Domain is listed on a domain reputation blocklist
What this check looks for
Your domain name itself appears on a reputation blocklist. Unlike an address listing, this follows the domain everywhere — changing servers does not clear it.
Why it matters
Domain listings are usually the result of the domain appearing in the body of spam, whether sent by you, by somebody forging you, or by a compromised page on your site. They affect mail sent from anywhere, and they persist across hosting changes.
When the check passes, your report says: “The domain is clear on every reputation list we checked”.
What it costs your score
When this check fails it removes 40 points from your Email reputation score, before the status, confidence and repeat multipliers are applied. Email reputation carries a weight of 5 in the overall score.
It shares the email-reputation.blocklists family ceiling of 80 points: however many findings that family produces, together they cannot remove more than that from Email reputation. One underlying problem showing up in several places is still one problem.
- Severity
- critical
- Default confidence
- confirmed
- Status when triggered
- fail
- Deduction
- 40 points
- Family cap
- email-reputation.blocklists · 80
- Category
- Email reputation
- Module
- Email blocklists
- Fix owned by
- user
- In the ruleset since
- 2026.09
How to fix it
Find why the domain is being advertised in spam, stop it, then request delisting at ‹delisting url›.
A domain listing follows the name rather than the server, so it cannot be escaped by moving hosts.
Check whether your website has been compromised — an injected redirect or spam page is the most common cause of a domain listing.
Check whether the domain is being forged: a DMARC record with reporting enabled will tell you within a day or two whether mail claiming to be from you is being sent elsewhere.
Move DMARC to
p=quarantineorp=rejectso forged mail is rejected rather than merely reported.Once the source has stopped, request delisting at ‹delisting url›.
How to confirm it worked
Re-run this check after requesting removal.
Check the list's own lookup page for the domain and confirm it reports no listing.
A named slot like ‹domain› — and the braces left in the configuration below — is filled in with your own values when this rule appears on a report.
Technical detail
‹domain› is listed on ‹list name›: ‹listing reason›. ‹coverage reason› A domain blocklist is queried by placing the domain under the list's zone and reading the 127.0.0.0/8 answer code (RFC 5782 §2.3).
Standards and references
Test this on your domain
Run the check that produces this finding, on its own, against any domain.