Spamhaus PBL Listing: What It Means and Who Can Remove It

Spamhaus PBL Listing: What It Means and Who Can Remove It

Author
Max Olkhovskyi
Published
Jul 21, 2023
Reading duration
7 min

A Spamhaus PBL listing is a policy label, not a spam verdict: it marks IP addresses, often ISP-assigned end-user ranges, that should not deliver email directly to other networks' mail servers. If a mail app or device is being blocked, send through your provider's mail server with SMTP authentication; the listing can stay. Request removal only for a static IP that runs a properly configured outbound mail server.

Use the steps below to identify the list and IP involved, choose the fix, and check the result. They follow Spamhaus's documentation as checked on September 29, 2026.

What the Spamhaus PBL is, and what it is not

Spamhaus describes the Policy Blocklist (PBL) as end-user IP ranges that should not send unauthenticated SMTP email directly to any Internet mail server. Mail from those addresses is expected to be submitted, with authentication, to a server that delivers it: the ISP's own or an external mail service.

Although it is often called a blacklist, the PBL is a policy list. It can include static and dynamic IPs. Networks maintain many ranges themselves; Spamhaus maintains others under its own policy until the network owner sets one. Spamhaus says IPs in the PBL are not necessarily “bad” and that a listing is not the result of anything the end user did.

The PBL, on its own or within Spamhaus's combined ZEN list, is meant to be checked only against the IP address that connects to a receiving mail server. A mail server that delivers directly from a listed IP may be rejected. A message submitted to your provider's server is delivered through that server's connection instead.

Step 1: Confirm the list and the IP address

Save the full rejection message and note the IP address that was refused. Spamhaus says this is generally your outbound mail server and is usually shown in the bounce. If a mail app is being refused for not authenticating, it can instead be the address your own computer or device is connecting from. Look that IP up in Spamhaus's IP and Domain Reputation Checker, which Spamhaus says is the only place PBL removals are handled. Use it manually for your own IPs and domains; Spamhaus asks users not to automate it.

Make sure the result names the PBL. A ZEN listing corresponds to one or more of its component lists: SBL, CSS, XBL or PBL. The other three point to different problems, so follow the checker's instructions for them; our Spamhaus SBL guide covers SBL listings. If the rejection does not mention Spamhaus, start from the response itself, for example with our 550 5.7.1 guide.

Step 2: Decide whether the listing should stay

Your situationWhat to doShould the listing stay?
A mail app such as Outlook, Apple Mail or Thunderbird is refused by your provider's server with a Spamhaus messageTurn on SMTP authentication and fix the outgoing-server settingsYes; Spamhaus says working authentication corrects the refusal
A computer, script or device on end-user IP space sends straight to recipients' mail serversSend through your ISP's or an email provider's outgoing server (a smarthost), with authenticationYes
You run a mail server on a dynamic IPRelay through your ISP's outgoing server or a commercial smarthost; Spamhaus says a mail server needs a static IP with forward and reverse DNSYes
You run an outbound mail server on a static IP assigned to you, with forward (A) and reverse (PTR) DNS, and only that server uses outbound port 25Request a single-IP exclusion in Spamhaus's checker, if the network's PBL policy allows itRemoval can be appropriate
Several IPs or a whole range are listedAsk the network that is assigned the IPs; ISPs manage their ranges through PBL accountsThe network owner decides

If the IP belongs to your email service provider or hosting company, ask that provider to review it: Spamhaus's criteria require the IP to be assigned to whoever requests the removal.

Step 3: Fix blocked mail with authenticated submission

For people sending through a provider, Spamhaus says a PBL listing does not prevent sending unless the email program is not authenticating correctly with the ISP's or company's mail server. Possible causes include changed settings or email software, or SMTP authentication that was never turned on or was switched off. Check the points in Spamhaus's SMTP authentication checklist:

  • The outgoing server name, username and password match your provider's instructions.
  • SMTP authentication is enabled in the app and working on the server; your provider can confirm the server side.
  • The port is right. Spamhaus says authenticated submission should use port 587 or 465, not 25, and providers document which ports they support. For Microsoft 365, see our Office 365 SMTP settings guide.

Enabling SMTP authentication does not remove anything from the PBL, and an end-user connection's listing does not need to change. Only Spamhaus, a network's PBL account or a single-IP exclusion changes a listing. What changes is the delivery path: your provider's server now makes the connection to recipients' mail servers.

Step 4: Request removal only when the IP qualifies

Spamhaus lets mail server administrators exclude a single static IP, and says an IP should be removed only if all of these are true:

  • The IP is static, not dynamic.
  • It runs an outbound mail server.
  • It has appropriate forward DNS (an A record) and reverse DNS (PTR).
  • It is assigned to the person or company making the request.
  • Outbound port 25 is closed to every device on that IP except the mail server.

Look up the IP in the checker, open the listing details and follow the removal steps shown there. Use an email address on a domain that matches the mail server: Spamhaus automatically invalidates removals made with free email accounts such as Gmail, Hotmail or Yahoo. Spamhaus asks administrators to allow approximately 15 minutes for DNS propagation after an exclusion.

