Have you been blocked?
All blocklists are researched and managed by The Spamhaus Project.
Simply click on the link below, which will take you to the Project’s IP and Domain Reputation Checker. From here you will be able to enter your IP or Domain and begin your request for removal.
Please note that the Project’s IP and Domain Reputation Checker is the only place where removals are handled.
IT and security teams consistently face multiple business challenges. Discover how our solutions can help overcome some of those issues.
From processing issues, to email-borne threats our blocklists easily integrate with your current email set-up to improve anti-spam & anti-virus email filtering.
Employ our threat intelligence to increase visibility across security events, reveal potential weaknesses in your network, and threats to your brand.
Stay on top of the latest threats and proactively combat botnet infections, and other forms of abuse, with our solutions.
From clicking on phishing emails to visiting malware dropper sites, our threat intelligence provides automatic protection for your users.
Data for Integration
Enhance your service and create competitive advantage by integrating Spamhaus’ world-class IP and domain reputation data.
Our products provide additional layers of security for networks and email. They also present security teams with additional insight into malicious behavior.
Border Gateway Protocol (BGP) Firewall
Block the worst of the worst at your network edge, taking advantage of your existing BGP-capable routers. Configuration only takes minutes.
Data Query Service (DQS)
Benefit from industry-leading real time blocklists. These DNSBLs easily plug into your existing email infrastructure to block spam and other email threats.
A powerful research tool to investigate relationships between internet infrastructures. Quickly pivot to new areas of concern to rapidly investigate potential threats.
Immediately block connections to dangerous sites, including phishing and malware dropper websites. A ‘set and forget’ solution.
Spamhaus Intelligence API
Threat intelligence data in API format to enable users to easily integrate metadata relating to threats with their own applications, programs, and products.
abuse.ch Real Time Feeds - coming soon
Actionable data signals on cyber threats, with a focus on malware and botnets, to strengthen threat investigations, detections, and help prevent data breaches.
Integration | MDaemon
Block over 99% of email-borne threats with Spamhaus’ real time DNS blocklists and MDaemon® Email Server.
Integration | Halon
Safeguard your email stream using Spamhaus’ real time DNS blocklists and Halon’s secure email infrastructure.
Integration | Messageware
Enhance Microsoft Exchange protection by blocking malicious IP addresses from connecting to your on-premise server in real time.
A wide range of datasets, providing multiple layers of protection. They can be plugged directly into your existing hardware, making them an affordable choice.
Exploits Dataset Statistics
View the geolocation, hosting network, malware names associated with each detection, and other critical data points.
Border Gateway Protocol (BGP) Feeds
Do Not Route Or Peer (DROP) and Botnet Controller List (BCL) datafeeds can peer with your existing BGP-capable router.
Domain (DBL), Zero Reputation (ZRD) and Hash blocklists (HBL) enable you to block content in emails, filtering out a higher rate of email-borne threats.
Data for Investigation
Passive DNS and extended datasets give you additional information on internet resources. They provide deeper insights into incidents and possible threats.
DNS Firewall Threat Feeds
A wide range of feeds to apply to your DNS recursive server. Choose the right level of protection for your organization.
Spam (SBL), Policy (PBL), Exploits (XBL) and Auth (AuthBL) blocklists allow you to filter email from IPs associated with spam, botnets, and other threats.
abuse.ch Threat Intelligence Feeds – coming soon
URLhaus, MalwareBazaar, ThreatFox, YARAify, Feodo Tracker and Sandnet enrich CTI feeds and support vulnerability mangement.
Find out more about us.
Learn more about Spamhaus; who we are, and what we do.
Find a partner
Discover our partners and how they can support you.
Become a partner
Learn about the benefits of being a Spamhaus partner and how to get started.
Discover a wide range of blog posts, case studies and reports.
Spamhaus’ insight into malware, botnet C&Cs, and the domain reputation landscape.
Commonly asked questions about Spamhaus products and processes.
The Blocklist Tester
A tool to help you check if your servers are correctly configured to use Spamhaus DNSBLs.
The Reputation Portal
A tool for ASN owners to get visibility of their IPs’ reputation and proactively manage listings.
Help for the Project's legacy DNSBLs users
Using the Project’s legacy blocklists and suddenly experiencing email issues? This page may be able to help.
In depth information about the technical details and implementation of our products.
Posted by The Spamhaus Team on 8 Nov 2023
With over 90% of cyberattacks initiated by email, every harmful message detected counts for innovative security service provider Censornet. By integrating Spamhaus’ real time blocklists and enabling two-way sharing of basic email connection data, Censornet has enhanced email protection and accuracy for its users… to exceptional levels. Read on to learn more.
Getting to know Censornet
With a mission to protect and serve mid-size enterprises, Censornet safeguards millions of users across the globe, processing over a billion security events per day. Today, over 2,500 organizations worldwide rely on Censornet for autonomous integrated cloud security, to fortify their cyber defences. Using a unique set of technologies and strategic machine learning, Censornet’s security platform stops threats that enter an organisation by email, over the web, or from the cloud.
