An answer is not yet a listing
A DNSBL query works like any DNS query: reverse the IP, append the zone, ask for an A record. NXDOMAIN means the IP is not listed. An address in return is where it gets interesting — because which address comes back is the actual statement.
Treating every answer as a listing produces false alarms at scale. That is exactly what many home-grown checking scripts do. The value almost always falls within 127.0.0.0/8, and the trailing digits encode the category: at Spamhaus, for instance, 127.0.0.2 for SBL, 127.0.0.3 for CSS, 127.0.0.4 through .7 for XBL, and 127.0.0.10/.11 for PBL — dynamic address ranges nobody should be sending from directly anyway.
What AnalyzeMy.Email checks
Every answer is sorted into one of three categories:
- listed — a genuine listing code for that particular list.
- clean — the list answered, but the code carries no spam claim. For example, SPFBL uses
127.0.0.4to say merely "no mail service detectable" — which is how Microsoft's Exchange Online addresses come back, among others. 0spam answers127.0.0.1rather than127.0.0.2for Apple's mail IPs. - error — the query itself was refused. That covers anything outside
127.0.0.0/8(typical of wildcard or hijacked DNS), the127.255.255.xrange Spamhaus uses to signal rate limiting and open resolvers, and list-specific block codes such as127.0.0.1at URIBL and SURBL.
This distinction is why the report prints the raw return code next to every listing: you should be able to see what the verdict rests on.
Why this is more than cosmetics
The "error" case is the dangerous one, because it disguises itself as "clean". A discontinued blacklist does not disappear — its zone keeps answering, usually NXDOMAIN to everything. A checking script then dutifully reports "not listed" although the check stopped happening long ago. Before a list is adopted it therefore has to pass the RFC 5782 self-test: 2.0.0.127.<zone> must answer as listed, 1.0.0.127.<zone> must not. A list that fails is dropped.
The second trap is reputation whitelists that look technically identical to blacklists. A list answering for apple.com, microsoft.com and paypal.com while returning NXDOMAIN for spam domains carries the good domains. Evaluated as a blacklist, it reports every major brand as listed.
How to interpret an answer
- The list first, then the code. There is no cross-list meaning of
127.0.0.4— each zone defines its own table, published in its own documentation. - Look at the TXT record: almost every DNSBL serves a TXT record alongside the A record with a plain-text reason and a delisting link.
- Answer outside
127.0.0.0/8? Then the query did not arrive as intended — usually because of a resolver replacing NXDOMAIN with an address of its own. - Not all lists carry equal weight. A listing at Spamhaus ZEN has immediate delivery consequences; one on a small regional list often has none.