Blacklist removal guide

DroneBL removal: how to get delisted

DroneBL is an abuse tracker more than a mail blacklist: it lists IPs behaving as botnet drones, open proxies, brute-forcers and compromised routers. A listing says a machine at your address is (or was) exploitable, so removal starts with finding and fixing that machine.

Published Updated 6 min read
DroneBL, at a glanceChecked
Operator
DroneBL project
Zone
dnsbl.dronebl.org
Lists
IP addresses
Status
Active
Severity
Standard
Removal
request from the affected device / provide IP; operator review: dronebl.org/lookup
Cost
free (undocumented)
Turnaround
undocumented
Auto-expiry
not uniform
Check DroneBL nowdnsbl.dronebl.org

What is DroneBL?

DroneBL is a real-time database of IP addresses observed doing abusable things: participating in botnets, running open SOCKS or HTTP proxies, operating as open DNS resolvers, brute-forcing logins, or serving as compromised routers. Each listing carries a class code describing exactly which behavior was seen, and our checker surfaces that code on the result card.

The list grew out of IRC network defence and remains heavily used there, but its data also feeds general abuse filtering and some mail setups. Reports come from automated detection and from participating networks that submit evidence of drone behavior.

What dnsbl.dronebl.org answersthe A record the zone returns for a listed query
127.0.0.3IRC drone
127.0.0.5Bottler
127.0.0.6Unknown spambot or open proxy
127.0.0.7DDOS drone
127.0.0.8SOCKS proxy
127.0.0.9HTTP proxy
127.0.0.10Proxy chain
127.0.0.11Web page proxying
127.0.0.12Open DNS resolver
127.0.0.13Brute force attacker
127.0.0.14Open wingate proxy
127.0.0.15Compromised router
127.0.0.16Autorooting worms
127.0.0.17Automatically determined botnet

How serious is a DroneBL listing?

For email specifically, moderate: some spam filters incorporate DroneBL as a signal, so a listing can cost you score points. The broader impact is often felt elsewhere, since IRC networks and various services outright ban listed IPs. Either way, the listing is a credible tip-off that something at your IP is compromised or misconfigured, which matters more than the blocking itself.

Why your IP got listed

A botnet-infected device

A machine at your IP was observed acting as a drone: connecting to command-and-control infrastructure or participating in coordinated abuse like DDoS.

An open proxy or resolver

Misconfigured SOCKS/HTTP proxies, VPN endpoints and open DNS resolvers let strangers launder traffic through your address, and DroneBL's probes find them.

A compromised router or IoT device

Consumer routers with default credentials or unpatched firmware are a listing class of their own. On NAT, the router itself is often the culprit.

Brute-force activity

SSH or login brute-forcing observed from your IP earns a dedicated class code, usually meaning an infected machine inside your network is scanning outward.

How to remove your IP from DroneBL

  1. 1

    Read your class code

    Look the IP up at dronebl.org. The listing type (proxy, drone, resolver, brute-forcer, compromised router) narrows the hunt considerably: a proxy code points at services you expose; a drone code points at infected hosts.

  2. 2

    Fix the machine or service

    Close or authenticate open proxies, disable open recursion on DNS resolvers, patch and reset compromised routers (factory-reset plus firmware update plus new credentials), and disinfect botnet-joined machines. Verify from outside your network that the exposed service is really gone.

  3. 3

    Request removal via the dronebl.org lookup

    The lookup page for a listed IP provides the removal-request path. State what was compromised and what you fixed; the maintainers re-check, and unfixed listings are declined or return quickly.

  4. 4

    Confirm and harden

    Re-check after the removal is processed. Then close the class of problem: no default credentials on anything internet-facing, no unauthenticated proxies, automatic updates on routers and IoT devices.

  1. 01Look it updronebl.org
  2. 02Fix the causebefore you ask
  3. 03Request removaldronebl.org/lookup
  4. 04Verifyundocumented

cost: free (undocumented)

The removal path for DroneBL, from the operator's own documentation: undocumented; expiry: not uniform.

How long removal takes

Removal requests are reviewed by the project rather than instant, so expect hours to a few days depending on queue and evidence. Some listing classes also auto-expire after extended clean behavior, but requesting removal after a genuine fix is faster and the norm.

Getting off DroneBL removes a block; it does not restore the trust the providers withdrew while you were listed. If placement does not recover within a couple of weeks, the domain needs a structured re-warm, and the warmup guide for your provider has the ramp and the limits it runs against. Re-running the free blacklist checker monthly stops the next listing getting a head start.

Frequently asked questions

How do I get my IP off DroneBL?

Identify the listing class from the lookup at dronebl.org, fix the exposed or infected device it points to, and submit the removal request offered on the listing page. Removal is free; the maintainers verify the problem is gone before or after clearing it.

Why is my home IP on DroneBL?

Most commonly a compromised router, an IoT device with default credentials, or a malware-infected computer behind your NAT. The class code in the listing says which pattern was seen. Fixing the device and requesting removal resolves it.

Does DroneBL affect email deliverability?

Somewhat: various spam filters use it as a scoring input, so a listing can nudge mail toward spam folders at some receivers. Its heaviest enforcement is on IRC networks and abuse-sensitive services. The compromise it signals is the thing to take most seriously.

Record checked against the operator's site on ; the whole set was last reviewed on . Cells that say undocumented or not found are gaps in the operator's own material, left as they are.

Sources

Every claim above that rests on a third party links to that party's own page. Checked . If something has changed since, tell us and we will correct it.