DNSBL - DNS-basierte Blacklist3 min read3 sections

Querying the DNSBL

How to query the DNSBL via DNS - including IPv4, IPv6 nibble format, and the HTTP API.

01

IPv4 Queries

To check an IPv4 address, reverse the octets and append .dnsbl.provider.tools:

Format

{reversed-octets}.dnsbl.provider.tools

Example: Check 1.2.3.4

# Reverse the octets: 1.2.3.4 → 4.3.2.1
dig 4.3.2.1.dnsbl.provider.tools A

# If soft-listed (spam, low confidence):
# 4.3.2.1.dnsbl.provider.tools. 300 IN A  127.0.0.2
# 4.3.2.1.dnsbl.provider.tools. 300 IN TXT "Listed: spam | state: soft-listed | confidence: medium | score: 65"

# If hard-listed (spam, high confidence):
# 4.3.2.1.dnsbl.provider.tools. 300 IN A  127.0.0.3

# If clean or watchlist: NXDOMAIN
02

IPv6 Queries (Nibble Format)

IPv6 addresses use the nibble format as defined in RFC 5782. Each hex character is reversed and dot-separated:

# 2001:db8::1 expanded = 2001:0db8:0000:0000:0000:0000:0000:0001
# Reversed nibbles:
dig 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.dnsbl.provider.tools A
03

HTTP API

Single IP Check

GET https://provider.tools/api/dnsbl/check?ip=1.2.3.4

Response:
{
  "success": true,
  "ip": "1.2.3.4",
  "listed": true,
  "listingState": "soft-listed",
  "score": 65,
  "category": "spam",
  "confidenceLevel": "medium",
  "confidence": 65,
  "signalCount": 3,
  "firstSeen": "2024-01-15T...",
  "lastSeen": "2024-02-20T...",
  "autoDelistAt": "2024-03-05T...",
  "dnsResponse": "127.0.0.2"
}

Detailed Status (with signal history)

GET https://provider.tools/api/dnsbl/check?ip=1.2.3.4&detail=true

# Returns full signal list with weights, decay, timestamps

Batch Check (up to 100 IPs)

POST https://provider.tools/api/dnsbl/check
Content-Type: application/json

{ "ips": ["1.2.3.4", "5.6.7.8", "2001:db8::1"] }