Scoring blacklist with confidence

Our own DNS blacklist (dnsbl.provider.tools) works on an evidence-based scoring model: every report is a signal, never a verdict. IPs pass through four states – from clean via watchlist to hard-listed – with automatic score decay.

FreeAccount requiredResults in seconds

Guest mode: limited usage. Register for free for unlimited usage, history & statistics.

Register free

DNSBL Documentation

Scoring model, return codes, mail server integration (Postfix, Exim, Rspamd, SpamAssassin)

Open Knowledge Base

How it works

1

1. Query

Query the IP like any DNSBL: 4.3.2.1.dnsbl.provider.tools.

2

2. Read return code

NXDOMAIN = clean; 127.0.0.2–9 = graduated listing codes.

3

3. React

Tag, quarantine or reject – depending on the code and your policy.

Features in detail

4 listing states

Clean → Watchlist → Soft-Listed → Hard-Listed. Graduated response instead of binary block.

Evidence-based

A single report can never cause a block – only multiple independent signals can.

Auto score decay

Scores decay automatically – without new activity, an IP returns to clean.

8 return codes

Differentiated DNS responses for spam, malware, phishing, botnet, exploit and more.

Reporter reputation

Trusted reporters weigh more – false positives less.

Transparent delisting

Score, category, confidence and auto-delist date – all visible.

Frequently asked questions

How do I integrate the DNSBL into Postfix?

Via reject_rbl_client dnsbl.provider.tools=127.0.0.3 – the complete guide with conservative and aggressive examples is in our knowledge base.

When does an IP get listed?

A single report only reaches the watchlist. Two independent reports soft-list the IP; critical categories (malware, botnet) list immediately. Entries decay automatically without new reports.

How do I report spam?

Via the reporting API or the Plesk plugin – both described in the knowledge base.

What does it cost?

Querying and reporting are free and work without an account.

Related guides