IP Reputation & Blacklist Checker

Enter an IPv4 address to see whether it appears on the blacklists that mail servers, forums and login systems actually consult — plus whether it is a published Tor exit node, a datacentre address or a known proxy. Every check below is a live query run at the moment you press the button.

Queries 10 DNS blacklists plus the Tor Project’s published exit-node list. IPv4 only — blacklists are indexed by IPv4 address, and private ranges like 192.168.1.1 have no public reputation at all.

—
    0Listings
    Need addresses that are not already burnt?

    Shared VPN exits and recycled datacentre ranges carry whoever used them last. If you need addresses under your own control for scraping, ad verification or managing multiple accounts, a dedicated proxy is the usual answer — and a VPN is the usual answer if you simply want your home address out of the logs.

    Proxy-Seller PureVPN

    These are affiliate links. They cost you nothing and we do not rank anyone by commission — see how to compare providers yourself.

    What this tool actually checks

    An IP address has a reputation in the same way a phone number does: nobody owns the record, but a lot of independent services keep notes, and those notes decide whether your mail arrives and whether a site lets you through. This page queries three different kinds of source, and it is worth knowing which is which, because they mean very different things.

    DNS blacklists (DNSBLs). Ten of them, queried live from our server. These are the lists mail servers consult in the fraction of a second before accepting a message: Spamhaus ZEN, SpamCop, Barracuda, UCEPROTECT, DroneBL, blocklist.de, PSBL, GBUdb, SPFBL and Mailspike. A listing means that operator saw abuse from the address, or considers the whole range unsuitable for sending mail directly.

    The Tor exit list. Checked against the list the Tor Project itself publishes, not guessed from the provider name. If an address is a current exit node, a large share of sites will treat traffic from it as anonymous and challenge or block it.

    Network type. Whether the address belongs to a datacentre, a mobile carrier, or a known VPN or proxy service. This comes from network-level classification rather than reading the company name, which is why a VPN exit rented from an ordinary hosting company is still identified as one.

    Key takeaway: a clean result means nothing bad has been reported — it is not a certificate of good character, and it says nothing about what the address is doing right now. A listing, by contrast, is concrete: somebody recorded abuse and you can usually find out exactly which list and why.

    How to read your result

    Clean on everything

    The ordinary outcome for a home broadband address. Note that Spamhaus PBL deliberately lists most residential ranges — that is not a black mark, it is a statement that mail should leave through your provider’s mail server rather than straight from your router. If you are not running a mail server, a PBL listing has no effect on you whatsoever.

    Listed on one or two lists

    Usually history rather than you — dynamic addresses change hands constantly, and you may have inherited one from someone who ran an open relay or picked up malware. It can also mean a device on your own network is infected and sending mail without you knowing. The lists that flag individual addresses rather than whole ranges — SpamCop, PSBL, blocklist.de — are the ones worth acting on, because they respond to recent activity.

    Listed on several lists

    Something is actively wrong, or the address is part of a range with a bad history. If this is your own connection, check every device for malware before requesting removal; if you request delisting while the abuse continues, you will be relisted within hours and some lists get slower to remove you each time.

    “Unavailable” on a list

    Some blacklists only answer servers they have authorised, and refuse everyone else. Spamhaus is the main one: it will usually show as unavailable here, because it reserves free lookups for registered mail servers rather than public tools. When a list will not answer, this page says so instead of pretending the address is clean — click the link beside it for a definitive answer from the operator’s own lookup form. We also ask each list a question we already know the answer to before trusting a “not listed” result, so a list that has quietly stopped talking to us cannot be mistaken for a clean bill of health.

    🔧 How to get an address delisted

    Delisting is free and self-service on nearly every list, but the order matters:

    1. Fix the cause first. Scan every machine on the network, close any open relay or open proxy, and check whether a web application of yours is being used to send mail. On a business connection, check for a compromised mailbox sending through your server.

    2. Set up reverse DNS. If you run a mail server and the address has no PTR record, a large share of receivers will reject you regardless of blacklists. Your provider sets this, not you.

    3. Request removal on each list separately. There is no central registry. Use the delisting link beside each listing in the table above. Most automated removals take effect within 24–48 hours; some lists expire entries on their own once the abuse stops.

    4. Re-check after a day, not after five minutes. Results are cached at several layers, and hammering the lists is itself a reason to be throttled.

    For the longer walk-through, including what to write in a removal request, see how to get your IP removed from a blacklist.

    Why a perfectly innocent address gets flagged

    Most flags have nothing to do with the person currently using the address.

    You are behind CGNAT. Your provider shares one public address between dozens of customers, so you inherit the reputation of all of them. Nothing you do on your own devices changes it — see what CGNAT is and how to tell if you are behind it.

    You are on a shared VPN exit. Commercial VPNs put hundreds of users on one address, so it accumulates reports quickly and is frequently blocked by streaming services and shops. That is a property of sharing, not of the provider being untrustworthy.

    The address is in a datacentre range. Fraud systems treat datacentre traffic as unusual for a human visitor, which is why a VPS you use as a jump host sees more CAPTCHAs than your laptop at home. See residential versus datacentre addresses.

    Your address changed hands. Dynamic assignment means yesterday’s spammer can be today’s you. This is the single most common explanation for a listing on an address that has never sent a single message.

    What IP reputation cannot tell you

    It cannot tell you who a person is. A listing is attached to a number, and the number is shared, reassigned and proxied — which is exactly why treating it as identity goes wrong so often. It also cannot tell you that an address is safe: a freshly rented server has no reputation at all, good or bad, and that blankness is the normal state for anything new. And it cannot tell you what will happen at any particular site, because large platforms keep private reputation data that no public list can see.

    A clean result on this page and a block at a specific website are perfectly compatible. If you are being blocked, the useful question is usually not “is my address blacklisted?” but “what else is this site seeing?” — which is where the VPN leak test and what-is-my-IP check are more use than a blacklist lookup.

    Frequently asked questions

    Does being on a blacklist stop me browsing the web?

    Almost never. DNSBLs were built for email, and that is where a listing bites: messages bounce or land in spam. Browsing is affected by different systems — bot detection, fraud scoring and site-specific bans — which is why you can be listed everywhere and still browse normally, or be clean everywhere and still hit CAPTCHAs.

    My address is on Spamhaus PBL. Is that bad?

    Not if you are a normal user. PBL is a list of addresses that should not be sending mail directly, and virtually all home connections are on it by design. It only matters if you are trying to run a mail server on a residential line, which you should not do anyway.

    Can I just change my IP to escape a listing?

    Sometimes, and it is often the pragmatic fix for a home connection: rebooting the router for long enough can get you a fresh address from your provider’s pool. It does nothing if you are behind CGNAT or if the problem is a malware infection that will get the new address listed too. See how to change your IP address.

    Why does a VPN make my reputation worse?

    Because you are sharing the address with everyone else on that server, and because many services classify anonymising traffic as risky by default. It is a deliberate trade: you gain privacy from the sites you visit and lose the clean record of your own line. A provider with more addresses and fewer users per address is the thing to look for.

    How often do these lists update?

    Continuously. Some entries appear within minutes of a spam run and expire automatically after a few days; others persist until you ask for removal. A result from last week tells you very little, which is why this page runs the queries fresh each time rather than serving a cached score.

    Is checking someone else’s IP address legal?

    Querying a public blacklist is a normal DNS lookup — the same thing every mail server in the world does thousands of times a minute. What you do with the answer is a different matter, and an address is not a person: see what someone can actually do with your IP address.

    Related reading

    Other tools

    Scroll to Top