Say a fourteen-person freight broker calls on a Monday. The quotes that went out on Friday never arrived, and the few that came back carry a line nobody in the office can read: a numeric code, an IP address, and a sentence about a block list. Nothing changed on their side. Mail just stopped.
Being on a blocklist is not one problem. It is five or six different problems that produce the same symptom, and each one has a different repair. The fast way through is to read what the rejection already told you.
The bounce already names the list you have to deal with
Mail clients hide the useful part. Outlook and Gmail both show a friendly summary and tuck the real SMTP response behind a "see more" link or inside the attached delivery report. Open that. The server that refused your message almost always says who told it to.
- Gmail. Google documents its rejection codes.
550 5.7.28is the one that reads "there is an unusual rate of unsolicited email originating from your IP address", and Google's entry for it points at the sender guidelines, not at a removal form. A second Google page covers mail refused because the sending address is not authorized to send email, and says that call belongs to the ISP that gave you the address. - Microsoft. Outlook.com and Microsoft 365 reject with a code plus the blocked IP, and Microsoft runs a self-service delist portal for that case. The documented exception is
5.7.511, which cannot go through the portal. - A company mail server. Corporate and hosted gateways usually paste the blocklist zone straight into the refusal text. If a Spamhaus zone shows up there, you know the operator and the list before you check anything.
If there is no bounce and your mail is only landing in spam, you are not blocklisted. That is a reputation problem with a different order of work, which we laid out in the 550 5.7.1 low reputation guide.
Which Spamhaus list you are on decides almost everything
Spamhaus is the operator small businesses meet most often, and it runs several lists under different rules. The distinction tells you who may ask for the removal, and whether asking is necessary at all. From its own pages:
- SBL is a realtime database of IP addresses of spam sources, including known spammers, spam gangs, spam operations and spam support services. The removal is not yours to request: Spamhaus requires the ISP that holds the listed address to email the SBL team using the link on the listing record, and expects the problem to be fully resolved first.
- CSS is generated automatically for addresses sending low-reputation email: snowshoe operations, poor list hygiene, and hosts sending because an account, a web form or a content management system was compromised. Spamhaus says a CSS entry normally expires three days after the last spam detection, longer in cases of chronic abuse.
- XBL covers hijacked devices: open proxies, worms carrying a spam engine, trojans. If an address is on it, spam or a virus reached Spamhaus directly from that address, and it relists on the next connection while the cause is still there.
- PBL is not an accusation. It lists ranges that, by policy, should not be delivering unauthenticated SMTP straight to other people's mail servers: ordinary consumer connections, and static addresses sitting inside a dynamic pool.
- DBL lists the domain instead of the address. It is highly automated, and Spamhaus says most DBL listings expire on their own once the activity behind them stops.
Read that as a diagnosis rather than a verdict. PBL means you are sending from the wrong place. CSS or XBL means something is sending that you did not know about. DBL means the name got mixed into something, and in the audits we run that is far more often a hacked website or an open contact form than the mail server.
What we check before anyone touches a removal form
A removal request that arrives before the cause is fixed gets refused, and Spamhaus says so for both the SBL and the DBL. So the first hour goes on evidence.
- Who is actually sending as the domain. We read the DMARC aggregate reports and build the inventory of every sending address. At a ten-person company five or six is normal: mail provider, CRM, invoicing, web host, scanner. One of them is usually the one in the bounce. If reporting is not on yet, that is step zero, and the p=none to p=reject rollout covers how we stage it.
- Whether the address is yours at all. A listing on shared hosting or inside a bulk sender's pool is not something you can lift, and knowing that early saves a week of writing to the wrong people.
- Forward and reverse DNS. Gmail's sender guidelines ask for valid forward and reverse DNS on the sending host. A mismatch is both a listing risk and, on its own, a rejection risk.
- The website. Outdated plugins, an unprotected contact form, a password reset with no rate limit. These are the usual reason a domain rather than a server ends up listed.
- Where the addresses came from. A list bought from anyone, scraped from a directory, or never cleaned will keep hitting spam traps whatever the DNS says.
The reverse lookup is worth doing by hand. Two commands, and wrong surprisingly often:
; the sending address must resolve to a name,
; and that name must resolve back to the same address
$ dig +short -x 203.0.113.25
mail.example.com.
