Domain list

Blacklist removal guide

How to remove your domain from URIBL

URIBL flags the domains that appear inside spam, not the server that sent it. Here is what a listing means and how to clear it.

What it is

The list, in plain terms.

URIBL is a Realtime URI Blacklist (an RHSBL) served over DNS. It lists domain names that turn up in the body of unsolicited bulk and commercial email — the links, sender domains and tracking hosts inside messages — so that anti-spam software can score or tag mail that references them. It does not list the IP address that delivered the message.

That distinction matters. If your mail is being blocked because of URIBL, the problem is a domain in your message content, not your sending server. A single lookup against multi.uribl.com returns a bit-masked answer telling the receiver which of URIBL's lists the domain is on: black, grey or red.

black.uribl.com holds domains URIBL attributes to spammers, maintained with a goal of zero false positives. grey.uribl.com holds domains found in bulk mail that may also send legitimate traffic. red.uribl.com holds domains actively appearing in current mail flow that are not on black. multi is simply the combined query across all three.

Why you get listed

What a listing on URIBL means.

black — a spammer domain The domain is attributed to spammers or spam operations. This is the most serious listing and the one most receivers act on. URIBL aims for zero false positives here, so a black listing means the domain appeared in spam URIBL trusts.
grey — seen in bulk mail The domain was found in unsolicited bulk or commercial email but may also carry legitimate traffic, such as URL shorteners, redirectors or shared hosting used by both good and bad senders.
red — active in current mail flow The domain is showing up in live mail flow and is not on black. It is an early, fast-moving signal rather than a settled spam attribution.
A referenced domain, not your server You can be caught out by a domain you only link to — a shortener, an image host, an affiliate or tracking domain in your template. URIBL lists the domain that appears in the message, so audit every host in your content, not just your own.

How to get removed

Delisting, in order.

Removal is free. Fix the cause first — a listing you clear without a fix comes straight back.

  1. 1 Confirm the listing and which list. Look the domain up on the URIBL form at admin.uribl.com. The bit-masked return code tells you whether it is on black (127.0.0.2), grey (127.0.0.4), red (127.0.0.8) or a combination. Check every domain that appears in your message body, not only your sending domain.
  2. 2 Fix the cause first. Stop the behaviour that got the domain listed: remove or replace a compromised link or redirector, secure any abused account or web form, and clean the reputation of any third-party host you reference. URIBL warns that a request submitted without resolving the underlying issue will simply be relisted, often for longer.
  3. 3 Register for a URIBL account. Delist requests can only be submitted through the web interface, and that requires a registered login. Create an account at admin.uribl.com before you can submit anything.
  4. 4 Submit the delist through the web form only. Use the same lookup form to request removal once you are logged in. Do not email URIBL — they state plainly that emailed delist requests and requests for information about a listing receive no reply. URIBL also does not disclose why a domain was listed or share trap data.
  5. 5 Re-check before you resume. After submitting, re-query the domain on multi.uribl.com to confirm it no longer returns a listing code, and allow time for DNS caches to expire before you rely on delivery again.

The official route

Straight to the source.

Removal happens on URIBL's own tool — never through a paid service.

URIBL removal tool ↗

Return codes

127.0.0.2 black — domain attributed to spammers
127.0.0.4 grey — domain found in bulk/commercial mail
127.0.0.8 red — domain active in current mail flow
127.0.0.14 black, grey and red combined (test points)
127.0.0.1 query blocked — the resolver you queried through is rate-limited or banned, not a domain listing
127.0.0.255 your DNS resolver is banned for abusing the public mirror infrastructure — not a domain listing

Common questions

About URIBL, specifically.

Does URIBL charge to delist a domain? URIBL's only removal channel is its own web form, which requires a free registered account. No third party can influence, speed up or guarantee a URIBL removal, so treat any paid "URIBL removal service" as a scam.
Why is my domain on URIBL if I did not send spam? URIBL lists the domains that appear inside spam messages, not the servers that send them. Your domain, or a shortener, tracking host or redirector you reference in your content, showed up in bulk or unsolicited mail. Audit every host in your message body, not just your sending IP.
How do I request removal from URIBL? Register for an account, then submit the delist through the lookup form at admin.uribl.com. Fix the cause of the listing first. URIBL does not accept delist requests by email and will not reply to them.
Will URIBL tell me why my domain was listed? No. URIBL does not provide feedback loops and will not disclose reported or trap data. You need to work out the cause yourself by reviewing the domains in your recent message content.
I got a 127.0.0.1 response — am I listed? No. 127.0.0.1 means your query was blocked because the DNS resolver you used is rate-limited or banned from the public mirrors, typically from high volume through a shared public resolver. Query through your own resolver or a rsync/DUL feed instead. 127.0.0.255 has the same meaning.
I delisted but got relisted — why? Because the cause was still present. URIBL warns that removals submitted without resolving the underlying issue result in the domain being relisted, sometimes for an extended period. Fix the compromised link, account or referenced host before you submit a delist.

Do not fix it blind.

See every list you are on and every authentication problem behind the listing in one 40-second check — then let monitoring tell you the day a listing comes back.