Enterprise-grade email security for mid-tiers
For Censornet, Email Security (EMS) is a linchpin in their cyber security offering. Integrating multiple traditional and ultra-modern approaches, the Email Security solution ensures enterprise-class threat detection rates with exceptional accuracy. By taking this multi-layered approach, the EMS solution holistically defends against traditional threats such as spam, viruses and large-scale phishing, as well as more sophisticated targeted attacks, impersonation fraud and malware.
Email traffic passes through Censornet’s EMS, where it completes a multi-step email filtering process. First, the email is analysed against threat intelligence data, including Spamhaus’ real-time DNS blocklists (DNSBLs) – accessed via the Data Query Service (DQS). The DNSBLs remove any obvious spam sent from known botnets and spammers, dropping a significant amount of bad email traffic before processing or analysis.
The remaining email traffic passes through anti-virus/anti-spam technology and a set of customer-defined rules before the clean mail is delivered to the customer’s server. Any detected harmful email is immediately quarantined or dropped.
By integrating Spamhaus’ DNSBLs, Censornet prevents over 99% of malicious emails from reaching users’ mailboxes. This instantly recovers bandwidth, servers and storage costs typically lost when accepting and processing spam. Furthermore, Richard Walters, CTO, shared: “Our infrastructure scales significantly better now we are dropping a significant amount of bad email traffic before we take it apart and analyze it.”
Every email counts for exceptional protection
For Censornet, the focus lies not only in providing an overall level of exceptionally high email security protection but also in ensuring accuracy. By blocking over 99.999% of spam emails, at this point, the game is all about tiny margins. Minuscule incremental improvements, where every 100 detected harmful email messages make a difference. Richard, explained, “If we manage to incrementally halt thousands of email messages every month, above and beyond what we were already stopping, it speaks volumes.”
Targeted protection for Censornet users
As a long-standing subscriber to Spamhaus’ DNSBLs, Censornet wanted to do more. They wanted targeted accuracy. At Spamhaus we call this ‘Enhanced Protection’.
By sharing their basic email connection data with Spamhaus, we can detect spammers and threats from patterns in data from Censornet’s users email streams, all without requiring any personally identifiable information (PII). Where malicious or suspicious activity is detected, the IP addresses and domains are added to Spamhaus data sets feeding back directly into Censornet’s EMS solution to block any harmful incoming email.
Keep in mind, not everybody receives the same spam, phishing, or malware emails. Censornet will receive traffic unique to their organization, geography, and industry. They may also detect malicious traffic before others. In both cases, sharing this sort of traffic with Spamhaus improves our data performance for Censornet – and for other users as well.
With Enhanced Protection, Censornet shares basic email connection data and in return accesses additional security against malicious emails specifically targeted at its users, and they are pleased with the results. In Richard’s words:“After 30 days, we received a report showing precisely what incremental value and the incremental protection the data exchange had provided.”
Increasing efficiency at every level
Sharing SMTP connection data with Spamhaus has yielded a multitude of benefits for Censornet. First and foremost, it provides targeted accuracy to their EMS solution, ensuring a higher level of security for users. To bang the drum, every harmful email message counts! Consequently, this allows Censornet to offset infrastructure costs, enabling expansion through adding more users to the existing infrastructure.
The advantages don’t stop there; there are indirect benefits too. Improved customer satisfaction is a natural outcome. Richard proudly shared: “Delivering a service with exceptionally high levels of protection and accuracy, we don’t see customer churn. Our net renewal rate annually is over 115%, which is pretty world class for a provider of SaaS solutions.”
He continued, “Furthermore, the accuracy of the solution has translated to fewer support calls, reducing the burden on the support and customer success teams.”
Setting the standard for email security
Even the athletes of email security seek enhanced performance. With Spamhaus’ industry leading DNSBLs and two-way sharing of basic email connection data, Censornet continues to strive for incremental advances to its security solution. And according to Richard, Censornet achieves this by strategically selecting and aligning with trusted and authoritative partners: “We wouldn’t dream of building a service without Spamhaus – we absolutely trust the tech, we love the data, more specifically the quality.”
United by a shared passion to safeguard users’ mailboxes worldwide, Spamhaus is inspired by Censornet’s commitment to providing exceptionally high email security protection. To learn more about Spamhaus’ Enhanced Protection, please contact us here.
Spamhaus’ Data Query Service (DQS) is an affordable and effective solution to protect your email infrastructure and users.
Using your existing email protection solution, you will be able to block spam and other related threats including malware, ransomware, and phishing emails.
The service has never failed and utilizes the longest established DNSBLs in the industry.
29 September 2023
Extracting the value from spamtraps requires time, expertise, and business assets. Learn about the benefits of sharing your spamtrap data with Spamhaus, and how we can mine these treasure troves of data on your behalf.
1 April 2022
If you've been using Spamhaus Project's free DNSBLs you need to be aware this is a legacy service. With an easy config change you could be getting more value from the Spamhaus data.