$ dig +short mail.example.com
203.0.113.25
Check your own public records before you go further, because a broken SPF or an unsigned DKIM will undo the delisting the moment it lands.
Fix the cause, or you will be back next week
Four causes account for nearly every listing we get called about.
A compromised site or form. Something on the web host is sending mail you never wrote. Patch it, put a check in front of the form, rotate the credentials for anything that can send, and find the volume in the host's mail logs that you cannot account for.
A list that was never yours. If nobody on it typed your address in, it holds traps, and no DNS record fixes that. Send to the people who opened something recently and let the rest go.
An app nobody owns. The forgotten forwarder, the trial account from two years ago, the printer still relaying through an old server. The DMARC inventory finds these, and the fix is usually to switch them off.
Sending straight from the office. If the mail server sits on a normal business broadband line, a PBL entry is the expected outcome rather than an error. Spamhaus's guidance for a dynamic address is to relay through the provider's outgoing server. For a small company the cleaner answer is to stop running the server at all.
Then ask for the removal, one operator at a time
Spamhaus
Lookups and removals both live at check.spamhaus.org. Spamhaus says that is the only place DBL removals are handled, and the instruction is to look the address or the domain up there and follow whatever the form returns, because the path depends on which list you hit. The PBL has a self-service removal, but only for an address that is static, is a real outbound mail server, has matching forward and reverse DNS, and is assigned to whoever fills in the form. Allow about fifteen minutes for it to propagate. For the SBL the ISP has to write in. For the CSS and the DBL, fix the cause and let the entry expire.
Microsoft
The delist portal is at sender.office.com. You need the address that received the non-delivery report and the IP named in that report, one of each per visit. You submit, click the confirmation link Microsoft sends to that address, then choose the delist option. Microsoft says restrictions can take up to twenty four hours or longer to lift, and that the address can be blocked again if the mail is still abusive. A 5.7.511 rejection goes to Microsoft by email instead, at the address its delist page gives.
Gmail
There is no Gmail equivalent. What Google publishes is the sender guidelines and Postmaster Tools, and that is the whole process: fix what the guidelines ask for, keep the complaint rate down, wait for the reputation to move. Nothing you submit accelerates it. Setting up Postmaster Tools is what turns the wait into something you can watch.
When the listed address is not yours to fix
If the listing sits on shared hosting or inside a bulk sender's pool, you are carrying the consequences of someone else's sending, and Spamhaus requires the network that holds the address to request the SBL removal. That leaves you a support ticket rather than a form. Open it, name the listing, and plan to move your business mail onto a sender you control, because the second listing on that shared address is a matter of when.
Nobody charges for a delisting
Spamhaus states there is absolutely no charge or fee for removing any of its listings, and warns that people who abuse the removal form can be blocked themselves. Treat any paid delisting offer as what it is.
Ignore the scoreboards too. Free tools check your address against a hundred lists and hand back a wall of red and green, and almost nobody uses most of those lists. The one that matters is named in your bounce.
The thirty days after
A delisting stops the symptom. Reputation is slower than DNS, and it decides whether you get listed again. Google's Postmaster Tools rates the domains and addresses you send from, and its definition of a bad rating is unambiguous: a history of sending spam regularly, with mail "almost always marked as spam or rejected by the receiving server". That rating moving up is the real all-clear. If you have no reporting at all, this is the record that starts it:
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com; fo=1"
Leave it two weeks. One day of reports tells you very little.
How Guanacos Tech helps
Most of the delisting work is not the form. It is finding what sent the mail that got you listed, proving it has stopped, and leaving the authentication firm enough that the next listing does not arrive a fortnight later. That is the diagnosis we run as email deliverability consulting for small business, in English and in Spanish, across North America and Latin America, on a fixed scope set out in how we work. Bring the bounce to the call and we can usually tell you which case you are in before it ends.
Sources
- Spamhaus Blocklist (SBL): delisting procedure
- Spamhaus Combined Spam Sources (CSS)
- Spamhaus Exploits Blocklist (XBL)
- Spamhaus Policy Blocklist (PBL)
- Spamhaus Domain Blocklist (DBL): FAQs
- Microsoft: remove yourself from the blocked senders list and address 5.7.511 errors
- Gmail SMTP errors and codes (Google Workspace Admin Help)
- Email sender guidelines (Gmail Help)
- Postmaster Tools dashboards (Gmail Help)