UCEPROTECT Levels 1, 2 and 3 Are One Operator, Not Three Lists

A UCEPROTECT listing usually arrives as three rows at once, and that looks like three organizations reaching the same conclusion about you. It is one. Levels 1, 2 and 3 are published by the same operator, they escalate from your address to your provider to your provider's entire network, and only the first of them is about anything you did.

Reading the three rows as three opinions is what sends people to fix something that is not theirs to fix.

Level 1 is your address, Level 2 is your provider, Level 3 is their network

The three zones answer three different questions, and only one of them names you.

LevelWhat is listedWhose behavior
Level 1A single IP addressYours
Level 2An allocation, meaning a netblock your provider holdsYour neighbours'
Level 3An entire ASN, meaning your provider's whole networkYour provider's

UCEPROTECT's own counters make the escalation visible: Level 1 holds tens of thousands of addresses, Level 2 holds thousands of allocations, and Level 3 holds a few hundred networks. A Level 3 entry is a statement about a hosting company, not about a customer, and every customer inside that network inherits it.

That is why the second question to ask about a UCEPROTECT listing is not "what did I send" but "which level is this".

Only Level 1 is about something you did

A Level 1 entry means an address hit UCEPROTECT's spamtraps. That is a claim about your sending, and it is the only one of the three that is.

A Level 2 entry means enough Level 1 entries accumulated inside one of your provider's netblocks. Your address can be perfectly clean and still sit inside the listed block, because the listing is about the block. A Level 3 entry means the provider's whole ASN crossed a threshold, and at that point your own conduct is not part of the calculation at all.

So the honest reading of "listed on UCEPROTECT levels 1, 2 and 3" is: you sent something, your neighbours sent something, and your hosting company has a problem. Three facts, one organization, and two of them are not addressed to you.

The three levels and Backscatterer are one operator

This is checkable rather than a matter of opinion, and it is worth checking because a fourth row from the same operator appears on the same reports under a different domain name.

ips.backscatterer.org and dnsbl-1.uceprotect.net are delegated to the identical five nameservers, dns-cluster-1 through dns-cluster-5.uceprotect.net. Their parent domains, backscatterer.org and uceprotect.net, resolve to the same pair of nameservers as each other too. The registrable domain differs; the operator does not.

Our own IP blacklist checker counts operators rather than rows for exactly this reason. The rows stay separate, because Level 3 listing an ASN genuinely is a different fact from Level 1 listing one address, but a headline that says "listed on 4 blocklists" when one organization holds all four is arithmetic in the wrong direction. It says "from n operators" when the two numbers differ.

Level 1 clears itself in seven days, or you can pay

UCEPROTECT publishes two routes off Level 1, and the free one requires no request at all: an entry expires automatically seven days after the last spam from that address reaches its spamtraps. Stopping the sending is the whole procedure. The clock restarts on every new hit, so an address that is still leaking mail never expires, which is the mechanism rather than a penalty.

The paid route is an immediate manual removal, charged per IP address, currently taken through Stripe. It is optional and it does not do anything the free route does not do more slowly. What it buys is the seven days, and it buys them only if the sending has actually stopped.

Before choosing either, find the source. An address that hits a spamtrap is usually a compromised account, a purchased or scraped segment, or a form with no confirmation step. If you pay for immediate removal and the cause is still live, you have bought a listing that returns.

Levels 2 and 3 have no button for you at all

Level 2 entries are removed automatically and free of charge once the netblock no longer meets the listing criteria, which in practice means the Level 1 entries inside it have to clear. UCEPROTECT is explicit that normally only your service provider can request this.

Level 3 works the same way at the scale of an ASN: it clears automatically when the network stops matching the criteria, and there is nothing a single customer inside it can do.

That leaves three real options when the listing is not yours:

  1. Check whether it is actually affecting you. Many receivers use Level 1 only. Levels 2 and 3 are aggressive by design and a substantial number of mail systems do not consult them, so the first question is whether your bounces actually cite the level you are worried about.
  2. Ask your provider, with the specific netblock or ASN, because they are the only party who can act.
  3. Move to a provider whose ranges are not listed, which is the answer UCEPROTECT itself suggests and the only one entirely in your hands.

