Which blocklists we check, and which we do not
What this check looks for
We check ‹checked lists›. We do not check ‹excluded lists› — not because we cannot, but because their free feeds are licensed for non-commercial use and we have not bought the paid ones.
Why it matters
Spamhaus is the list most mail providers actually consult. A tool that reports a clean result without saying it never asked Spamhaus is telling you something narrower than it sounds, and you would act on it as though it were the whole picture.
What it costs your score
This check never deducts. It reports a fact — or reports that something could not be verified — and is shown on the report without moving the score.
- Severity
- info
- Default confidence
- confirmed
- Status when triggered
- info
- Deduction
- 0 points
- Family cap
- none
- Category
- Email reputation
- Module
- Email blocklists
- Fix owned by
- third party
- In the ruleset since
- 2026.09
Technical detail
Checked: ‹checked lists›. Not checked: ‹excluded lists›. The excluded sources publish free public mirrors licensed for non-commercial use only (Spamhaus, SURBL, URIBL) or state 'for non-commercial use only' in their API terms (Google Safe Browsing v4 and v5). dotvitals is a commercial site, so querying them would breach those terms. The compliant alternatives are paid, quoted per volume, and not yet bought. You can check Spamhaus yourself, free, at https://check.spamhaus.org/. The full explanation, including what we would add if we bought a feed, is at ‹disclosure url›.
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.