Overview
A DNSBL (DNS-based Blacklist, also known as RBL - Realtime Blackhole List) is a service that publishes a list of IP addresses known to be associated with spam, malware, phishing, or other malicious activity. Mail servers can query this list in real-time during the SMTP transaction to decide whether to accept or reject an incoming connection.
How It Works
The basic principle: your mail server performs a DNS lookup against the DNSBL zone. The response tells it whether the sending IP is listed:
- A record returned (e.g., 127.0.0.2): The IP is listed - the specific return code indicates the category and confidence level.
- NXDOMAIN (no record): The IP is clean - not listed.
What Makes Our DNSBL Different
Unlike traditional blacklists that operate on a simple "one report = global block" principle, the Provider.tools DNSBL uses a multi-level reputation and scoring model:
- Evidence-based: A single report is a signal, not a verdict. Only the accumulation of multiple independent signals or critical evidence (malware, phishing, botnet, spamtrap) can lead to a hard block.
- Graduated response: IPs transition through four states - Clean → Watchlist → Soft-Listed → Hard-Listed - based on their accumulated score.
- Differentiated return codes: Spam with low confidence (127.0.0.2) is clearly separated from spam with high confidence (127.0.0.3), allowing mail servers to react appropriately.
- Automatic decay: Scores decrease over time. If no new malicious activity is detected, an IP automatically returns to clean status.
- Reporter reputation: Reports from trusted, verified sources carry more weight than reports from new or unverified reporters.
Core Principle
"A single report is a hint, not a verdict."
The DNSBL collects solid evidence and responds in graduated steps, instead of globally blocking on a single report.
Data Sources
- Trusted Reporter Program: Verified hosting providers and email administrators report via API token.
- Honeypot Network: Purpose-built spam traps that capture malicious senders.
- Community Reports: User-submitted reports that contribute to the score.
- Trusted External Feeds: Data from established threat intelligence sources.
- Manual Verification: Admin-confirmed entries for critical threats.
Related articles
Scoring Model, States & Return Codes
Detailed explanation of the multi-level scoring model, listing states, signal weights, score decay, and the DNS return codes.
ReadQuerying the DNSBL
How to query the DNSBL via DNS - including IPv4, IPv6 nibble format, and the HTTP API.
ReadMail Server Integration
Step-by-step guides for Postfix, Exim, Rspamd, and SpamAssassin - including recommended conservative, balanced, and aggressive configurations.
Read