An answer is not yet a listing

A DNSBL query works like any DNS query: reverse the IP, append the zone, ask for an A record. NXDOMAIN means the IP is not listed. An address in return is where it gets interesting — because which address comes back is the actual statement.

Treating every answer as a listing produces false alarms at scale. That is exactly what many home-grown checking scripts do. The value almost always falls within 127.0.0.0/8, and the trailing digits encode the category: at Spamhaus, for instance, 127.0.0.2 for SBL, 127.0.0.3 for CSS, 127.0.0.4 through .7 for XBL, and 127.0.0.10/.11 for PBL — dynamic address ranges nobody should be sending from directly anyway.

What AnalyzeMy.Email checks

Every answer is sorted into one of three categories:

  • listed — a genuine listing code for that particular list.
  • clean — the list answered, but the code carries no spam claim. For example, SPFBL uses 127.0.0.4 to say merely "no mail service detectable" — which is how Microsoft's Exchange Online addresses come back, among others. 0spam answers 127.0.0.1 rather than 127.0.0.2 for Apple's mail IPs.
  • error — the query itself was refused. That covers anything outside 127.0.0.0/8 (typical of wildcard or hijacked DNS), the 127.255.255.x range Spamhaus uses to signal rate limiting and open resolvers, and list-specific block codes such as 127.0.0.1 at URIBL and SURBL.

This distinction is why the report prints the raw return code next to every listing: you should be able to see what the verdict rests on.

Why this is more than cosmetics

The "error" case is the dangerous one, because it disguises itself as "clean". A discontinued blacklist does not disappear — its zone keeps answering, usually NXDOMAIN to everything. A checking script then dutifully reports "not listed" although the check stopped happening long ago. Before a list is adopted it therefore has to pass the RFC 5782 self-test: 2.0.0.127.<zone> must answer as listed, 1.0.0.127.<zone> must not. A list that fails is dropped.

The second trap is reputation whitelists that look technically identical to blacklists. A list answering for apple.com, microsoft.com and paypal.com while returning NXDOMAIN for spam domains carries the good domains. Evaluated as a blacklist, it reports every major brand as listed.

How to interpret an answer

  • The list first, then the code. There is no cross-list meaning of 127.0.0.4 — each zone defines its own table, published in its own documentation.
  • Look at the TXT record: almost every DNSBL serves a TXT record alongside the A record with a plain-text reason and a delisting link.
  • Answer outside 127.0.0.0/8? Then the query did not arrive as intended — usually because of a resolver replacing NXDOMAIN with an address of its own.
  • Not all lists carry equal weight. A listing at Spamhaus ZEN has immediate delivery consequences; one on a small regional list often has none.

Test your own configuration

Send any email to hello@analyzemy.email and within seconds you get back a complete report with over 20 checks — including this one.

Analyze your email now

Last updated: · All checks at a glance