Blocklists
A sending IP or domain appears on a DNS blocklist used by receivers or downstream filters.
Problem summary
A sending IP or domain appears on a DNS blocklist used by receivers or downstream filters.
Symptoms
- Blocklist query tools show a listing for IP or domain
- Sudden rejects citing blocked/listed senders
- Delivery collapses at multiple receivers at once
Possible causes
- Spamtrap hits or abuse complaints
- Compromised account or open relay behavior
- Neighbor damage on a shared IP
- Malware or form-injection sending spam
How to diagnose
- Confirm which list and whether IP or domain is listed
- Identify traffic that preceded the listing
- Check for account compromise or unexpected outbound volume
How to fix
- Stop abusive traffic immediately
- Follow the list’s delisting process with evidence of remediation
- Move clean traffic off burned shared infrastructure if needed
How to verify
- Listing cleared on authoritative lookup
- Rejects citing the list stop
Prevention
- Monitor major lists for sending IPs
- Enforce abuse detection on outbound systems
When to escalate
- Production mail is failing for a material share of recipients after remediation attempts