[{"data":1,"prerenderedAt":312},["ShallowReactive",2],{"search-en":3,"content-en-developer\u002Fdnsbl-delisting":4,"surround-en-\u002Fdeveloper\u002Fdnsbl-delisting":303},[],{"id":5,"title":6,"body":7,"description":295,"extension":296,"meta":297,"navigation":298,"path":299,"seo":300,"stem":301,"__hash__":302},"content_en\u002F3.developer\u002F38.dnsbl-delisting.md","DNS blocklist recovery",{"type":8,"value":9,"toc":282},"minimark",[10,14,18,21,26,62,83,87,104,108,119,132,136,139,156,169,173,176,226,232,242,252,257,263,267],[11,12,6],"h1",{"id":13},"dns-blocklist-recovery",[15,16,17],"p",{},"Fix the cause before requesting removal. A successful form submission without\nremediation is temporary at best and can make later requests harder. Start by\npausing the affected traffic, preserving logs, checking for compromised\naccounts or applications, reviewing recent recipients and complaints, and\nconfirming PTR, EHLO, forward DNS, SPF, DKIM, and DMARC.",[15,19,20],{},"Owlat quarantines an outbound IP only for a confirmed Spamhaus listing.\nBarracuda, SpamCop, and optional Abusix checks are warning signals: investigate\nthem, but they do not automatically starve the pool. A resolver error is never\ntreated as a listing or a delisting.",[22,23,25],"h2",{"id":24},"spamhaus","Spamhaus",[27,28,29,41,53,56,59],"ol",{},[30,31,32,33,40],"li",{},"Open the ",[34,35,39],"a",{"href":36,"rel":37},"https:\u002F\u002Fcheck.spamhaus.org\u002F",[38],"nofollow","Spamhaus IP and Domain Reputation Checker","\nfrom a network associated with the IP. Do not use a VPN for a removal request.",[30,42,43,44,48,49,52],{},"Identify the returned list\u002Fcode. CSS is ",[45,46,47],"code",{},"127.0.0.3"," through the SBL\u002FZen zone;\n",[45,50,51],{},"127.255.255.x"," answers are resolver\u002Fconfiguration errors, not listings.",[30,54,55],{},"For CSS, verify a meaningful PTR exists, PTR resolves forward to the same IP,\nthe SMTP EHLO matches that host, the machine is not compromised, wildcard DNS\ndoes not expose unexpected hosts, and list acquisition\u002Fconsent is sound.",[30,57,58],{},"Remove malicious queued mail, close the compromise, and correct list hygiene.",[30,60,61],{},"In the checker, explain what caused the traffic, what you fixed, when you\nfixed it, and what prevents recurrence. Removal is not guaranteed. CSS often\nexpires after the last detection, but waiting without fixing the cause is not\nremediation.",[15,63,64,65,70,71,76,77,82],{},"Sources: ",[34,66,69],{"href":67,"rel":68},"https:\u002F\u002Fwww.spamhaus.org\u002Ffaqs\u002Fcombined-spam-sources-css\u002F",[38],"Spamhaus CSS FAQ",",\n",[34,72,75],{"href":73,"rel":74},"https:\u002F\u002Fwww.spamhaus.org\u002Ffaqs\u002Fdnsbl-usage\u002F",[38],"DNSBL response codes",", and\n",[34,78,81],{"href":79,"rel":80},"https:\u002F\u002Fwww.spamhaus.org\u002Ffaqs\u002Fgeneral-questions\u002F",[38],"removal-request guidance",".",[22,84,86],{"id":85},"barracuda","Barracuda",[27,88,89,92,95],{},[30,90,91],{},"Confirm the IP in Barracuda Central and investigate the sending cause.",[30,93,94],{},"Correct the compromise, authentication, or recipient-quality issue first.",[30,96,97,98,103],{},"Submit one complete ",[34,99,102],{"href":100,"rel":101},"https:\u002F\u002Fwww.barracudacentral.org\u002Frbl\u002Fremoval-request",[38],"Barracuda Reputation System removal request","\nwith a valid contact and explanation. Multiple requests are ignored;\nBarracuda says complete requests are typically investigated within 12 hours.",[22,105,107],{"id":106},"spamcop","SpamCop",[27,109,110,113,116],{},[30,111,112],{},"Follow the evidence links in any SpamCop report and stop the reported mail.",[30,114,115],{},"Check for an open relay, compromised credential, infected host, or bad list\nsource; remove queued abuse.",[30,117,118],{},"The SpamCop Blocking List is time-based and delists automatically after\nreports stop. Do not hunt for a manual fast-track that does not exist.",[15,120,64,121,126,127,82],{},[34,122,125],{"href":123,"rel":124},"https:\u002F\u002Fwww.spamcop.net\u002Fbl.shtml",[38],"SpamCop Blocking List"," and\n",[34,128,131],{"href":129,"rel":130},"https:\u002F\u002Fwww.spamcop.net\u002Ffom-serve\u002Fcache\u002F76.html",[38],"SpamCop removal FAQ",[22,133,135],{"id":134},"abusix","Abusix",[15,137,138],{},"Abusix is optional because its production DNS namespace requires a 32-character API key.