Spamhaus is the blocklist that matters most — its data sits in front of the majority of the world's mailboxes. This guide covers every Spamhaus list (ZEN, SBL, CSS, XBL, PBL, DBL): how to read the return code, find the exact listing, fix the cause, file the removal request, and how long each one takes.
Updated on 7 September 2026 · expanded with return-code table, bounce decoder, per-list walkthroughs and Workspace/M365 sender section
First: confirm the listing and see every other list you're on.
Short answer: go to check.spamhaus.org, enter the IP or domain from your bounce message, and note which list is named. PBL, XBL and CSS listings are self-service once the cause is fixed. SBL and DBL listings need a short, specific written appeal. Every removal is free, and most clear within 24–72 hours. The rest of this page is the detail that decides whether you stay delisted.
"Spamhaus" is a family of lists, and the removal path is different for each. Most mail servers query ZEN, a combined zone; a ZEN hit means you are on at least one of the lists below. The DNS return code tells you which.
| Return code | List | What it means | Removal path |
|---|---|---|---|
127.0.0.2 | SBL | Verified spam source, manually listed by Spamhaus investigators | Fix cause, then written appeal |
127.0.0.3 | SBL CSS | Automated listing for low-reputation or "snowshoe" sending patterns (typical for cold-email infrastructure) | Fix cause, self-service removal; auto-expires when spam stops |
127.0.0.4 – 127.0.0.7 | XBL (incl. CBL data) | Compromised machine: malware, open proxy, botnet traffic seen from this IP | Clean the host, then self-service removal |
127.0.0.10 – 127.0.0.11 | PBL | Policy list: this IP range should not send mail directly (residential, dynamic, or ISP-declared) | Self-service removal for static IPs with a real mail server; otherwise relay via your provider |
127.0.1.x (queried via dbl.spamhaus.org) | DBL | Your domain is listed — as a spam, phishing, malware or "abused legitimate" domain — regardless of which IP sent the mail | Fix cause, then written appeal via the DBL removal form |
127.255.255.252 / .254 / .255 | Error, not a listing | Your query was refused: typo in the zone, no DQS key, or you are querying through a public resolver Spamhaus blocks | Query from your own resolver or use a checker like the one above |
Two practical notes. First, the IP in a bounce is the connecting IP — if you send through an email service provider (ESP) or a mailbox provider, that is their IP, not yours, and only your domain is under your control. Second, most "I'm on Spamhaus" reports from cold-email teams turn out to be DBL domain listings, not IP listings. Check both.
You rarely learn about a listing from Spamhaus. You learn from a bounce. These are the common shapes, and which list they point to:
| Bounce text (abridged) | Where it comes from | Listing to check |
|---|---|---|
554 5.7.1 Service unavailable; Client host [1.2.3.4] blocked using zen.spamhaus.org | Postfix / Exim receivers (most corporate mail servers) | IP on ZEN — look up the IP for the exact list |
550 5.7.1 ... blocked using dbl.spamhaus.org or Sender domain listed in DBL | Receivers doing URI/domain checks | Domain on DBL — the domain in your From header or in a link in the body |
550 5.7.1 [S3150] ... blocked because it is listed on Spamhaus | Microsoft 365 / Outlook.com | IP on ZEN; if you send via Microsoft, your domain on DBL |
421 4.7.0 ... temporarily deferred; listed in Spamhaus | Receivers that soft-fail on listings | Same lookup; mail is queued, so you have hours, not minutes |
550 5.7.1 Our system has detected that this message is likely suspicious | Gmail | Not a Spamhaus bounce — Gmail uses its own reputation. See Gmail 550 5.7.1 |
Requesting removal without fixing the cause is the fastest way to get re-listed with a longer duration. Spamhaus tracks repeat listings, and appeals from IPs or domains with a history are read with less patience. For outbound and SDR teams the causes are consistent:
Diagnose with evidence, not guesses. Your ESP's bounce log shows the first rejection timestamp; compare it with the campaign that launched just before. Spamhaus's lookup page often shows the listing date and a one-line reason, which usually names the pattern (for example "spam-emitting domain seen in unsolicited mail") without naming the recipient.
Everything below happens at check.spamhaus.org, Spamhaus's Blocklist Removal Center. There is no phone line and no paid fast lane.
If you send through Google Workspace or Microsoft 365 — which describes most SDR teams — you do not control the sending IP, and Google's and Microsoft's outbound IPs are almost never on Spamhaus. When a Workspace or M365 sender hits a Spamhaus bounce, the listing is nearly always the domain on the DBL: either your primary domain, one of your secondary "outreach" domains, or a link domain in the body. Look up the domain, follow the DBL process, and pause every mailbox on that domain until it clears. Continuing to send from a DBL-listed domain through Workspace also erodes your Google reputation, which is a separate, slower problem to fix (see Postmaster Tools reputation).
| List | Removal type | Typical time to clear | If it comes back |
|---|---|---|---|
| PBL | Self-service with email confirmation | Minutes | Range re-declared by the ISP — relay instead |
| XBL | Self-service after cleanup | Immediate | Host still infected; re-listed within hours |
| SBL CSS | Self-service; auto-expiry | Hours to 48h after spam stops | Each re-listing lasts longer; written explanation required |
| SBL | Written appeal, human review | 24–72h | Further appeals need new evidence of change |
| DBL | Written appeal, human review | 24–72h | Check linked/tracking domains; fix the abused resource |
Receivers don't all refresh at the same moment. After Spamhaus confirms removal, allow several hours for DNS caches at corporate gateways to expire before judging whether bounces have stopped.
A rejection is almost always one of three things: the cause is still visible (spam still arriving in traps), the explanation didn't address the evidence Spamhaus cited, or the IP or domain has a history that a first appeal can't offset. Don't resubmit the same text. Wait until the sending has genuinely stopped for at least 48 hours, gather what changed (list source removed, credential rotated, volume plan), and write a fresh, shorter appeal that references those facts. If you are on a shared IP that a neighbour burned, ask your ESP to move you to a different pool — the appeal for that IP is theirs to make, not yours.
p=none with reporting. Run the domain grader to see all four at once.No. Spamhaus never charges for removal. Anyone offering paid Spamhaus delisting is filling in the same free form on your behalf, or is a scam.
Yes, but from your own resolver. Queries through large public resolvers (Google DNS, Cloudflare, OpenDNS) return error codes in the 127.255.255.x range rather than answers. High-volume users need a free Data Query Service (DQS) key.
Ask them to move you to a different IP pool and to handle the appeal. Meanwhile, confirm your own domains are clean on the DBL so that a pool move actually fixes your deliverability.
Indirectly. Gmail relies primarily on its own reputation signals, but the same behaviour that causes a Spamhaus listing usually damages Gmail reputation in parallel. Fix the cause and both recover; fix only the listing and Gmail stays cold.
We re-check every few hours and send exactly one email when your domain comes back clean — no account, no newsletter.
Related: Why CSS listings come back · Barracuda removal · SpamCop removal · All blacklists — removal master guide · Blacklist Checker