Skip to content
Real-time DNS Blocklists | Commercial (Data Query Service)

Real-time DNS Blocklists | Commercial (Data Query Service)

www.spamhaus.com June 15, 2026

Seamlessly integrate industry-leading threat intelligence data into your email infrastructure, and immediately protect against the vast bulk of spam and other email-borne threats at the SMTP gateway.

Block more than 99% of malicious email.

Real-time updates with low-false positive rates.

Easily integrated into your existing infrastructure.

Access real-time DNSBL data covering IPs, domains, and hashes (including malware files, cryptowallets, email addresses and URLs) to protect your email infrastructure, wider network, and users.

Why are there two different names for the data?

Our datasets have been supporting users for a very long time. With new users requesting our support, the dataset names are being updated for clearer understanding. We’re documenting two names, for now, to best support all users.

(Authentication Blocklist - AuthBL)

IP addresses known to host bots using stolen credentials or brute-forcing SMTP-AUTH (and other authentication protocols), helping detect and mitigate ongoing abuse from malicious login attempts.

(Exploits Blocklist - XBL)

(Combined Spam Sources - CSS)

Highly Malicious Networks

(Don't Route Or Peer - DROP)

Low Reputation Domains

(Domain Blocklist - DBL)

Low Reputation Resources

(Hash Blocklist - HBL)

Malicious network ranges

(Spamhaus Blocklist - SBL)

Non-mail emitting IPs

(Policy Blocklist - PBL)

Zero reputation domains

(Zero Reputation Domains - ZRD)

Querying DNSBLs in real-time has many applications beyond protecting your email infrastructure, wider network, and users from email-borne threats. They can also be used to ensure compliance.

Spamhaus sets the gold standard in DNSBLs for email protection. Trusted by the world’s largest mailbox providers, our data protects billions of users every single day.

Access affordable, effective protection for your email infrastructure and users, utilizing real-time threat intelligence data, with industry-leading low false positive rates.

Save on associated remediation costs and protect your reputation.

Stop a large amount of unwanted email before it hits your network, saving on processing and storage costs.

With less time focused on email management, there is more time available for other issues.

Our Domain datasets and Non-mail emitting IPs (Policy Blocklist) can protect against threats before they are seen in the wild.

Gain actionable insights from binary data covering IPs, domains, and other internet resources. Determine whether an IP or domain is listed to ensure outbound email compliance and protect your sending infrastructure, resource reputation, wider network, and users.

Proactively scan outbound emails for malicious URLs to prevent the spread of harmful content and protect both senders and network reputation.

Real-time signals that help teams identify and resolve issues before they impact compliance or deliverability.

Simply complete the form and submit. No credit card or payment details are required for the free trial.

You’ll receive an email asking you to verify your address. If you haven’t already, you’ll be prompted to create an account.

Once verified, log in to the Customer portal to view your API key and follow the setup instructions provided in the manual.

If you have any questions, please add them to the box on the form. Once you gain access to the data, technical support is available via our Customer Portal.

How can I purchase the data?

During your free trial, you can request a quote in the Customer Portal to get the subscription cost based on your setup. You can also enable trials of additional datasets via the Customer Portal.

Set up is straightforward, using your existing email infrastructure.

Our Real-Time DNSBLs can be used with most open-source tools, and we have specially designed plug-ins for SpamAssassin and Rspamd . Alternatively, it can be integrated with your existing anti-spam platforms.

Go to Integrations for Real-Time DNS Blocklists for more information.

This ease of integration keeps costs to a minimum, with no additional hardware required.

Full set up details to access the Real-Time DNS Blocklists are on our documentation page .

Pricing is based on users and query volume, with final costs provided after the trial. Alternatively, please our sales team .

Get a free 30-day trial to query Spamhaus’ Real-Time DNSBLs. No credit card details required.

Ready-made integration, pre-configured in the Halon interface to provide instant email protection. Available to any Halon Protect customer.

Enable the pre-configured settings, to gain an additional and immediate layer of security protection. Available to any MDaemon® Email Server customer.

Ready to go integration, with simple configuration enriching the EPG product for additional Microsoft Exchange Server protection. Available to any Messageware (EPG) customer.

Purpose-built plug-in available on GitHub to classify email and block spam based on an analysis of headers and message body – compatible with several MTAs.

Purpose-built plug-in available on GitHub to classify email and block spam based on an analysis of headers and message body – compatible with several MTAs.

Alcides Zanarotti Junior

Director of Technology, UOL

Email administrators and email engineers running their own mail transfer agent (MTA) or email infrastructure.

You may qualify for a non-commercial account to query the DNSBLs, free of charge – you can check if you meet the usage criteria for a free account here . To understand what’s included in the free service, see this comparison table .

First, incoming email sent from a listed IP address can be dropped at SMTP connect, saving storage and processing costs. You have the choice to block, accept, or quarantine messages according to your company policy.

When an email is blocked, the sender will immediately receive a notification, ensuring that emails do not lie unread in junk folders for weeks.

After blocking unwanted emails during the SMTP transaction, the remaining traffic can then be filtered by content utilizing our low reputation domains, low reputation resources, and zero reputation domains datasets.

This staged process is considered best practice:

Read “ Where to apply blocklists for effective email filtering ” for further details.

Incremental synchronization of binary and contextual datasets to local servers, including access to our entire binary DNS blocklist data. Efficiently transfer data by only copying changes between the source and destination.

Integrate context-rich metadata relating to IP and domain reputation to enhance existing data feeds, or consume as an independent data source. Gain additional intelligence to monitor, assess and remediate as required.

Access our wide variety of DNS Response Policy Zone files to block or redirect access based on your appetite for risk. We provide the data, you set the terms, configurable to your business’ needs and company requirements/policies.

Cyber Threat Intelligence