What this DNSBL is
This DNSBL exists to protect mail systems from active abuse, not to punish mistakes. Listings are evidence-based, persistent until delisted or manually reviewed, and reversible with proof of control. If you’re listed, the fastest path out is to fix the issue and complete the signed delist flow below.
Attacking countries
Top hostile traffic origins over the rolling 7-day country-abuse window.
Country reflects observed network origin, not the nationality or identity of an attacker. Rankings use aggregated hostile-event telemetry only; raw attacker records are not exposed here.
Transparency snapshot
User reports: active • last 19:15:09 BST
Threat activity is based on classified Apache security telemetry. Ordinary successful visitors and private/internal addresses are excluded; only high-confidence attack patterns can enter the DNSBL.
Source: BIND zone file (authoritative) • last updated 2026-08-09 19:17:03 BST • Exact IPv4: 1,540 • exact IPv6: 9 • escalated IPv4 /24: 35 • escalated IPv6 /64: 0 • A responses: 1,584 • SOA serial 2026100890 • counted from BIND zone file
Visitor
Automatic check for the IP you’re connecting from.
Not listed
Lookup
Check any IPv4 or IPv6 address against this DNSBL.
Progressive query protection: 2 lookups, then a 5-minute pause; after that, 5 more lookups before a 10-minute pause. Continued or excessive requests are paused for 1 hour. Transparency and policy pages remain available; JSON APIs have separate request budgets.
Public test records
PermanentThese loopback test names verify DNSBL integration without querying a real listed address. They are excluded from active-listing totals and history.
2.0.0.127.bl.scott.ovh127.0.0.2User-reported spam3.0.0.127.bl.scott.ovh127.0.0.3Open relay/proxy4.0.0.127.bl.scott.ovh127.0.0.4Web/application attack8.0.0.127.bl.scott.ovh127.0.0.8Repeat offenderPolicy
We block
- Trusted user-reported spam and direct spam emission
- Open relays / open proxies
- Malware / botnet-driven SMTP activity
- Persistent abusive behaviour and policy violations
- High-confidence web/application exploit probes and repeated hostile scanning
We don’t block
- Single transient misconfigurations (unless persistent)
- Greylisting delays
- Content-based heuristics (this is an IP reputation list)
- One-off mistakes without repeat activity
Dual-stack behaviour
Exact-address listing is the default: IPv4 /32 and IPv6 /128.
Apache-security and Threatmail are evaluated independently and their counts are never combined. Apache uses IPv4 /24 after 6 distinct addresses in 7 days and IPv6 /64 after 3 in 7 days; Threatmail uses the same thresholds over 14 days.
Repeated traffic from one address does not satisfy the distinct-address threshold. Escalated ranges use 127.0.0.8 and expire after 30 quiet days.
Return codes
The same A-record return codes are used for IPv4 and IPv6 DNSBL queries. IPv6 addresses differ only in the query owner: the full address is expanded and reversed nibble by nibble.
| Code | Meaning |
|---|---|
| 127.0.0.2 | User-reported spam or direct spam emission |
| 127.0.0.3 | Open relay or proxy |
| 127.0.0.4 | Web/application attack or malware behaviour |
| 127.0.0.8 | Repeat offender |
| 127.0.0.10 | Legacy repeat/policy code (deprecated; use 127.0.0.8) |
Machine-readable policy: policy.txt • policy.json
Delist
Signed delistingDelisting requires DNS proof of domain control. Higher-risk listings also require a web challenge file served from the listed IP, so a random third party cannot simply point a throwaway domain at someone else’s address.
Nothing to delist right now. Delisting appears when an IP is listed (visitor or manual lookup).