There is also a paid whitelisting route: UCEPROTECT states that individual clean addresses registered at ips.whitelisted.org are generally excluded from Level 2. That is a commercial service from the same operator, and whether it belongs in your plans is a judgement about your own situation rather than a technical question.

Backscatterer is not a spam list, and its operator says so

The fourth zone from this operator lists addresses that emitted misdirected bounces or ran sender callouts. Its own documentation is emphatic that this is not a statement about spamming, and that it is meant for rejecting those specific transactions rather than for judging a sender.

We treat it as advisory for that reason: a listing there is real and is always shown, but it does not turn a headline red and it is not counted in "clean on n of m". Counting it red accuses a sender of spamming on evidence the operator says is not about spam. Counting it clean pads the denominator with a zone that could never have listed most senders in the first place.

If you are listed there, the fix is usually in your bounce handling or in a verification feature that probes recipient servers, not in your marketing.

What to do about a UCEPROTECT listing

  1. Identify the level before anything else. UCEPROTECT's own lookup names it.
  2. If it is Level 1, find the source and stop it, then either wait seven days or pay to skip them.
  3. If it is Level 2 or 3, check whether it is costing you delivery at all, then talk to your provider, then consider moving.
  4. Check the rest of the picture. Across the sending IPs we check for the Unspam 2026 Email Deliverability Benchmark, 6% appear on an IP blacklist, leaving 94% clean, and an address listed by one operator is often listed by others for the same underlying cause.
  5. Read the codes rather than the row count. Our guide to blocklist return codes covers what each zone's answer actually means, and the largest operator of all is the subject of our guide to Spamhaus delisting.

For causes and prevention on the IP side generally, our guide to IP blacklists covers the ground. To see whether a listing is what is actually stopping your mail, run a free spam test and read the blocklist result next to authentication and content.

Frequently asked questions

What is the difference between UCEPROTECT Level 1, 2 and 3?

Level 1 lists a single IP address, and it is the only level that is a claim about your own sending: it means that address hit UCEPROTECT's spamtraps. Level 2 lists an allocation, meaning a netblock your provider holds, once enough Level 1 entries accumulate inside it, so your address can be clean and still sit in the listed block. Level 3 lists an entire ASN, meaning your provider's whole network, at which point your own conduct is not part of the calculation.

How do I get off UCEPROTECT Level 1?

Stop the sending. A Level 1 entry expires automatically seven days after the last spam from that address reaches the spamtraps, free and with no request, and the clock restarts on every new hit. There is also an optional paid immediate removal charged per IP address. It buys the seven days and nothing else, so it is only worth it once the cause is actually fixed. An address paid off the list while still sending is listed again.

Can I remove myself from UCEPROTECT Level 2 or Level 3?

No. Level 2 clears automatically and free of charge once the netblock no longer meets the criteria, which means the Level 1 entries inside it have to clear first, and UCEPROTECT says normally only your service provider can request it. Level 3 works the same way at the scale of an ASN. Your options are to check whether the level is affecting delivery at all, to raise the specific netblock or ASN with your provider, or to move to a provider whose ranges are not listed.

Is being on UCEPROTECT levels 1, 2 and 3 three separate problems?

It is one operator reporting three facts. The three zones are published by the same organization, and a fourth zone from the same operator, ips.backscatterer.org, appears under a different domain name: it is delegated to the identical five dns-cluster nameservers under uceprotect.net, and the two parent domains share a nameserver pair as well. The rows are still separate facts, but a headline that counts four blocklists is counting one organization four times.

Should I pay UCEPROTECT for removal?

It is optional and it does nothing the free route does not do more slowly. The free route is automatic expiry seven days after the last spamtrap hit, so what the fee buys is those seven days. Paying while the cause is still live buys a listing that returns. There is also a separate paid whitelisting service, which UCEPROTECT says generally excludes registered clean addresses from Level 2, and whether that belongs in your plans is a judgement about your situation rather than a technical question.

What is Backscatterer and why is my IP on it?

It lists addresses that emitted misdirected bounces or ran sender callouts, and its operator is emphatic that it is not a statement about spamming. It is meant for rejecting those specific transactions rather than for judging a sender, which is why a careful checker shows the listing but does not let it turn a verdict red or count it in a clean-on-n-of-m total. If you are on it, the fix is usually in your bounce handling or in a verification feature that probes recipient servers.

See where your campaign actually lands.

Start a free spam test Inbox placement test