Back to blog

    July 28, 2026

    What to Do When Your Business Email Domain Gets Blacklisted

    You send a quote to a prospect and it bounces. Then your accountant says she hasn't gotten your invoices in a week. You check your sent folder — everything looks fine on your end. Somewhere out there, your domain has been flagged, and now every email you send is either bouncing or landing in spam. Here's how to figure out what happened, get delisted, and make sure it doesn't happen again.

    First, confirm you're actually blacklisted

    Before you panic, verify the problem. Bounced emails can mean a lot of things — a full mailbox on the recipient's side, a typo in the address, a temporary server issue. Blacklisting has a specific fingerprint: bounce messages that mention "listed on" or reference a specific blocklist like Spamhaus, Barracuda, or SORBS.

    Three free tools will tell you where you stand:

    MXToolbox Blacklist Check (mxtoolbox.com/blacklists.aspx). Type in your domain or sending IP. It checks about 90 major blacklists in a few seconds and shows red for any that have you listed. This is your triage tool — it tells you which lists to worry about.

    Google Postmaster Tools (postmaster.google.com). If you send any meaningful volume to Gmail addresses, you need to have your domain verified here. It shows your domain reputation (High, Medium, Low, or Bad), spam rate, and whether your SPF/DKIM/DMARC are passing. A "Low" or "Bad" reputation is Gmail's version of a blacklist — no formal list exists, but your mail is going to spam by default.

    mail-tester.com. Send a test email to the address they give you and it scores your message out of 10. It flags missing authentication, blacklist hits, spammy content, and misconfigured DNS. Anything below 8 needs work.

    Run all three. You want a complete picture before you start filling out delisting forms.

    Why it happened — the four usual suspects

    Blacklisting isn't random. Something triggered it. Before you request removal, you need to know what, or you'll be back on the list within a week.

    Your site or an email account got compromised. This is the most common cause for small businesses. An attacker gets into a WordPress site or a mailbox and starts blasting spam through it. Your IP or domain gets flagged fast — some blacklists have automated honeypots that catch this within minutes. I worked a case for a Southern California contractor where a self-healing WordPress backdoor a previous contractor missed was pumping out spam posts and outbound email. We killed 115+ spam posts and eradicated the backdoor before their domain reputation got permanently trashed. If your site was hacked, assume it was sending mail you didn't authorize.

    Missing or broken email authentication. If you don't have SPF, DKIM, and DMARC records set up correctly, mailbox providers can't verify that your mail is actually from you. That alone won't always get you on a formal blacklist, but it will absolutely tank your Gmail and Microsoft 365 reputation, which is functionally the same thing.

    Shared IP in a bad neighborhood. If you use a shared sending service (some cheap web hosts, older SMTP providers), you're sharing an IP with hundreds of other senders. One of them spams, everyone on that IP gets penalized. This is why serious senders use dedicated IPs or reputable services like Google Workspace, Microsoft 365, or Postmark.

    Your list practices. Bought lists, old lists you haven't cleaned in years, high bounce rates, or people marking your mail as spam. Complaint rates above 0.3% will get you flagged quickly.

    Fix the cause before you request delisting

    This is the step people skip, and it's why they get re-listed a week later. Blacklists will remove you once, sometimes twice. Get listed a third time and it gets much harder to come back.

    Work through this in order:

    1. Close the infection vector. If your website or a mail account was compromised, that's job one. For a hacked WordPress site: pull it offline or into maintenance mode, scan with something like Wordfence or Sucuri, but understand that automated scanners miss custom backdoors. If mail was going out from a mailbox, force a password reset on every account, revoke all app passwords and OAuth tokens, and check for forwarding rules the attacker left behind — that's a classic persistence trick.

    2. Check your outbound mail logs. In Google Workspace, that's the Email Log Search in the admin console. In Microsoft 365, it's the Message Trace tool. Look for mail your users didn't send — that's your smoking gun and it tells you exactly which account was compromised.

    3. Rotate credentials. Every account on the affected mail platform, not just the one you think was breached. Turn on MFA if it isn't already on. Every mailbox, no exceptions.

