Signal-based Scoring
Every report, detection, or piece of evidence is recorded as a signal with a specific weight. The total score of an IP is the sum of all active (non-decayed) signal weights.
Signal Types & Weights
| Signal Type | Base Weight | Description | Decay Rate |
|---|---|---|---|
| Normal User Report | +8 | Report from an unverified user | Fast (3d half-life) |
| Trusted Reporter | +15 | Report from a verified reporter with API token | Normal (7d) |
| Independent Report | +12 | Additional independent corroborating report | Normal (7d) |
| Heuristic / Pattern | +15 | Suspicious pattern detected by automated analysis | Normal (7d) |
| Honeypot | +25 | Caught by a spam trap / honeypot | Normal (7d) |
| Trusted External Feed | +40 | Data from an established threat intelligence source | Slow (14d) |
| Spamtrap Hit | +60 | Email sent to a known spamtrap address | Slow (14d) |
| Manual Verification | +80 | Admin-confirmed after manual review | Very Slow (30d) |
| Confirmed Malware | +100 | Verified malware distribution | Very Slow (30d) |
| Confirmed Phishing | +100 | Verified phishing activity | Very Slow (30d) |
| Confirmed Botnet | +100 | Verified botnet membership | Very Slow (30d) |
Reporter Reputation
Signal weights are multiplied by the reporter's trust multiplier (0.25x–2.0x). New/unknown reporters start low (~0.75x), while reporters with a proven track record of accurate reports can reach up to 2.0x. False positives reduce the multiplier.
Key Rule
A single normal user report (weight 8 × ~0.75 multiplier ≈ 6 points) can NEVER exceed the watchlist threshold (20). Hard-listing requires either:
- At least 2 independent corroborating signals, OR
- 1 critical confirmed signal (Malware, Phishing, Botnet, Spamtrap, Manual Verification)
Listing States
Four States
| Score | State | DNS Response | Recommended Action |
|---|---|---|---|
| 0–19 | 🟢 Clean | NXDOMAIN | Accept - no issues detected. |
| 20–49 | 🟡 Watchlist | NXDOMAIN | Internal monitoring only. Not publicly listed. No DNS response. |
| 50–89 | 🟠 Soft-Listed | A record (low confidence) | Tag, quarantine, greylist, or increase spam score. Do NOT reject. |
| 90+ | 🔴 Hard-Listed | A record (high confidence) | Reject is appropriate. Multiple corroborating signals or critical evidence. |
Important: Soft-listed IPs return a DNS response, but it signals low confidence. Mail servers should use this for scoring/tagging, not for outright rejection. Only hard-listed IPs have enough evidence to warrant rejection.
DNS Return Codes
Our DNSBL uses differentiated return codes that encode both the threat category and the confidence level:
| Return Code | Category | Description | Recommended Action |
|---|---|---|---|
127.0.0.2 | Spam (low confidence) | Suspected spam, but limited evidence. Soft-listed. | Tag only. Increase spam score, quarantine, greylist. Do NOT reject. |
127.0.0.3 | Spam (high confidence) | Confirmed spam with strong evidence. Hard-listed. | May reject. Multiple independent signals confirm spam activity. |
127.0.0.4 | Malware | IP distributing malware via email. | Reject immediately. |
127.0.0.5 | Phishing | IP involved in phishing campaigns. | Reject immediately. |
127.0.0.6 | Botnet | IP is part of a known botnet. | Reject immediately. |
127.0.0.7 | Exploit/Scanner | IP performing exploit scans or vulnerability probing. | Reject or quarantine. |
127.0.0.8 | Abuse/Policy | IP violating acceptable use policies. | Reject or quarantine. |
127.0.0.9 | Manual Block | Manually blocked by administrator. | Reject. |
NXDOMAIN | Clean / Watchlist | Not listed or under observation only. | Accept. |
TXT Records
Each listed IP also returns a TXT record with detailed information:
"Listed: spam | state: soft-listed | confidence: medium | score: 65"
Critical Enforcement Rule
- 127.0.0.4 (malware), 127.0.0.5 (phishing), 127.0.0.6 (botnet): May reject immediately.
- 127.0.0.3 (spam high confidence): May reject.
- 127.0.0.2 (spam low confidence): Do NOT reject directly! Use for tagging, quarantine, greylisting, or increasing the spam score.
Score Decay & Auto-Delisting
Time-based Decay
Every signal loses weight over time using exponential decay with a configurable half-life:
| Decay Rate | Half-Life | Used For |
|---|---|---|
| Fast | 3 days | Normal user reports |
| Normal | 7 days | Trusted reports, heuristics, honeypots |
| Slow | 14 days | External feeds, spamtrap hits |
| Very Slow | 30 days | Manual verification, confirmed malware/phishing/botnet |
Example: A user report with weight 8 will have only ~4 weight after 3 days, ~2 after 6 days, and become negligible after ~15 days.
Automatic Delisting
If no new signals are received, the IP is automatically delisted after:
- Spam / Open Relay: 14 days
- Exploit / Abuse: 21 days
- Phishing: 30 days
- Malware / Botnet: 60 days
The auto-delist date is shown in the lookup results.
Related articles
What is the Provider.tools DNSBL?
Understanding our DNS-based Blacklist with its multi-level reputation and scoring model - what it is, how it works, and why it differs from traditional blacklists.
ReadMail Server Integration
Step-by-step guides for Postfix, Exim, Rspamd, and SpamAssassin - including recommended conservative, balanced, and aggressive configurations.
Read