Visitor IP: 216.73.216.105 NOT LISTED
IPv6-aware policy.txt / policy.json

ScotNet DNSBL

Evidence-based listings • transparent return codes • dual-proof delisting for high-risk listings • dual-stack by default

What this DNSBL is

This DNSBL exists to protect mail systems from active abuse, not to punish mistakes. Listings are evidence-based, persistent until delisted or manually reviewed, and reversible with proof of control. If you’re listed, the fastest path out is to fix the issue and complete the signed delist flow below.

Attacking countries

Top hostile traffic origins over the rolling 7-day country-abuse window.

live updated 1m ago
#2
SwedenSE
2,003 hostile events
22 distinct IPs
#1
United StatesUS
3,425 hostile events
758 distinct IPs
#3
PolandPL
1,872 hostile events
19 distinct IPs

Country reflects observed network origin, not the nationality or identity of an attacker. Rankings use aggregated hostile-event telemetry only; raw attacker records are not exposed here.

Transparency snapshot

Active listings
1,584
Live from BIND zone (exact addresses + escalated ranges)
Threat activity (7 days)
64
Unique suspicious public IPs • 8,169 matched events • 24,337 requests evaluated • auto-list active
Repeat offenders
427
Threatmail: 143 • Apache security: 283 • Other: 1
Lifecycle
Active
Pending review: 0 • Expiring ≤7d: 243
Delisted (7 days)
0
Unique IPs with a recorded delist in the last 7 days
Mail feeds
Active
Threatmail: active, 1 new
User reports: active • last 19:15:09 BST
Zone updated
2026-08-09 19:17 BST
Zone updated 19:17:03 BST

Threat activity is based on classified Apache security telemetry. Ordinary successful visitors and private/internal addresses are excluded; only high-confidence attack patterns can enter the DNSBL.
Source: BIND zone file (authoritative) • last updated 2026-08-09 19:17:03 BST • Exact IPv4: 1,540 • exact IPv6: 9 • escalated IPv4 /24: 35 • escalated IPv6 /64: 0 • A responses: 1,584 • SOA serial 2026100890 • counted from BIND zone file

Visitor

Automatic check for the IP you’re connecting from.

Not listed

Lookup

Check any IPv4 or IPv6 address against this DNSBL.

Progressive query protection: 2 lookups, then a 5-minute pause; after that, 5 more lookups before a 10-minute pause. Continued or excessive requests are paused for 1 hour. Transparency and policy pages remain available; JSON APIs have separate request budgets.

Public test records

Permanent

These loopback test names verify DNSBL integration without querying a real listed address. They are excluded from active-listing totals and history.

2.0.0.127.bl.scott.ovh127.0.0.2User-reported spam
3.0.0.127.bl.scott.ovh127.0.0.3Open relay/proxy
4.0.0.127.bl.scott.ovh127.0.0.4Web/application attack
8.0.0.127.bl.scott.ovh127.0.0.8Repeat offender
dig +short 4.0.0.127.bl.scott.ovh A dig +short 4.0.0.127.bl.scott.ovh TXT

Policy

We block

  • Trusted user-reported spam and direct spam emission
  • Open relays / open proxies
  • Malware / botnet-driven SMTP activity
  • Persistent abusive behaviour and policy violations
  • High-confidence web/application exploit probes and repeated hostile scanning

We don’t block

  • Single transient misconfigurations (unless persistent)
  • Greylisting delays
  • Content-based heuristics (this is an IP reputation list)
  • One-off mistakes without repeat activity

Dual-stack behaviour

Exact-address listing is the default: IPv4 /32 and IPv6 /128. Apache-security and Threatmail are evaluated independently and their counts are never combined. Apache uses IPv4 /24 after 6 distinct addresses in 7 days and IPv6 /64 after 3 in 7 days; Threatmail uses the same thresholds over 14 days. Repeated traffic from one address does not satisfy the distinct-address threshold. Escalated ranges use 127.0.0.8 and expire after 30 quiet days.

Return codes

The same A-record return codes are used for IPv4 and IPv6 DNSBL queries. IPv6 addresses differ only in the query owner: the full address is expanded and reversed nibble by nibble.

CodeMeaning
127.0.0.2User-reported spam or direct spam emission
127.0.0.3Open relay or proxy
127.0.0.4Web/application attack or malware behaviour
127.0.0.8Repeat offender
127.0.0.10Legacy repeat/policy code (deprecated; use 127.0.0.8)

Machine-readable policy: policy.txtpolicy.json

Delist

Signed delisting

Delisting requires DNS proof of domain control. Higher-risk listings also require a web challenge file served from the listed IP, so a random third party cannot simply point a throwaway domain at someone else’s address.

Nothing to delist right now. Delisting appears when an IP is listed (visitor or manual lookup).