Spamhaus Checker
Spamhaus Domain Block List (DBL) lookup for spam/malware-associated domains.
This is one independent signal used by the Domain Security Score, and can also be run on its own for any domain.
Based on: RFC 5782 — DNS Blacklists and Whitelists (DNSBL/RHSBL) · Spamhaus — Domain Block List (DBL)
About this validation
Spamhaus Domain Block List (DBL) lookup for spam/malware-associated domains.
- Protocol / standard:
- Vendor documentation:
- Rules reviewed:
- Sep 6, 2026
SEOTechTests methodology: Data source: a live DNS query against Spamhaus's DBL zone (optionally via an authenticated DQS key), following RFC 5782's DNSBL query mechanism. FAIL on a listing; PASS on NXDOMAIN (not listed); UNKNOWN on a query-refused/rate-limited response code -- Spamhaus's own reserved 127.255.255.0/24 range is never treated as a listing.
Standards and vendor-documented behavior can change. This reflects the source as last reviewed above, not a permanent guarantee.
FAQ
What does Spamhaus check for a domain?
It queries Spamhaus's Domain Block List (DBL), a DNS-based list of domains associated with spam, phishing, malware, or botnet command-and-control activity.
Why is Spamhaus used as a domain reputation source?
Spamhaus maintains widely used blocklist data covering domains and network infrastructure, built from its own abuse monitoring; SEOTechTests uses it as one independent abuse-reputation signal, not the sole determinant.
What does it mean if a domain is listed?
Spamhaus has associated the domain with spam, malware distribution, or similar abuse at some point -- this check reports the current listing status via a live DNS query, so a recently delisted domain will show as clean.
Does not being listed guarantee that a domain is safe?
No. Absence from one blocklist does not rule out abuse that Spamhaus hasn't observed or listed yet -- that's why this score combines it with several other independent sources.
Why can this check return UNKNOWN instead of PASS or FAIL?
Spamhaus's public DNS mirror returns a reserved "query refused / rate limited" code (127.255.255.0/24) to unauthenticated high-volume callers like datacenter IPs -- this is never treated as a listing, only as UNKNOWN, and is avoided by configuring an authenticated DQS key.