- Operator
- DroneBL project
- Zone
- dnsbl.dronebl.org
- Lists
- IP addresses
- Status
- Active
- Severity
- Standard
- Lookup
- dronebl.org
- Removal
- request from the affected device / provide IP; operator review: dronebl.org/lookup
- Cost
- free (undocumented)
- Turnaround
- undocumented
- Auto-expiry
- not uniform
- Source
- DroneBL project: DroneBL
What is DroneBL?
DroneBL is a real-time database of IP addresses observed doing abusable things: participating in botnets, running open SOCKS or HTTP proxies, operating as open DNS resolvers, brute-forcing logins, or serving as compromised routers. Each listing carries a class code describing exactly which behavior was seen, and our checker surfaces that code on the result card.
The list grew out of IRC network defence and remains heavily used there, but its data also feeds general abuse filtering and some mail setups. Reports come from automated detection and from participating networks that submit evidence of drone behavior.
| 127.0.0.3 | IRC drone |
| 127.0.0.5 | Bottler |
| 127.0.0.6 | Unknown spambot or open proxy |
| 127.0.0.7 | DDOS drone |
| 127.0.0.8 | SOCKS proxy |
| 127.0.0.9 | HTTP proxy |
| 127.0.0.10 | Proxy chain |
| 127.0.0.11 | Web page proxying |
| 127.0.0.12 | Open DNS resolver |
| 127.0.0.13 | Brute force attacker |
| 127.0.0.14 | Open wingate proxy |
| 127.0.0.15 | Compromised router |
| 127.0.0.16 | Autorooting worms |
| 127.0.0.17 | Automatically determined botnet |
How serious is a DroneBL listing?
For email specifically, moderate: some spam filters incorporate DroneBL as a signal, so a listing can cost you score points. The broader impact is often felt elsewhere, since IRC networks and various services outright ban listed IPs. Either way, the listing is a credible tip-off that something at your IP is compromised or misconfigured, which matters more than the blocking itself.
Why your IP got listed
A botnet-infected device
A machine at your IP was observed acting as a drone: connecting to command-and-control infrastructure or participating in coordinated abuse like DDoS.
An open proxy or resolver
Misconfigured SOCKS/HTTP proxies, VPN endpoints and open DNS resolvers let strangers launder traffic through your address, and DroneBL's probes find them.
A compromised router or IoT device
Consumer routers with default credentials or unpatched firmware are a listing class of their own. On NAT, the router itself is often the culprit.
Brute-force activity
SSH or login brute-forcing observed from your IP earns a dedicated class code, usually meaning an infected machine inside your network is scanning outward.
How to remove your IP from DroneBL
- 1
Read your class code
Look the IP up at dronebl.org. The listing type (proxy, drone, resolver, brute-forcer, compromised router) narrows the hunt considerably: a proxy code points at services you expose; a drone code points at infected hosts.
- 2
Fix the machine or service
Close or authenticate open proxies, disable open recursion on DNS resolvers, patch and reset compromised routers (factory-reset plus firmware update plus new credentials), and disinfect botnet-joined machines. Verify from outside your network that the exposed service is really gone.
- 3
Request removal via the dronebl.org lookup
The lookup page for a listed IP provides the removal-request path. State what was compromised and what you fixed; the maintainers re-check, and unfixed listings are declined or return quickly.
- 4
Confirm and harden
Re-check after the removal is processed. Then close the class of problem: no default credentials on anything internet-facing, no unauthenticated proxies, automatic updates on routers and IoT devices.
- 01Look it updronebl.org
- 02Fix the causebefore you ask
- 03Request removaldronebl.org/lookup
- 04Verifyundocumented
cost: free (undocumented)
How long removal takes
Removal requests are reviewed by the project rather than instant, so expect hours to a few days depending on queue and evidence. Some listing classes also auto-expire after extended clean behavior, but requesting removal after a genuine fix is faster and the norm.
Frequently asked questions
How do I get my IP off DroneBL?
Identify the listing class from the lookup at dronebl.org, fix the exposed or infected device it points to, and submit the removal request offered on the listing page. Removal is free; the maintainers verify the problem is gone before or after clearing it.
Why is my home IP on DroneBL?
Most commonly a compromised router, an IoT device with default credentials, or a malware-infected computer behind your NAT. The class code in the listing says which pattern was seen. Fixing the device and requesting removal resolves it.
Does DroneBL affect email deliverability?
Somewhat: various spam filters use it as a scoring input, so a listing can nudge mail toward spam folders at some receivers. Its heaviest enforcement is on IRC networks and abuse-sensitive services. The compromise it signals is the thing to take most seriously.
Record checked against the operator's site on ; the whole set was last reviewed on . Cells that say undocumented or not found are gaps in the operator's own material, left as they are.