Know the limits before you apply:

  • End-user exclusions expire after one year, or sooner under an ISP's PBL policy, and are reversed immediately if spam is detected from the IP.
  • The network owner's PBL policy can allow or disallow removals for its ranges.
  • The ISP that is assigned multiple IPs should request their removal. Spamhaus warns that individuals who remove many IPs may lose removal access and have their removals reversed.
  • An exclusion affects only the PBL. It does not resolve an SBL, CSS or XBL listing, another network's own filtering, or a separate authentication problem.

How to read a PBL check done through DNS

Mail servers check Spamhaus through DNS, not the website. For an IPv4 address, reverse its four numbers and query the result under zen.spamhaus.org; for the documentation example address 203.0.113.25, the query is 25.113.0.203.zen.spamhaus.org. Spamhaus's return-code table explains the answers:

AnswerMeaning
127.0.0.10Listed in the PBL; range maintained by the ISP
127.0.0.11Listed in the PBL; range maintained by Spamhaus
127.0.0.2, 127.0.0.3, 127.0.0.4 or 127.0.0.9Other Spamhaus IP data (SBL, CSS, XBL or DROP), not the PBL
NXDOMAINNot listed, provided your resolver and network can query Spamhaus correctly
127.255.255.252, 127.255.255.254 or 127.255.255.255Errors, not listings: a typing error in the zone name, a query through a public or open resolver, or too many queries

Test the resolver before you trust a “not listed” answer

Spamhaus publishes a simple resolver test. Because 127.0.0.2 is known to be listed, a query for 2.0.0.127.zen.spamhaus.org should return 127.0.0.2, 127.0.0.4 and 127.0.0.10; the not-listed 127.0.0.1 should return NXDOMAIN. We ran the listed query with dig on September 29, 2026, twice, and got the same answers each time:

Resolver usedAnswer for 2.0.0.127.zen.spamhaus.orgWhat it means
The resolver configured on our test machine127.0.0.10, 127.0.0.2 and 127.0.0.4Working lookups
Google Public DNS (8.8.8.8)NXDOMAINLooks like “not listed”, although the test address is listed
Cloudflare (1.1.1.1)127.255.255.254Spamhaus's error code for a query through a public or open resolver
Quad9 (9.9.9.9)127.0.0.4, 127.0.0.2 and 127.0.0.10Expected answers in both runs; answers from public resolvers can vary between queries

Run both checks, the listed and the not-listed address, through the resolver that your mail server or checking tool actually uses, and repeat them a few times: Spamhaus notes that paths to public resolvers vary, so results can differ. Spamhaus's free DNSBL service is for low-volume, non-commercial use from an identifiable network, and queries from large shared hosting environments are not accepted. Spamhaus also warns that public resolvers can be risky for these lookups even when some answer correctly.

Verify the result and choose the next check

After the fix, send a new test from the same app or server and read the response. A changed lookup and successful delivery are separate observations; if messages still fail, read the new rejection before changing anything else.

Folderly tools can help with the next checks, but none of them removes a Spamhaus listing:

  • Folderly Lens inspects public DNS, reverse DNS and blocklist signals for a domain or IP; confirm any Spamhaus result in Spamhaus's own checker.
  • Folderly Flash checks an actual email sent from your setup, so you can review the corrected path's authentication and readiness signals.
  • An Inbox Insights placement test shows where test messages land once delivery works, which is a separate question from any blocklist result.

Frequently asked questions

Does a PBL listing mean my IP sent spam?

No. Spamhaus says IPs in the PBL are not necessarily bad and that a listing is not the result of anything the end user did. The list identifies address space that, by policy, should not send email directly to other networks' mail servers.

Will enabling SMTP authentication remove my IP from the PBL?

No. It fixes a mail app that was refused for not authenticating. The listing stays, which is the intended outcome for an end-user connection.

Can I remove a dynamic IP from the PBL?

Spamhaus's criteria require a static IP that runs an outbound mail server. With a dynamic IP, send through your provider's authenticated mail server or a smarthost instead.

How long does a PBL exclusion last?

Spamhaus says end-user single-IP exclusions expire after one year, or sooner if an ISP with a PBL account sets a shorter period, and are reversed immediately if spam is detected from the IP.

Why does a PBL-listed IP appear in my message headers?

That is normal. Spamhaus notes that legitimate users' PBL-listed IPs appear in the first (lowest) Received header, where their computer hands the message to the provider, and that email should not be blocked for this.

Max Olkhovskyi
Author:
Max Olkhovskyi
Lead of Email Deliverability Specialists
As the adept Team Lead of Email Deliverability Specialists at Folderly, Maksym masters the art of perfecting email deliverability, going beyond mere domain setups. His profound knowledge enables him to provide expert solutions and advice that ensure 100% email deliverability and 70-90% open rate during campaigns. Contact at maksym.olkhovskyi@folderly.com

Also you may like