UCEPROTECT-Network (UCEPROTECT-Orga), Switzerland · IP addresses (the DNSBL zones list IPv4 addresses / netblocks / autonomous systems; it is fundamentally an IP-based list, not a domain/URI list)
UCEPROTECT (Levels 1-3)
UCEPROTECT-Network is a Switzerland-based DNSBL that detects spam via a cluster of spam-trap servers ("Executive-Members") and publishes three escalating zones: dnsbl-1 (single IP), dnsbl-2 (the surrounding allocation/netblock), and dnsbl-3 (the entire ISP/autonomous system, ASN). It is one of the most aggressive lists in existence: Levels 2 and 3 deliberately list innocent neighbors and whole provider networks to pressure ISPs, and the same operator monetizes its own listings — one-time paid "express delisting" on uceprotect.net plus a recurring whitelisting subscription at whitelisted.org — profiting from the listings it creates. Because of this, Levels 2 and 3 are widely distrusted and most major mailbox providers and reputable filters do not use them.
Why you get listed
- Level 1 (dnsbl-1): your specific IP hit one of UCEPROTECT's spam traps or sent mail flagged as spam/abuse — usually means the problem is genuinely on your IP (compromised account, bad list, malware, open relay).
- Level 2 (dnsbl-2): you did nothing wrong — a different IP inside the same allocation/netblock as yours got a Level 1 listing, so the whole surrounding block is escalated. Guilt by proximity.
- Level 3 (dnsbl-3): your hosting/cloud provider's entire autonomous system (ASN) crossed UCEPROTECT's ratio of spamming IPs to total IPs, so every IP on that provider is listed regardless of your own behavior — this is why AWS, Google Cloud, OVH, DigitalOcean ranges frequently appear.
- High send volume from a 'fresh' or low-reputation IP that trips trap thresholds even without classic spam content.
Impact
Limited for most senders. The trustworthy, widely-deployed zone is Level 1 only; major providers (Gmail, Outlook, Yahoo) and reputable filters generally do NOT consume Levels 2 and 3, and some hosts (e.g. Comcast Business) publicly refuse to use UCEPROTECT at all. A Level 1 listing can cause rejections or spam-foldering at the minority of receivers that query dnsbl-1. Level 3 in particular is almost cosmetic for deliverability — if you sit on a big cloud provider you will appear there constantly with no real-world inbox impact. RFC 6471 and several hosts have called its pay-to-delist model "perilously close to extortion," so a UCEPROTECT L2/L3 hit alone is rarely a reason to panic; weight it far below Spamhaus.
How to delist from UCEPROTECT (Levels 1-3)
- First identify which level you are on at the lookup tool (rblcheck.php) — the fix is completely different per level.
- LEVEL 1: Fix the root cause on your IP (secure compromised accounts, remove bad recipients, close any open relay, stop the spam source). Then do nothing — Level 1 listings expire automatically 7 days after the LAST spam was seen from your IP. No request is needed and no free manual removal exists.
- LEVEL 1 (urgent only): If you cannot wait 7 days, you can pay UCEPROTECT for 'express delisting' DIRECTLY on uceprotect.net — look up your IP at the RBL check tool, then follow its paid-removal link (priced per IP, paid via Stripe; removal is done manually once payment clears). This is temporary (commonly cited as lasting ~30 days) and does NOT fix the cause — you will relist if traps keep firing. Note: this is NOT whitelisted.org; that separate subscription does not remove a Level 1 abuse listing.
- LEVEL 2: You cannot delist yourself directly. A Level 2 block is automatically removed once the underlying Level 1 IP(s) in your netblock drop off. File an abuse complaint with your hosting provider/ISP asking them to stop the abuser in your allocation; otherwise wait for the L1 listings to expire. (The operator also sells a whitelisted.org subscription that pre-emptively excludes a clean IP from Level 2/3 escalation, but a paid product is not required to clear an existing L2 listing.)
- LEVEL 3: There is nothing an individual end-server admin can do — it lists your provider's whole ASN. The ASN auto-removes once it no longer meets the Level 3 spam-ratio criteria. Report abuse to your provider; if L3 is genuinely hurting you, move to a cleaner IP range or a provider not chronically listed.
- Any paid removal/whitelisting is temporary and the operator profits from it — only use it for a time-critical campaign after the real cause is already resolved.
Good to know
- Level 1 is TIME-BASED and self-healing: it auto-expires 7 days after the last detected spam hits their spamtraps, with NO free manual removal button — stop the abuse and wait. Paying only buys a temporary (commonly cited ~30-day) suppression of that one listing, not a fix.
- Levels 2 and 3 list INNOCENT parties by design (neighbors / your whole cloud provider). You usually cannot self-delist L2/L3 — they clear automatically when the underlying L1 IPs expire or the provider's spam ratio drops. Don't try to 'remove yourself' from L3; it's the ASN, not you.
- The operator monetizes its own listings two ways, both under UCEPROTECT-Network: (a) one-time paid 'express delisting' of a Level 1 IP on uceprotect.net (via Stripe), and (b) a separate recurring whitelisted.org subscription that only excludes a clean IP from Level 2/3 escalation — it does NOT cover a Level 1 abuse listing (an L1 listing overrides whitelisting). RFC 6471 and several hosts (e.g. Comcast Business) liken this pay model to extortion — a strong reason most mainstream receivers ignore L2/L3. Don't pay reflexively.
Stay off the lists in the first place.
Most listings trace back to volume spikes, bad lists, and cold domains. Scheduler Zero warms your domains, paces sending, and keeps your lists clean so you build reputation instead of blacklisting yourself.