    4. Fix your authentication records. If you don't have SPF, DKIM, and DMARC properly configured, do this before requesting removal. A basic SPF for Google Workspace looks like this:

    v=spf1 include:_spf.google.com ~all
    

    DKIM has to be generated in your mail platform's admin panel and published as a TXT record at a specific selector. DMARC starts in monitoring mode:

    v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
    

    Once you have a week of clean DMARC reports showing everything passing, tighten to p=quarantine and eventually p=reject. Skipping this step is the single most common reason small businesses end up back on blacklists.

    Delisting, list by list

    Every blacklist has its own process. Here are the ones that actually matter:

    Spamhaus (SBL, XBL, PBL, DBL). The most consequential blacklist on the internet. If Spamhaus lists you, a big chunk of mail servers globally will refuse your mail. Go to spamhaus.org/lookup, enter your IP or domain, and follow the specific removal link for the list you're on. SBL (Spamhaus Block List) requires you to explain what happened and what you fixed — they read these. XBL is for compromised machines and usually auto-delists once the machine stops sending abuse. PBL is for IPs that shouldn't be sending mail directly. Timeline: hours to several days. Do not resubmit if you get denied — fix what they told you to fix, then try again.

    Barracuda Reputation Block List. Go to barracudacentral.org/rbl/removal-request. Fill in the IP, your contact info, and a description. Usually processed within 12–48 hours if there's no active spam coming from you.

    Microsoft SNDS and JMRP. Microsoft doesn't run a public blacklist the way Spamhaus does, but they filter mail aggressively based on their internal reputation. Sign up for SNDS (Smart Network Data Services) at sendersupport.olc.protection.outlook.com to see how they view your IP. If your mail to Outlook, Hotmail, or Live addresses is bouncing, use the sender support form at that same domain. Delistings from Microsoft can be same-day or can take a week — no promises.

    Google Postmaster. No form, no ticket. Google's reputation is algorithmic. You fix the root cause, keep sending clean mail, and reputation improves over days to weeks. Watch the Postmaster dashboard daily during recovery.

    Smaller lists (SORBS, UCEProtect, etc.). Some are legitimate, some are borderline shakedowns that want you to pay for expedited removal. Ignore the paid ones — most real mail servers don't use them. Focus on the majors.

    Timeline expectations — don't get impatient

    The single biggest mistake I see is people resubmitting delisting requests every few hours because nothing's happening. This flags you as a problem sender and can extend your listing.

    Rough expectations:

    • Barracuda: hours to 48 hours
    • Spamhaus SBL: 24 hours to 3–5 days for first request
    • Spamhaus XBL: often auto-clears within 24 hours once the sending stops
    • Microsoft: unpredictable, often 24–72 hours
    • Google reputation recovery: 1–3 weeks of consistent clean sending

    While you're waiting, send less mail, not more. Cut anything non-essential. High volume during recovery makes things worse.

    What "back to normal" looks like

    You'll know you've recovered when:

    • MXToolbox shows all clear across the major lists
    • Google Postmaster shows Medium or High reputation
    • mail-tester.com scores above 9
    • Your actual test emails to Gmail, Outlook, and Yahoo addresses land in the inbox, not spam

    Keep monitoring for at least 30 days after delisting. Reputation is sticky — bad reputation lingers, and one relapse resets your progress.

    The short version

    Confirm the listing with MXToolbox and Postmaster. Find and close the cause — usually a hacked site or account, or missing authentication. Fix SPF, DKIM, and DMARC before you request removal. Submit the delisting forms for the specific lists that flagged you. Wait. Don't resubmit early.

    If you were listed because your authentication records were missing or broken — which is what I find in maybe two-thirds of these cases — that's the fix that keeps you off the list permanently. I set up SPF, DKIM, and DMARC as a fixed-price productized service, including a week of DMARC report review to make sure legitimate mail isn't getting caught. If you'd rather have that done right the first time instead of guessing at DNS syntax, head over to thewizrdz.io/#security and let's get your mail flowing again.

    Need help with what this post covers? I do this for a living.

    Book a free 15-min site audit