← Back to blog
Blocklists · Spamhaus DBL

Spamhaus DBL: what actually gets a domain listed

The DBL lists domains, not IP addresses, by how Spamhaus observed the domain used in mail traffic. That is a different question from who owns or controls it.
3 min read · Updated August 2026

The Spamhaus Domain Block List, DBL, lists domain names rather than IP addresses. A domain lands on it for how Spamhaus observed it being used in mail traffic, which is a different question from who owns or controls that domain.

Spamhaus splits DBL listings by return code: spam domains, phishing domains, malware domains, and botnet command-and-control domains, plus a separate "abused legit" category for otherwise legitimate hostnames compromised and used for one of those same purposes. A domain used directly to send spam and a domain merely linked to from someone else's spam message can both end up listed, under different codes.

Why your domain can be listed for something you did not send

If a link to your domain appears inside a phishing or spam message someone else sent, whether a compromised site pointing at you or spammers spoofing a link for credibility, Spamhaus can list the domain under its spam or abused-legit codes even though nothing left your own servers. This is the case I check for first when a client is confident they have never sent anything resembling spam and the listing still shows up.

How I check it The return code a DBL lookup reports names which category triggered the listing, before I assume it is your own sending behavior. A spam-domain code with no matching outbound campaign at all points toward the domain being referenced in someone else's mail, not your own.

Getting delisted

Spamhaus does not disclose its exact listing criteria and reviews listings on an ongoing basis, so some clear on their own once the triggering pattern stops. A removal request goes through Spamhaus's own reputation checker, and Spamhaus states there is never a fee for removal, worth knowing given how many paid delisting services promise to speed this up. Spamhaus requires the underlying cause addressed, not just the request filed, most often confirmed opt-in or a CAPTCHA on whichever signup form the listing traces back to.

Where the cause turns out to be list quality rather than a compromised asset, list quality and where those addresses came from covers the same root cause from the reputation side.

Questions I get asked a lot

Does the Spamhaus DBL list IP addresses too?

No. Spamhaus states the DBL only lists domain names. IP-level listings run on Spamhaus's separate SBL, a different list with a different lookup.

Is there a fee to get removed from the DBL?

Spamhaus states there is never a fee for removing any of its listings. A service charging for DBL removal is not acting on Spamhaus's behalf.

Why would a domain I do not recognize be linked to my listing?

The DBL's abused-legit category exists for exactly this: a legitimate domain compromised and used for spam, phishing, or malware without its owner's involvement, listed under a different code than a domain actively used to send.

Listed and not sure the cause is yours?
Run the free diagnostic and I will tell you whether this traces to your own sending, a compromised asset, or something else.
Start the free diagnostic →
Julian Turgelski
The Diagnostic Blog
hello@julianturgelski.com
Julian's diagnostic console