The Spamhaus Domain Block List, DBL, lists domain names rather than IP addresses. A domain lands on it for how Spamhaus observed it being used in mail traffic, which is a different question from who owns or controls that domain.
Spamhaus splits DBL listings by return code: spam domains, phishing domains, malware domains, and botnet command-and-control domains, plus a separate "abused legit" category for otherwise legitimate hostnames compromised and used for one of those same purposes. A domain used directly to send spam and a domain merely linked to from someone else's spam message can both end up listed, under different codes.
If a link to your domain appears inside a phishing or spam message someone else sent, whether a compromised site pointing at you or spammers spoofing a link for credibility, Spamhaus can list the domain under its spam or abused-legit codes even though nothing left your own servers. This is the case I check for first when a client is confident they have never sent anything resembling spam and the listing still shows up.
Spamhaus does not disclose its exact listing criteria and reviews listings on an ongoing basis, so some clear on their own once the triggering pattern stops. A removal request goes through Spamhaus's own reputation checker, and Spamhaus states there is never a fee for removal, worth knowing given how many paid delisting services promise to speed this up. Spamhaus requires the underlying cause addressed, not just the request filed, most often confirmed opt-in or a CAPTCHA on whichever signup form the listing traces back to.
Where the cause turns out to be list quality rather than a compromised asset, list quality and where those addresses came from covers the same root cause from the reputation side.
No. Spamhaus states the DBL only lists domain names. IP-level listings run on Spamhaus's separate SBL, a different list with a different lookup.
Spamhaus states there is never a fee for removing any of its listings. A service charging for DBL removal is not acting on Spamhaus's behalf.
The DBL's abused-legit category exists for exactly this: a legitimate domain compromised and used for spam, phishing, or malware without its owner's involvement, listed under a different code than a domain actively used to send.