\nWhen enabled, Owlat queries it as warning-only.",[27,140,141,150,153],{},[30,142,143,144,149],{},"Open ",[34,145,148],{"href":146,"rel":147},"https:\u002F\u002Flookup.abusix.com\u002F",[38],"Abusix Lookup and Delisting"," and inspect the\nspecific list\u002Freason.",[30,151,152],{},"Fix the indicated abuse or policy\u002FrDNS problem.",[30,154,155],{},"Sign in to request delisting. Abusix says removals are processed immediately,\nwith DNS propagation normally completing within minutes; a recurring cause\nwill be observed and listed again.",[15,157,64,158,163,164,82],{},[34,159,162],{"href":160,"rel":161},"https:\u002F\u002Fdocs.abusix.com\u002Fdocs\u002Fguardian-mail\u002Fproduction-zones",[38],"Abusix production zones","\nand ",[34,165,168],{"href":166,"rel":167},"https:\u002F\u002Fdocs.abusix.com\u002Fdocs\u002Fguardian-mail\u002Fdelisting-overview",[38],"delisting overview",[22,170,172],{"id":171},"pre-flight-ip-audit","Pre-flight IP audit",[15,174,175],{},"Before an operator invests hours in DNS, the MTA audits every configured\nsending address — at install and daily thereafter — and reduces the result to\none of three plainly-worded verdicts:",[177,178,179,192],"table",{},[180,181,182],"thead",{},[183,184,185,189],"tr",{},[186,187,188],"th",{},"Verdict",[186,190,191],{},"Meaning",[193,194,195,206,216],"tbody",{},[183,196,197,203],{},[198,199,200],"td",{},[45,201,202],{},"clean",[198,204,205],{},"Nothing is blocking setup; continue with SPF, DKIM, and DMARC.",[183,207,208,213],{},[198,209,210],{},[45,211,212],{},"action_required",[198,214,215],{},"The address can work once the listed items are fixed.",[183,217,218,223],{},[198,219,220],{},[45,221,222],{},"unusable",[198,224,225],{},"This address will not work; ask the provider for another one.",[15,227,228,229,231],{},"The audit covers four things: outbound TCP\u002F25 egress (probed against several\nindependent MX hosts, because most providers block it by dropping packets\nrather than refusing them), the blocklists — Spamhaus ZEN decoded into\nSBL\u002FCSS\u002FXBL\u002FPBL\u002FDROP, Barracuda, SpamCop, SORBS, and the credential-gated\nInvaluement and Abusix feeds — forward-confirmed reverse DNS, and a sample of\nthe surrounding \u002F24. A neighbourhood where most sampled addresses are listed is\ntreated as ",[45,230,222],{},": IP-heavy filters score the range, not just the address.",[15,233,234,235,238,239,241],{},"Two rules keep it honest. A resolver that does not answer produces ",[45,236,237],{},"unknown",",\nnever ",[45,240,202],{},"; the verdict then asks for a re-run and the report is marked\nlow-confidence. And a feed whose credential is absent is simply skipped — it\nneither lowers the verdict nor raises a warning.",[15,243,244,247,248,251],{},[45,245,246],{},"GET \u002Fip-audit"," returns the stored audits with a delisting assistant attached to\nevery listing found: the zone-specific removal URL, the likely cause derived\nfrom recent sending metrics, and a pre-filled removal request. ",[45,249,250],{},"POST \u002Fip-audit\u002Frun"," requests a fresh sweep, serving a sweep from the last few\nminutes rather than re-probing (each run opens TCP\u002F25 connections from the\nsending IP). The audit is advisory throughout: it never\nquarantines an address and never blocks a send. Only the shipped DNSBL sweep\ndoes that, and only for a confirmed Spamhaus listing.",[253,254,256],"h3",{"id":255},"before-you-pick-a-vps","Before you pick a VPS",[15,258,259,262],{},[45,260,261],{},"GET \u002Fip-audit\u002Fprovider-note\u002F:provider"," returns a short factual note per\nprovider: whether outbound port 25 is open, needs a request after some account\ntenure, or is blocked outright, and whether that provider's ranges commonly\narrive already listed.",[253,264,266],{"id":265},"in-the-installer","In the installer",[15,268,269,272,273,275,276,278,279,281],{},[45,270,271],{},"owlat-setup doctor"," reads ",[45,274,246],{}," and prints one SEND PATH line per\nsending address: the verdict headline, its next action, and the removal URL for\neach listing found. An ",[45,277,222],{}," address fails doctor, so the installer cannot\nproceed silently on an address that will never deliver; ",[45,280,212],{},"\nprints the delisting path and passes. If the MTA has not audited anything yet,\nor the endpoint is unreachable, doctor prints nothing — the audit is advisory\nand its absence is a supported configuration.",{"title":283,"searchDepth":284,"depth":284,"links":285},"",2,[286,287,288,289,290],{"id":24,"depth":284,"text":25},{"id":85,"depth":284,"text":86},{"id":106,"depth":284,"text":107},{"id":134,"depth":284,"text":135},{"id":171,"depth":284,"text":172,"children":291},[292,294],{"id":255,"depth":293,"text":256},3,{"id":265,"depth":293,"text":266},"List-specific investigation and delisting runbooks for outbound IPs.","md",{},true,"\u002Fdeveloper\u002Fdnsbl-delisting",{"title":6,"description":295},"3.developer\u002F38.dnsbl-delisting","avU6B-hTIIX8rbDabgdqnD4tabIw45muYP4YcmbaaZY",[304,308],{"title":305,"path":306,"stem":307,"children":-1},"External reputation feedback","\u002Fdeveloper\u002Fexternal-reputation-feedback","3.developer\u002F37.external-reputation-feedback",{"title":309,"path":310,"stem":311,"children":-1},"Convex Backend","\u002Fdeveloper\u002Fconvex","3.developer\u002F4.convex",1786915100440]