- Operator
- The Spamhaus Project
- Zone
- xbl.spamhaus.org
- Lists
- IP addresses
- Status
- Active
- Severity
- Critical
- Lookup
- check.spamhaus.org
- Removal
- self-service (automated); 24h between tickets: check.spamhaus.org
- Cost
- free
- Turnaround
- automatic once behavior stops
- Auto-expiry
- unpublished
What is Spamhaus XBL?
The Spamhaus Exploits Block List (XBL) tracks IP addresses showing signs of compromise: malware infections, botnet drones, open proxies and hijacked devices. Detections come largely from sinkhole and honeypot traffic, meaning a machine at your IP actually connected to infrastructure that only infected machines talk to.
The XBL absorbed the old CBL (Composite Blocking List) data, so guides that mention cbl.abuseat.org end up in the same place today: the XBL, managed through Spamhaus. On a NAT network, remember the listing applies to the public IP, so any device behind your router could be the culprit, including phones, IoT devices and visitor laptops.
| 127.0.0.4 | CBL: Composite Blocking List |
| 127.0.0.5 | CBL: Composite Blocking List |
| 127.0.0.6 | NJABL: Open Proxy |
| 127.0.0.7 | NJABL: Open Proxy |
How serious is a Spamhaus XBL listing?
XBL data ships inside ZEN, so effectively every Spamhaus-using receiver checks it. Mail from a listed IP is typically rejected outright. Because the signal is "this machine is compromised", receivers treat it seriously, but the flip side is that delisting is quick once the device is clean.
Why your IP got listed
A malware-infected device on your network
Any machine sharing the public IP: a workstation, server, phone or IoT gadget participating in a botnet or spam run without your knowledge.
An open proxy or misconfigured relay
A proxy, VPN endpoint or SMTP relay on your IP that third parties can route traffic through.
A hacked website or CMS
Compromised WordPress plugins and web shells frequently send spam or beacon to command-and-control servers from your hosting IP.
A previous tenant of the IP
On freshly assigned cloud IPs, the listing may predate you. The removal process is the same, and it will hold if your usage is clean.
How to remove your IP from Spamhaus XBL
- 1
Identify the compromised device
Look the IP up at check.spamhaus.org: the listing usually names the malware family and the timestamp of the last detection. Use that to find the offending machine. On NAT, check firewall logs for outbound connections at that time; on a server, audit processes, cron jobs and web apps.
- 2
Clean and lock down
Remove the malware or web shell, patch the vulnerable software, rotate all mail and hosting credentials, and block outbound port 25 for devices that have no business sending mail.
- 3
Self-delist at check.spamhaus.org
XBL removal is self-service from the lookup page. Submit it only after the cleanup, because a re-detection relists you automatically and quickly.
- 4
Re-check within a day
Run the lookup again, and confirm with our blacklist checker. If the IP returns, the infection is still active and step 1 needs another pass.
- 01Look it upcheck.spamhaus.org
- 02Fix the causebefore you ask
- 03Self-service removalcheck.spamhaus.org
- 04Verifyautomatic once behavior stops
cost: free
How long removal takes
Self-service XBL removal takes effect within minutes to an hour, with receiver caches lagging a few hours. If you skip the cleanup, the sinkholes will see the machine again and the listing returns within hours, often flagged as a repeat.
Frequently asked questions
My mail server is clean. Why is my IP on the XBL?
The XBL flags the public IP, not just the mail server. On an office or home NAT, any device sharing that IP can trigger the listing, and on shared hosting a neighbouring compromised site can. The Spamhaus lookup shows the detection time and malware name, which narrows the search considerably.
How do I remove my IP from the XBL?
Find and clean the infected device, then use the self-service removal at check.spamhaus.org. It is free and near-instant. Delisting before cleaning just schedules a relisting.
Is the CBL the same as the XBL now?
Yes. The Composite Blocking List's data and detection infrastructure were folded into the Spamhaus XBL, and old cbl.abuseat.org listings are handled through the Spamhaus checker today.
Record checked against the operator's site on ; the whole set was last reviewed on . Cells that say undocumented or not found are gaps in the operator's own material, left as they are.