IP list

Blacklist removal guide

How to remove your IP from SpamRats Spam

RATS-Spam is an evidence-based spam list. Stop the sending that triggered it, then remove the IP yourself for free.

What it is

The list, in plain terms.

RATS-Spam is one of several DNS blocklists published by SpamRats (operated by mThreat Technology Inc.) in the zone spam.spamrats.com. It lists IP addresses that have been repeatedly observed or reported sending spam in large volumes, including mail that hits SpamRats spam traps.

By the operator's own description the list contains IPs from compromised servers, hosts or relays, and mail servers set up for the purpose of spamming. SpamRats states it only adds an address once a significant amount of spam-style behaviour has been reported or observed, which it credits for a low false-positive rate.

It lists IP addresses, not domains — the flagged party is your sending server, not the domain in your message. A RATS-Spam listing only affects you if you run a mail server on that IP. If you do, it can cause deferrals or rejections at the receivers that consult the list until the cause is fixed and the listing cleared.

Why you get listed

What a listing on SpamRats Spam means.

Spam sent in volume The IP was repeatedly observed or reported sending unsolicited bulk email, enough spam-style activity to meet the listing threshold rather than a single stray message.
Spam-trap hits Mail from the IP reached SpamRats spam traps — addresses that should never receive legitimate mail — which is treated as direct evidence of spam or a poorly maintained list.
Compromised host or open relay The IP belongs to a compromised server, host or relay that is being abused to emit spam, often without the owner's knowledge. The machine is the source even if you did not send the mail deliberately.
Server built for spamming SpamRats also lists mail servers that appear to have been created specifically to send spam, based on their sending behaviour.

How to get removed

Delisting, in order.

Removal is free. Fix the cause first — a listing you clear without a fix comes straight back.

  1. 1 Confirm the listing and the zone. Look the sending IP up with the SpamRats lookup tool. Check that it returns 127.0.0.38 for RATS-Spam specifically, and not a sibling zone such as RATS-Dyna or RATS-NoPtr, because the fix here is stopping spam rather than correcting reverse DNS.
  2. 2 Stop the spam before you remove anything. This is the actual fix. Find and shut down the source: clean a compromised server, close any open relay, terminate the abused or hijacked account, and stop the bulk sending that triggered the listing. SpamRats warns that if the IP keeps up the abusive behaviour it becomes harder to remove next time.
  3. 3 Harden the sending setup. Once the immediate abuse is stopped, tighten authentication and rate controls so it cannot recur — secure SMTP AUTH credentials, require submission on port 587, and check that SPF, DKIM and DMARC are in order. An IP that resumes spamming is simply re-listed.
  4. 4 Submit the automatic self-removal. Go to the SpamRats removal page, enter the IP address and complete the CAPTCHA. RATS-Spam removal is automatic self-service and free — you do not need to wait for a human to review it once the spam is resolved.
  5. 5 If self-removal is blocked, use the contact form. If the automatic removal is not available for your IP, contact SpamRats through their contact form with the details of the case, rather than paying any third party.
  6. 6 Re-check before resuming. Allow cached DNS answers at receivers to expire, then confirm the IP no longer returns 127.0.0.38 in the SpamRats lookup before you ramp sending back up.

The official route

Straight to the source.

Removal happens on SpamRats Spam's own tool — never through a paid service.

SpamRats Spam removal tool ↗

Return codes

127.0.0.38 RATS-Spam — IP repeatedly seen sending spam or hitting spam traps
127.0.0.36 RATS-Dyna — dynamic or generic reverse DNS (separate SpamRats zone)
127.0.0.37 RATS-NoPtr — no reverse DNS at all (separate SpamRats zone)
127.0.0.43 RATS-Auth — abusive authentication attempts (separate SpamRats zone)

How long it takes

RATS-Spam removal is automatic self-service, so a successful request takes effect without waiting for manual review. Allow time for cached DNS answers to expire at receivers before the change is visible everywhere. SpamRats publishes no fixed guaranteed turnaround, and if the spam has not actually stopped the IP is re-listed — so resolving the cause is what determines whether removal sticks.

Common questions

About SpamRats Spam, specifically.

Does SpamRats charge to remove my IP from RATS-Spam? No. Removal is free and self-service at the SpamRats removal page. Any service offering to clear a SpamRats listing for a fee is a scam — no third party can influence or speed up a SpamRats removal.
How do I actually get off RATS-Spam? Stop the spam first — clean the compromised host, close the open relay or secure the abused account — then enter the IP on the SpamRats removal page and complete the CAPTCHA. The self-removal is automatic once the cause is resolved.
Why is my IP on RATS-Spam? Because the IP was repeatedly observed or reported sending spam in volume, or it reached a SpamRats spam trap. That usually means a compromised server, an open relay, an abused account, or a server being used to spam.
What does return code 127.0.0.38 mean? It is the RATS-Spam result in the spam.spamrats.com zone, telling the receiver the IP is listed as a spam source. The sibling zones return different codes: 127.0.0.36 is RATS-Dyna, 127.0.0.37 is RATS-NoPtr and 127.0.0.43 is RATS-Auth.
I removed my IP but it got re-listed — why? Because the spam behaviour was still happening. SpamRats re-adds an IP that keeps sending spam, and warns that repeat listings become harder to clear. Fix the source before you self-remove, not after.
I am not a mail server administrator — do I need to do anything? Probably not. A RATS-Spam listing only affects you if you run your own mail server. If you send through your ISP and mail is failing, contact your ISP and check your mail client uses port 587 with SMTP authentication, and scan your devices for malware that may have caused the listing.

Do not fix it blind.

See every list you are on and every authentication problem behind the listing in one 40-second check — then let monitoring tell you the day a listing comes back.