Spamhaus, SURBL, and URIBL Blacklists: What They Are, Why a Domain Gets Listed, and How to Check One Before You Buy It

· Last reviewed · 16 min read

Spamhaus, SURBL, and URIBL are three of the leading domain reputation blacklists. Each one publishes a list of domain names with a poor reputation, and mail servers across the world query those lists in real time to decide whether to reject, quarantine, or strip a message that links to a listed name.

The detail that matters for anyone buying a domain is this. These lists are tied to the name, not to your server. A domain that earned a listing under a previous owner carries that reputation problem forward, and you inherit it the moment the registration transfers to you. A clean check is cheap before purchase and expensive afterward.

This guide explains what each list is, why a domain ends up on one, how the lookups work, and how to run the check yourself with the free official tools. SEO Domains operates the curated marketplace where aged and expired domains are screened against reputation lists before they are listed, so the raw material is read for inherited liabilities before it is priced.

What Spamhaus, SURBL, and URIBL blacklists are

Spamhaus DBL, SURBL, and URIBL are domain reputation blacklists. Each one is a published list of domain names flagged for appearing in spam, phishing, malware, or other abuse. Mail filters query them over DNS to score incoming messages, and a domain on any of these lists carries a reputation problem that follows the name itself.

The three names get grouped together because they do the same core job from three independent vantage points. SURBL has run its reputation database since 2004, according to its operator. URIBL publishes a realtime URI blacklist. Spamhaus, the oldest of the three projects, maintains the Domain Block List alongside its better-known list of sending IP addresses.

A domain reputation list, in plain English

Each list answers one question: does this domain name have a history of showing up in abuse? When a domain is added, every mail server that consults the list starts treating messages that mention that domain with suspicion. The domain does not have to send the message. It only has to be linked inside it.

That is the trait the three share and the reason it matters to a buyer. A sending IP belongs to a server you control today. A domain reputation belongs to the name, and the name is exactly what changes hands in a domain sale.

Why an SEO buyer runs into these names

Anyone sourcing aged or expired domains meets these three lists during diligence. An expired domain inherits whatever its previous owner did, and a domain that was used for spam, was hacked, or hosted an abused redirect can carry a live listing into its next life. The listing is a signal that the name has a problem the registration history is hiding.

A clean check across Spamhaus DBL, SURBL, and URIBL is one of the screens that separates a usable aged domain from a poisoned one. It sits alongside the backlink and Safe Browsing checks covered across the Blacklists and Safety Checks pillar.

Domain reputation versus the things people confuse it with

Four different signals get lumped together as a domain being blacklisted, and they are not the same. A domain reputation listing on DBL, SURBL, or URIBL is about the name. An IP DNSBL listing is about a sending server. A Google Safe Browsing flag is about a website serving threats. A Google manual action is about search rankings. Each has a different cause, a different check, and a different fix.

Conflating them is the single biggest mistake in this topic, and it sends people to the wrong tool. The table below separates the four so the rest of this guide can focus on the first row, the domain reputation lists this page is about.

SignalWhat it is aboutExamplesWhere to check
Domain reputation listThe domain NAME that appears inside a message or links outSpamhaus DBL, SURBL, URIBLOperator lookups (this page)
IP or mail-server DNSBLThe sending server IP address, not the domain nameSpamhaus SBL, XBL, PBL, ZENAn IP DNSBL lookup against the server IP
Safe Browsing flagA website serving malware, phishing, or unwanted softwareGoogle Safe BrowsingThe Safe Browsing checks in the Blacklists and Safety Checks pillar
Search penaltyA search ranking action, not deliverabilityGoogle manual action, algorithmic devaluationSearch Console Manual Actions report
Figure 1. Four signals searchers conflate. Spamhaus runs both a domain list (DBL) and IP lists (SBL, XBL, PBL, ZEN), which is the main source of the confusion. This page covers domain reputation lists only. A Safe Browsing flag and a search penalty are separate systems with their own checks.

Spamhaus is two things, and that is the trap

Spamhaus is the reason the categories blur. Spamhaus DBL lists domain names. Spamhaus SBL, XBL, PBL, and ZEN list IP addresses of sending servers, according to the Spamhaus blocklist documentation. A domain buyer cares about the DBL, because that is the list keyed to the name they are acquiring. The IP lists describe where mail was sent from, which is a property of a server, not of a domain for sale.

SURBL and URIBL are purely domain-side. Both list the URIs and domains found inside message bodies instead of the IPs that delivered them, which is why all three sit in the same diligence step for a domain buyer.

The three lists compared: Spamhaus DBL, SURBL, and URIBL

The three lists differ in operator, the sub-lists they publish, the data they expose for free, and how they handle removal. Spamhaus DBL uses graded return codes for spam, phishing, malware, and botnet domains. URIBL splits into black, grey, and red tiers by confidence. SURBL publishes a single public multi list. All three are queried over DNS and all three offer free removal.

DimensionSpamhaus DBLSURBLURIBL
OperatorThe Spamhaus ProjectSURBL, since 2004URIBL.com
What it listsDomain names with poor reputation, never IPsURIs and domains in message bodies, regardless of sender IPDomains that appear in spam, not where they were sent from
Public sub-listsOne DBL zone, graded by return codemulti (the public combined list)black, grey, red, white, multi
Coverage classesSpam, phishing, malware, botnet C&C, abused-legitPhishing, malware, cracked and abused sitesConfirmed spammer domains (black), opt-out senders (grey), young or monitored domains (red)
Public query hostdbl.spamhaus.orgmulti.surbl.orgmulti.uribl.com
RemovalAlways free, auto-expires when activity ceasesDelist form after fixing the root causeDelist form; some tiers auto-expire
Figure 2. The three domain reputation lists side by side, sourced from each operator’s own documentation. The practical takeaway is that they overlap: a genuinely abusive domain often appears on all three at once, while a borderline listing on URIBL grey or red may sit alone.

Spamhaus DBL: graded by threat type

The Spamhaus Domain Block List is a list of domain names with poor reputation, published in a domain DNSBL format, and it lists domain names only, never IP addresses. Its coverage spans spam domains, phishing domains, malware distribution domains, botnet command-and-control domains, and compromised legitimate sites in an abused-legit category. The bulk of DBL listings happen automatically from traffic analysis, according to Spamhaus.

The DBL is graded. A lookup does not just return listed or not listed. It returns a code that names the threat type, which lets a filter weight a phishing domain differently from a merely spammy one. The exact codes are covered in the lookup section below.

SURBL: domains inside the message body

SURBL filters on the links inside a message body, regardless of the sender IP address, according to its operator. Combined with IP-based filtering, SURBL states this approach detects 95 percent of unsolicited messages. The publicly available dataset is the multi list, which combines SURBL’s reputation data into one queryable zone. Private datasets, including Fresh for recently delegated domains and HashBL for cryptographic hashes, sit behind paid feeds.

URIBL: black, grey, and red tiers

URIBL lists domains that appear in spam, not where they were sent from, and it splits that data into confidence tiers. The black list holds domains belonging to and used by spammers, with a stated goal of zero false positives. The grey list holds domains found in unsolicited bulk or commercial email that URIBL itself warns will cause false positives. The red list holds domains actively in mail flow that are being monitored, are newly registered by their registration date, or use WHOIS privacy. The white list and the multi list round out the public set.

How a blacklist lookup works under the hood

A domain blacklist lookup is a specially formatted DNS query. The checker prepends the domain to the list’s zone, asks DNS whether a record exists, and reads the answer. A returned address in the 127.0.0.0/8 range means listed, and the exact final number encodes which sub-list or threat type matched. No answer, an NXDOMAIN, means the domain is not listed.

The query format

To check a domain on a list, a filter appends the domain to the list zone and resolves it as a hostname. For a domain on URIBL, the checker queries against multi.uribl.com. URIBL documents an IP example where 1.2.3.4 is queried as the reversed 4.3.2.1.multi.uribl.com, and the same prepend-and-resolve pattern applies to domain queries against the zone.

If the lookup resolves to an address, the domain is listed. If DNS returns NXDOMAIN, no such name, the domain is not listed. That binary, resolves or does not, is the whole mechanism, which is why these lists are fast enough to run on every message a mail server processes.

Reading the answer code

The returned address is not arbitrary. It encodes the result. Spamhaus DBL uses the 127.0.1.0/24 range, where 127.0.1.2 marks a spam domain, 127.0.1.4 a phishing domain, 127.0.1.5 a malware domain, and 127.0.1.6 a botnet command-and-control domain. Codes from 127.0.1.102 through 127.0.1.106 mark the abused-legit subcategories, and 127.0.1.255 signals an invalid query, such as submitting an IP address to a domain-only list. URIBL uses a 127.0.0.X bitmask where the final octet identifies which of its lists matched.

Return codeMeaningWhat a buyer reads from it
NXDOMAIN (no answer)Domain not listedClean on this list at the moment of the check
127.0.1.2Spam domainThe name has a documented spam history
127.0.1.4Phishing domainA serious abuse class, harder to dismiss as a fluke
127.0.1.5Malware domainThe name distributed malware under a prior use
127.0.1.6Botnet command-and-control domainThe most severe class, a deliberate abuse infrastructure
127.0.1.102 to 127.0.1.106Abused-legit subcategoriesA legitimate site that was compromised, not born malicious
127.0.1.255Invalid queryAn IP was submitted to a domain-only list; re-run with the domain
Figure 3. Spamhaus DBL return codes, taken from the DBL documentation. A botnet or phishing code is a far heavier signal on an acquisition candidate than a single spam code, and an abused-legit code points to a hacked-then-cleaned history that the registration record alone will not reveal.

Why a domain ends up on Spamhaus, SURBL, or URIBL

A domain gets listed for documented reasons: it was used to send or advertise spam, the site was compromised and abused to distribute phishing or malware, it operated an abused redirect or URL shortener, it ran cold outreach that drew complaints, or it hit spam traps. URIBL also flags domains that are newly registered or hide their registration. Each cause has a different weight for a buyer.

Understanding the cause matters because not every listing is the same. A botnet listing reflects deliberate abuse. A young-domain flag on URIBL red reflects nothing more than newness. A buyer reads the cause, not just the presence of a flag.

The documented listing causes

  • Spam advertising. The domain was advertised in unsolicited bulk or commercial email, which is the original purpose SURBL was built to catch when it launched in 2004.
  • A compromised site. Attackers exploited a website or stole its credentials to send phishing or malware. The SH Consulting writeup documents an exposed SendGrid API key that generated 2.3 million spam emails before the owner noticed, and the listing persisted after the sending stopped because it was tied to the distributed URLs.
  • Malware or phishing hosting. The domain served malware or hosted a phishing page, which lands it in the heavier Spamhaus DBL classes and on SURBL’s phishing and malware data.
  • Abused redirects and shorteners. A redirect or URL shortener on the domain was abused to mask malicious destinations, a pattern SURBL tracks through its shortener data.
  • Cold outreach complaints. Even legitimate but unsolicited outreach can trigger manual reports to these lists when recipients forward the messages, per SH Consulting’s documented patterns.
  • Spam-trap hits. Sending to abandoned addresses that have been recycled into trap networks, typically after 12 to 24 months of inactivity, signals poor list hygiene and draws a listing.
  • Newness or hidden registration. URIBL’s red tier flags domains that are very young by their registration date or that use WHOIS privacy, before any proven abuse.

Why the cause changes the decision

A single spam code on an otherwise strong aged domain can sometimes be the residue of a brief misuse that auto-expires once activity stops. A phishing, malware, or botnet code is a different matter, because it reflects deliberate abuse infrastructure, and the inherited reputation is far stickier. A URIBL red listing on a freshly dropped domain can clear on its own as the name proves itself. Reading which of these applies is the difference between rejecting a name and pricing the cleanup.

How to check a domain across all three lists

Checking a domain takes three free official lookups plus one optional aggregator. Query the Spamhaus Reputation Checker, the SURBL lookup, and the URIBL multi lookup, then read each result against the return codes and tiers above. An aggregator such as a multi-list checker queries dozens of lists in one pass, which is faster for a first sweep but hides which specific list matched.

Run the check on the bare domain name. Do not include a protocol or path. The lookups evaluate the registered domain, so example.com is the input, not the full URL. Here is the sequence for a thorough check before an acquisition.

  1. Check Spamhaus DBL with the Reputation Checker

    Open the Spamhaus Reputation Checker at check.spamhaus.org and enter the bare domain name. The free tool reports the domain’s standing across Spamhaus data, including the DBL. Read the result against the return-code table: a phishing, malware, or botnet result is a heavy signal, a single spam code is lighter, and a clean result is no answer at all.

    The mistake: entering the full URL with https and a path, or submitting an IP. The DBL is a domain-only list, and an IP query returns the 127.0.1.255 invalid code instead of a real verdict.

  2. Check SURBL with the official lookup

    Use the SURBL lookup on surbl.org to query the domain against the public multi list. SURBL reports which category applies, such as phishing or an abused or cracked site. Because SURBL filters on links inside message bodies, a listing here means the name itself has been seen advertised in unsolicited mail.

    The mistake: treating a SURBL hit as identical to a Spamhaus hit. They are independent operators with different data, so a clean SURBL result does not clear the domain on Spamhaus or URIBL.

  3. Check URIBL multi, and read the tier

    Query the domain against URIBL’s multi list. The result identifies which of URIBL’s lists matched. The tier is the key detail: a black listing is a confirmed spammer domain, a grey listing carries a known false-positive risk by URIBL’s own admission, and a red listing can mean nothing worse than a newly registered or privacy-protected registration.

    The mistake: rejecting a freshly dropped domain solely for a URIBL red flag. Red flags newness and privacy, not proven abuse, so weigh it against the rest of the profile instead of treating it as a disqualifier on its own.

  4. Optionally sweep with a multi-list aggregator

    A multi-list checker queries dozens of blacklists in one pass, which is a fast way to confirm a domain is clean across the wider field, not just the three covered here. Use it as a first sweep, then return to the official operator lookups for any list that flagged, because the aggregators rarely explain which sub-list matched or why.

    The mistake: relying on an aggregator alone, or paying for a checker subscription. The data lives at the three operators, and reading it there is free and unambiguous. A bundled report that mixes domain lists with unrelated IP lists obscures the one answer a buyer needs.

  5. Record the result against the registration history

    Note the date of the check, the lists queried, and any codes returned, then read them alongside the domain’s ownership history. Registration data moved from WHOIS to RDAP, the Registration Data Access Protocol, as the standard ICANN lookup on 28 January 2025. A listing that lines up with a prior owner or a known gap in the history tells you when the reputation problem was created.

    The mistake: checking once and assuming the result is permanent. Listings expire and new ones appear, so a check is a snapshot. Re-run it close to the point of purchase, not weeks before.

Figure 4. The five-step check sequence. The official operator lookups are free and authoritative; aggregators are a convenience layer on top. Reading the result against the RDAP registration history is what turns a yes-or-no flag into an understanding of when and why the reputation was earned.

What a listing means and how to get a domain delisted

A listing means mail filters will treat messages mentioning the domain with suspicion, which translates into rejection, quarantine, or link stripping regardless of sender authentication. Removal is free on all three lists and follows the same shape: identify the sub-list, fix the root cause, harden the domain’s email security, then submit a delisting request with concrete evidence. Spamhaus DBL listings auto-expire once the abuse stops.

What a live listing does

The impact is concrete. When a recipient’s mail server queries one of these lists during message processing and finds the domain listed, it can bounce the message outright, route it to quarantine, or strip the offending link, even when the sending IP and authentication are perfect. Commercial gateways such as Mimecast and Proofpoint weight a SURBL listing into their risk scoring, per SH Consulting, so a listing degrades deliverability across the enterprise mail estate, not just one inbox.

The removal process

Removal on all three lists is free. Spamhaus states there is never any charge or fee associated with removing any Spamhaus listing, and that DBL listings expire automatically once the associated activity ceases. SURBL and URIBL provide delisting forms once the underlying problem is resolved. The shape of a successful delisting is consistent across the lists.

  1. Identify the sub-list and the reason

    Run the lookups to learn exactly which list and which category applies, such as a phishing code on DBL or a cracked-site category on SURBL. Each cause needs a different fix, so a generic cleanup request fails.

  2. Fix the root cause

    For a compromised site, run a security audit, remove the malware, and rotate every exposed credential. For an outreach-driven listing, tighten the audience, cut volume, and sunset disengaged recipients. The listing will not clear while the cause is live.

  3. Harden email security

    Move DMARC policy to p=reject, deploy MTA-STS, and audit third-party application access, per SH Consulting’s removal guidance. This prevents the spoofing and unauthorized sending that caused the listing from recurring after delisting.

  4. Submit the delist request with evidence

    Use the operator’s removal form and document the specific fix, for example that an exposed API key was found and all credentials rotated. Specific, evidenced requests get approved; generic ones do not. Spamhaus approvals typically take minutes to 24 hours once the underlying activity has ceased.

Figure 5. The delisting sequence, drawn from operator policy and SH Consulting’s documented removal steps. The recurring lesson is that delisting follows a fix, never replaces it: submitting a request while the abuse continues only resets the clock.

Why a fresh domain is not the easy escape

Abandoning a listed domain for a freshly registered one carries its own cost. New domains draw heavy scrutiny from major mail providers, and SH Consulting notes that roughly 98 percent of new domains are spam operations in Gmail’s experience, so cold mail from an unwarmed new name routinely performs worse than a repaired one. The same logic applies to a buyer: a freshly dropped domain that lands on URIBL red for newness is not automatically safer than a screened aged domain with a clean, proven history.

Why this is a pre-purchase check on any aged or expired domain

A blacklist check belongs before the purchase, not after. The listing is tied to the domain name, so it transfers with the registration. Done right, a buyer screens Spamhaus DBL, SURBL, and URIBL during diligence and walks away from or discounts a poisoned name. Done wrong, the buyer discovers the listing after the transfer and inherits the cleanup with no leverage. The domain is the raw material; its reputation is part of what is being bought.

The inherited-liability principle

Everything in this guide points at one fact a buyer must internalise. A domain reputation listing is a property of the name, and the name is the asset changing hands. Unlike a sending-IP listing, which you leave behind when you move servers, a domain listing follows the registration into your account. The previous owner’s spam run, hacked site, or abused redirect becomes your reputation problem the moment the transfer completes.

That is the honest reality of buying aged and expired domains, stated without alarm. An aged domain is a powerful asset precisely because it carries history, and history cuts both ways. The earned backlinks are the upside. A reputation listing is the downside, and the only reliable way to separate the two is to read the reputation before money moves.

Where the marketplace fits

The legitimate demand behind a search for these three lists is a buyer trying not to inherit a problem. That is a sourcing question, and it is where SEO Domains operates. Aged and expired domains in our marketplace are screened against reputation lists as part of the listing process, so the inherited liabilities these blacklists expose are read before a name is priced. You can still run the free official lookups yourself, and doing so is worthwhile. The marketplace just means the raw material has already been read once before it reaches you. Browse screened inventory on the SEO Domains marketplace when you want the check done before the name is even listed.

Frequently asked questions

The five questions buyers and SEOs raise when they search for Spamhaus, SURBL, and URIBL, answered against the operators’ own documentation and the inherited-liability framing this guide draws.

Q1What is the difference between SURBL, URIBL, and Spamhaus DBL?

All three are domain reputation blacklists that list the domain appearing inside a message instead of the sending IP. SURBL, running since 2004, filters on links in the message body. URIBL publishes black, grey, and red confidence tiers. Spamhaus DBL grades domains by threat type with return codes for spam, phishing, malware, and botnet domains. They are independent operators with overlapping but separate data, which is why a thorough check queries all three.

Q2Does a Spamhaus, SURBL, or URIBL listing affect a domain’s Google rankings?

Not directly. These are email deliverability lists, so the immediate impact is on mail that mentions the domain, not on search rankings. A search ranking problem is a separate system, a Google manual action or algorithmic devaluation. That said, a domain with a heavy abuse history that earned a blacklist listing is also a domain a careful SEO buyer scrutinises closely, because the same misuse can correlate with a poor backlink profile or a Safe Browsing flag.

Q3Is it free to check and to get removed from these blacklists?

Yes on both counts. The official operator lookups are free: the Spamhaus Reputation Checker, the SURBL lookup, and the URIBL multi lookup. Removal is also free. Spamhaus states there is never any charge or fee for removing any Spamhaus listing, and SURBL and URIBL provide free delisting forms once the underlying cause is fixed. A paid checker subscription buys convenience, not access, because the data lives at the operators.

Q4Does a blacklist listing transfer when I buy the domain?

Yes, and this is the central point for a buyer. The listing is keyed to the domain name, so it follows the registration into your account when the transfer completes. A sending-IP listing stays with the old server, but a domain reputation listing on DBL, SURBL, or URIBL is inherited. Checking before purchase is the only way to avoid taking on a cleanup you did not create, which is why the check belongs in diligence.

Q5My aged domain shows up on URIBL red. Is it ruined?

Not necessarily. URIBL’s red list flags domains that are newly registered by their registration date, use WHOIS privacy, or are under active monitoring, before any proven abuse. A freshly dropped domain can land on red for newness alone, and the flag can clear as the name establishes a clean record. Weigh a red listing against the rest of the profile instead of treating it as a disqualifier. A black listing, by contrast, marks a confirmed spammer domain and is a far heavier signal.

Source aged domains with a clean reputation, screened before listing

A domain’s reputation decides whether an aged-domain acquisition is an asset or a liability. A name with a clean record across Spamhaus DBL, SURBL, and URIBL is the raw material of doing it right; a listed name is a cleanup you inherit. Sourcing from a screened catalogue separates the two before money moves. SEO Domains operates that curated marketplace.

Why reputation decides the outcome

The whole of this guide converges on one variable. Whether you are building a single authority site, running a 301, or sourcing domains for white-hat link building, the inherited reputation of the name is what holds or fails. A clean check is the floor of doing it right with any aged or expired domain. A listed name is the ceiling on what you can do with it, because the reputation problem travels with the registration.

The asset versus the liability

A clean aged domain is a legitimate asset you own under your own name. Its history of earned links is the upside, and a clean reputation across these three lists is the evidence that the history is sound. A listed name is the inverse: the same history that ought to read as an asset has instead recorded abuse. Reading the difference before purchase is the error every fear-first guide skips and every careful buyer makes routine.

How to source domains that check out clean

A domain that holds up survives a reputation screen before money changes hands. The signals that matter sit alongside the authority metrics documented across the wider resource library:

  • A clean result across Spamhaus DBL, SURBL, and URIBL at the point of purchase, not weeks before.
  • An RDAP registration history with no gap that lines up with a known abuse period.
  • A backlink profile that is editorially earned, cross-validated against the Domain Authority & Metrics hub.
  • A clean Google Safe Browsing result, checked separately because it is a different system, alongside the other checks in the Blacklists and Safety Checks pillar.

A poisoned name fails one or more of these and is a liability the moment it enters any strategy. A screened name passes them and is an asset whatever you build on it.

Kalin Karakehayov, Chief Executive Officer at SEO Domains

Kalin Karakehayov

Chief Executive Officer @ SEO Domains · Founder

Kalin is the founder of SEO Domains, the world’s largest supplier of aged domain names across every country and niche. A former professional chess player with 18 years in SEO, he sets the company’s standards for sourcing and screening high-authority domains.

He leads SEO at the SEO Domains marketplace, which operates a 220,000+ curated catalogue from $100 entry-level domains through premium acquisitions, screened across the catalogue, with Managed Account expert support for premium-tier clients.

· Last reviewed