not run a mail server — do I need to delist? Probably not. SpamRATS only affects you if the listed IP is your own mail server. If you are an ordinary user, contact your ISP and check that your mail client uses port 587 with SMTP authentication; in most cases you do not need to touch SpamRATS at all.
What return code does RATS-Auth use? RATS-Auth answers with 127.0.0.43. In a combined lookup you may also see 127.0.0.36 (RATS-Dyna), 127.0.0.37 (RATS-NoPtr) and 127.0.0.38 (RATS-Spam); each is a separate list with its own removal route.
How long does RATS-Auth removal take? It is a manual review, so there is no fixed time. Once you have proven ownership and shown the abuse has stopped, the listing clears from DNS soon after approval. Delist without fixing the cause and the address will be listed again.

Do not fix it blind.

See every list you are on and every authentication problem behind the listing in one 40-second check — then let monitoring tell you the day a listing comes back.