DNSBL - DNS-basierte Blacklist5 min read1 sections

What is the Provider.tools DNSBL?

Understanding our DNS-based Blacklist with its multi-level reputation and scoring model - what it is, how it works, and why it differs from traditional blacklists.

01

Overview

A DNSBL (DNS-based Blacklist, also known as RBL - Realtime Blackhole List) is a service that publishes a list of IP addresses known to be associated with spam, malware, phishing, or other malicious activity. Mail servers can query this list in real-time during the SMTP transaction to decide whether to accept or reject an incoming connection.

How It Works

The basic principle: your mail server performs a DNS lookup against the DNSBL zone. The response tells it whether the sending IP is listed:

  • A record returned (e.g., 127.0.0.2): The IP is listed - the specific return code indicates the category and confidence level.
  • NXDOMAIN (no record): The IP is clean - not listed.

What Makes Our DNSBL Different

Unlike traditional blacklists that operate on a simple "one report = global block" principle, the Provider.tools DNSBL uses a multi-level reputation and scoring model:

  • Evidence-based: A single report is a signal, not a verdict. Only the accumulation of multiple independent signals or critical evidence (malware, phishing, botnet, spamtrap) can lead to a hard block.
  • Graduated response: IPs transition through four states - Clean → Watchlist → Soft-Listed → Hard-Listed - based on their accumulated score.
  • Differentiated return codes: Spam with low confidence (127.0.0.2) is clearly separated from spam with high confidence (127.0.0.3), allowing mail servers to react appropriately.
  • Automatic decay: Scores decrease over time. If no new malicious activity is detected, an IP automatically returns to clean status.
  • Reporter reputation: Reports from trusted, verified sources carry more weight than reports from new or unverified reporters.

Core Principle

"A single report is a hint, not a verdict."
The DNSBL collects solid evidence and responds in graduated steps, instead of globally blocking on a single report.

Data Sources

  • Trusted Reporter Program: Verified hosting providers and email administrators report via API token.
  • Honeypot Network: Purpose-built spam traps that capture malicious senders.
  • Community Reports: User-submitted reports that contribute to the score.
  • Trusted External Feeds: Data from established threat intelligence sources.
  • Manual Verification: Admin-confirmed entries for critical threats.