Spamhaus is not one blocklist, and the list you are on decides whether removal takes a click, a form or a conversation. Before any of that, you have to find out which one it is, and the free checker in your browser tab almost certainly cannot tell you.
That second point is worth establishing first, because it decides whether the rest of the page is even about you.
Two public resolvers, two different wrong answers
RFC 5782 requires every DNS blocklist to list the address 127.0.0.2, so that a client can prove the zone is answering at all. Asked for that entry on 21 September 2026, Spamhaus ZEN gave two different answers depending on the resolver:
| Resolver | Answer | What a reader does with it |
|---|---|---|
| Google Public DNS | NXDOMAIN | reads as "not listed" |
| Cloudflare | 127.255.255.254 | an address in 127.0.0.0/8, which RFC 5782 defines as a listing |
Neither is the truth. 127.255.255.254 is inside the error range Spamhaus publishes for query problems, which its operator says must not be read as the subject being listed, and the NXDOMAIN is the same refusal with nothing in it to notice. One reads as clean and one reads as listed, for an address that is listed by definition.
The cause is not a bug at either resolver. Spamhaus refuses queries arriving through open public resolvers, because its free mirrors are rate-limited per querier and a public resolver is millions of queriers wearing one address. Spamhaus says the old free public mirror service is being deprecated, and points users at a free Data Query Service key or at its own web lookup instead.
So a browser-based checker has three options: use a key, send you to the web lookup, or report a Spamhaus result it did not measure. Our IP blacklist checker takes the second, and shows Spamhaus as a direct-check link rather than a row, because a row that can only ever say "clean" is worse than no row. An unreadable answer is not an absent one.
Spamhaus is five blocklists, and ZEN is three of them at once
Each list answers a different question, and the answer decides your route out.
- SBL, the Spamhaus Blocklist. IP ranges associated with spam operations. Evidence-based and reviewed by people.
- CSS, Combined Spam Sources. An automatic subset of SBL for IPs sending spam that do not merit a full SBL entry.
- XBL, the Exploits Blocklist. Compromised machines: open proxies, worms, hijacked hosts.
- PBL, the Policy Blocklist. IPs that should not be sending mail directly at all, such as consumer and dynamic ranges. A PBL entry is not an accusation.
- DBL, the Domain Blocklist. Domains, not IPs, checked at the content stage rather than at connection.
ZEN is PBL, SBL and XBL combined in one zone, which is what most mail servers query, and it is why "we are on Spamhaus" is not yet a diagnosis. A ZEN hit tells you one of three lists matched. Which one changes everything about what you do next.
Find out which list you are on before you fill anything in
Spamhaus runs a public web lookup at check.spamhaus.org. Put the IP in, and the result names the specific list and usually carries a short reason and a removal link. Do that before filling in a form, because every one of the routes below is a different form and submitting the wrong one wastes the only attempt worth making.
If the lookup says your IP is not listed and your mail is still being refused with a Spamhaus URL in the bounce, read the bounce again. Receivers quote the list they use, and several quote Spamhaus while running a local policy. The rejection text names the checking party, not always the listing one.
PBL and XBL you can usually remove yourself
The two self-service routes exist because both lists describe a state rather than an accusation.
PBL. The entry says this address is in a range whose owner has declared it should not send mail directly. If the range owner is your ISP and you have a legitimate reason to run a mail server there, the self-service removal on the lookup result handles it. If you are sending through your ISP's relay as intended, a PBL listing is not affecting you at all.
XBL. The entry says the machine looked compromised. Self-service removal is available, and it is the one case where removing without fixing is guaranteed to fail: the listing is generated by observed behavior, so a still-compromised host is relisted within hours. Find the infection or the open relay first.
SBL and CSS need evidence, not a request
These two are not self-service, and a request that reads as "please remove me" without anything else attached is the most common reason removal takes weeks.
What actually moves an SBL or CSS entry is a description of what was sending, what you changed, and how you know it stopped. Concretely: the source (a compromised account, a bought list, a misconfigured form), the change (the account disabled, the list deleted, the form given a confirmation step), and the evidence that sending has stopped.
CSS is automatic, so it also expires on its own once the behavior stops. If you have fixed the cause and you are not in a hurry, the cheapest action is to wait rather than to file.
DBL is about your domain, and it travels
A DBL entry lists a domain, so it follows you across every IP you send from, and changing servers does nothing. It is the one Spamhaus list where the fix is nearly always in your own content or your own signup flow rather than in your infrastructure.
Our domain blacklist checker queries the domain-side lists that do answer over public DNS, and shows Spamhaus DBL as a direct-check link for the same reason as ZEN. Across the domains we test for the Unspam 2026 Email Deliverability Benchmark, only 0.30% appear on a domain blacklist, so a domain listing is rare and, when it happens, specific.
What to fix before you ask, because a relisting costs more
A removal that is followed by a relisting is worse than the original listing, because it tells the list your fix was not one. Before any request, confirm the sending stopped at the source: the compromised account closed, the relay shut, the list segment removed, the form protected.
Then check the rest of the picture, because an IP on one list is usually on more than one. 6% of the sending IPs we check appear on an IP blacklist, and the ones that do are frequently listed by several operators at once for the same underlying cause.
What a free checker can honestly tell you
A browser-based checker can query the zones that answer public resolvers truthfully, and ours does: the tier-one IP lists, the domain and URI lists, each one decoded against its own return-code table rather than a shared assumption. What it cannot do is invent a Spamhaus verdict, and the honest output is a link rather than a green row.
If you want to know what the codes mean when a zone does answer, our guide to blocklist return codes covers the ones that are not what they look like. For the IP side more broadly, our guide to IP blacklists covers causes and prevention.
To see whether a listing is actually what is stopping your mail, rather than one signal among several, run a free spam test and read the blocklist result next to authentication and content.