Skip to content

Spamhaus listings explained: SBL, XBL, PBL, CSS, DBL

Spamhaus runs several blocklists with different causes and fixes. What each one means for a sender, how to check a listing and where to start.

Koltrix Team5 min read
An old padlock hanging on a wooden fence
Photo by Georg Bommeli on Unsplash
On this page(6 sections)
  1. Why Spamhaus listings matter
  2. The lists
  3. SBL: Spamhaus Block List
  4. CSS
  5. XBL: Exploits Block List
  6. PBL: Policy Block List
  7. DBL: Domain Block List
  8. ZEN: the combined zone
  9. Reading return codes
  10. Checking a listing
  11. Before requesting removal
  12. Key takeaways

"We're on Spamhaus" can mean several very different things. Spamhaus runs multiple blocklists, each listing different kinds of problems for different reasons, and the fix for one has nothing to do with the fix for another.

Knowing which list you are on is the first step to getting off it.

Why Spamhaus listings matter

Spamhaus data is used by a very large number of mail servers, filtering products and providers to decide whether to accept or score incoming mail. Many receivers query its lists in real time during the SMTP conversation and reject mail from listed IPs outright. A listing can therefore cause hard bounces across many unrelated recipient domains at once.

The main lists are queried as DNS blocklists (DNSBLs). Receivers reverse the octets of an IP address, append the list's zone name, and look up the result. An answer means the IP is listed; the specific answer code says which list.

The descriptions below summarize Spamhaus's own public explanations at the time of writing. Spamhaus updates its products and documentation, so check its site for current details before acting on a listing.

The lists

SBL: Spamhaus Block List

The SBL lists IP addresses that Spamhaus has identified as sources of spam, spam operations or related abuse, such as hosting for spammers. Listings are generally made by Spamhaus researchers, and each typically has a reference record explaining the reason.

If you are on the SBL: treat it as serious. The listing record usually says what was observed. You will need to stop the activity, and if the listing concerns a hosting or network provider's range, work with that provider.

CSS

The CSS is an automatically generated component, published as part of the SBL zone, that targets IPs associated with low-reputation sending, such as snowshoe spam spread across many addresses or mail with characteristics Spamhaus associates with spam. Legitimate senders sometimes land here because of poor list practices or misconfiguration.

If you are on the CSS: look for the cause in your sending: unauthenticated mail, bad HELO names, sending to old or purchased lists, or a compromised application. CSS listings typically expire once the problematic behavior stops, and Spamhaus provides a removal process through its lookup tool.

XBL: Exploits Block List

The XBL lists IP addresses of hijacked or infected machines: computers running malware that sends spam, open proxies and similar exploits. It incorporates data from automated detection systems.

If you are on the XBL: something on that IP is compromised, or the IP is shared with something compromised (common behind NAT). Find and clean the infected device or misconfigured service before requesting removal, or the listing will return.

PBL: Policy Block List

The PBL is different in kind. It does not say the IP did anything wrong. It lists ranges that, according to the network owner or Spamhaus, should not be sending mail directly to receiving servers: typically dynamic consumer broadband and similar end-user ranges. Mail from those IPs is expected to go through the provider's mail servers with authentication.

If you are on the PBL: if the IP really is a mail server on a static address that you control, you can usually request removal through Spamhaus's process. If it is a home or office connection, the correct fix is to send through a proper relay or provider rather than direct-to-MX.

DBL: Domain Block List

The DBL lists domains rather than IPs: domains found in spam, phishing or malware, including domains used in links inside messages. Receivers check the domains in message bodies and headers against it.

If your domain is on the DBL: a listing can affect every message that contains a link to it, regardless of who sends it. Causes include your domain appearing in spam (sometimes sent by others, such as through a compromised form), a compromised website hosting malicious content, or a shared link domain you used. Fix the cause, secure the site, and then use Spamhaus's removal process.

ZEN: the combined zone

ZEN is a single DNS zone that combines the SBL, CSS, XBL and PBL, so receivers can make one query instead of several. When a bounce message says your IP is listed in "zen.spamhaus.org," the return code tells you which underlying list it came from.

Reading return codes

Spamhaus documents the return codes for ZEN. As published at the time of writing, they map roughly as follows:

Return code List
127.0.0.2 SBL
127.0.0.3 CSS
127.0.0.4 to 127.0.0.7 XBL
127.0.0.10 and 127.0.0.11 PBL

Confirm against Spamhaus's current documentation before building automation on these values.

Checking a listing

The most reliable way to check is Spamhaus's own web lookup tool, which shows which lists an IP or domain appears on and links to the reason and removal options.

You can also query DNS directly:

# For IP 192.0.2.25, reverse the octets
dig +short 25.2.0.192.zen.spamhaus.org

Be careful interpreting results. Spamhaus restricts free use of its public mirrors, and queries sent through large public DNS resolvers may be refused or answered with an error code rather than a real result. An unexpected answer outside the documented listing codes usually means the query was blocked, not that you are listed. Query from your own resolver, or use the web tool.

Before requesting removal

Whatever the list, the same rule applies: fix the cause first. Removal requests for IPs or domains that are still doing what got them listed tend to be denied or relisted quickly, and repeated relisting makes future removals harder.

List Typical cause First fix
SBL Spam operation or abusive hosting Stop the activity; engage your provider
CSS Poor sending practices or misconfiguration Authenticate, fix HELO/PTR, clean lists
XBL Compromised machine or service Find and clean the infection
PBL Direct-to-MX mail from an end-user range Use a relay, or request removal for a real static mail server
DBL Domain in spam or compromised site Secure the site and stop the abuse

Key takeaways

  • Spamhaus runs several lists: SBL for spam sources, CSS for low-reputation sending, XBL for compromised machines, PBL for ranges that should not send direct-to-MX, and DBL for domains.
  • ZEN combines the IP lists; the return code tells you which list applies.
  • A PBL listing is a policy statement, not an accusation.
  • Use Spamhaus's lookup tool, and beware misleading results when querying through public resolvers.
  • Always fix the underlying cause before requesting removal.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn