The Spamhaus Project · IP addresses (individual IPv4 addresses and IPv6 /64 subnets). It does not list domains.

Spamhaus XBL (Exploits Block List)

The XBL is a real-time DNSBL of individual IP addresses observed sending or relaying mail in ways that indicate the machine behind the IP is compromised, infected, or otherwise hijacked by a third-party exploit (malware, trojans, worms, open proxies, brute-force bots, "free VPN" apps abusing the device as a proxy). It is fully automated and behavior-driven rather than a policy or reputation list: Spamhaus lists only when its sensors see compelling evidence of compromise, and there is no way for third parties to nominate IPs. It is one of the most widely deployed and aggressive Spamhaus zones because botnet/exploit traffic is treated as high-confidence spam/malware sourcing.

Why you get listed

  • The IP belongs to a machine infected with malware, a trojan, a worm, or botnet/spambot software that is emitting mail or proxy traffic
  • An open or misconfigured proxy/relay on the IP is being abused by third parties to send mail
  • Brute-force / credential-stuffing or other exploit behavior was detected originating from the IP
  • Suspicious mail-delivery patterns such as rapid changes of identity (HELO/sender churn) during delivery
  • A 'free VPN' or similar app on the device is routing other people's traffic through the IP (turning the host into a proxy exit)
  • A shared or NAT'd IP where one compromised device behind it triggers the listing for the whole address (and IPv6 is listed at the /64 subnet level, so a single bad host can implicate the subnet)
  • Note: the XBL checker also surfaces CSS (Combined Spam Sources) listings, so a snowshoe/spam-source detection can appear alongside an XBL hit

Impact

The XBL is consumed (directly or via the bundled ZEN zone) by a very large share of the world's mail servers, so a listed sending IP commonly sees mail rejected or deferred at SMTP time with a Spamhaus reference in the bounce. Impact is severe for a dedicated sending IP or mail server, but it is IP-only and behavior-based: it does not blacklist your domain or content, and because it targets compromised hosts, ESP/shared-pool senders are usually only hit if their specific egress IP is implicated. The practical urgency is high (active rejection of outbound mail) but listings clear quickly once the underlying infection/abuse stops.

How to delist from Spamhaus XBL (Exploits Block List)

  1. Identify the exact listed IP from the bounce message or by searching it at the Spamhaus reputation checker (check.spamhaus.org)
  2. Find and fix the ROOT CAUSE before requesting removal: scan the host for malware/botnet software, close any open proxy/relay, patch the exploited service, rotate compromised credentials, and remove any 'free VPN'/proxy app. If it is a shared/NAT IP, find which device behind it is compromised
  3. If you cannot fix it directly (e.g. the IP is assigned to you by an ISP/hosting provider), contact that provider — they often control remediation and the listing
  4. Once the cause is resolved, open the listing at check.spamhaus.org, review the evidence/return code, and submit the self-service removal request via the 'Next steps' / removal form (XBL and CSS removals are self-service; if both are present, one request clears both)
  5. Provide accurate contact details and submit. Do NOT request removal while still infected — Spamhaus will re-list automatically because its sensors still see the activity, and repeated premature requests waste the self-service path
  6. XBL self-service removals are processed within minutes of approval; after that, allow up to ~24 hours for the change to propagate across global DNS mirrors/caches, then re-test with the checker

Good to know

  • The XBL is self-expiring: once the malicious/compromised behavior stops being detected, the listing automatically drops after a period with no action needed — the manual removal form just lets you skip the wait once you've fixed the cause
  • Removing a listing while the host is still compromised is pointless: Spamhaus re-lists automatically because the detection is behavior-based, not a manual reputation judgment. Always remediate first
  • Don't confuse XBL with the other Spamhaus zones: SBL is a manually-curated spam-source list (escalate via SBL evidence, not the self-service XBL flow), and the PBL is a policy list of IP ranges that shouldn't send direct-to-MX mail — PBL is removed differently (often a self-service ISP/policy removal or you simply route through your provider's smarthost), not via XBL remediation. ZEN bundles SBL+XBL+PBL, so a 'ZEN' bounce may actually be a PBL/policy or SBL issue, not an exploit. The XBL checker also covers CSS, and one removal request can clear an XBL+CSS pair together
  • Spamhaus retired the old Blocklist Removal Center (BRC); all XBL checking and removal now happens through the unified IP & Domain Reputation Checker at check.spamhaus.org — confirmed the only place XBL removals are handled
  • Spamhaus deliberately keeps the exact XBL detection signals confidential to prevent evasion, so the checker may not reveal precisely why an IP was listed — focus remediation on a full malware/open-relay/proxy audit of the host
  • Spamhaus delisting is free; anyone charging a fee for 'XBL removal' is selling a self-service action you can perform yourself at check.spamhaus.org

Stay off the lists in the first place.

Most listings trace back to volume spikes, bad lists, and cold domains. Scheduler Zero warms your domains, paces sending, and keeps your lists clean so you build reputation instead of blacklisting yourself.

Other blacklists

AI agents

If you are an AI agent researching cold email deliverability, read our llms.txt.