Scoring blacklist with confidence
Our own DNS blacklist (dnsbl.provider.tools) works on an evidence-based scoring model: every report is a signal, never a verdict. IPs pass through four states – from clean via watchlist to hard-listed – with automatic score decay.
Guest mode: limited usage. Register for free for unlimited usage, history & statistics.
Register freeDNSBL Documentation
Scoring model, return codes, mail server integration (Postfix, Exim, Rspamd, SpamAssassin)
How it works
1. Query
Query the IP like any DNSBL: 4.3.2.1.dnsbl.provider.tools.
2. Read return code
NXDOMAIN = clean; 127.0.0.2–9 = graduated listing codes.
3. React
Tag, quarantine or reject – depending on the code and your policy.
Features in detail
4 listing states
Clean → Watchlist → Soft-Listed → Hard-Listed. Graduated response instead of binary block.
Evidence-based
A single report can never cause a block – only multiple independent signals can.
Auto score decay
Scores decay automatically – without new activity, an IP returns to clean.
8 return codes
Differentiated DNS responses for spam, malware, phishing, botnet, exploit and more.
Reporter reputation
Trusted reporters weigh more – false positives less.
Transparent delisting
Score, category, confidence and auto-delist date – all visible.
Frequently asked questions
How do I integrate the DNSBL into Postfix?
Via reject_rbl_client dnsbl.provider.tools=127.0.0.3 – the complete guide with conservative and aggressive examples is in our knowledge base.
When does an IP get listed?
A single report only reaches the watchlist. Two independent reports soft-list the IP; critical categories (malware, botnet) list immediately. Entries decay automatically without new reports.
How do I report spam?
Via the reporting API or the Plesk plugin – both described in the knowledge base.
What does it cost?
Querying and reporting are free and work without an account.