Reputation is an asset.
Scan it like one.
It only takes one listed IP address to bounce your outgoing mail, to hold up a cloud BYOIP onboarding, or to take money off the price of a block when the time comes to sell it. It is for this reason that the reputation tool in the Prefixx portal scans every IP address in your ranges against twelve major blacklists, and shows you in plain terms what is listed, where it is listed, and how you can go about getting it removed again.
Twelve blacklists. Every IP. One health score.
Spamhaus ZEN and Barracuda are the blacklists that most people are already familiar with, and the reputation tool naturally checks both of them as a matter of course. It also checks ten more that have a way of turning up in other people's due diligence, namely SpamCop, SORBS, CBL (Abuseat), UCEPROTECT Level 1, Truncate, PSBL, Mailspike, SpamRATS, JustSpam and Invaluement. Every IP address in a monitored range receives a DNSBL lookup against each of these lists, which works out to twelve answers for every single address. That may seem like more coverage than anyone needs, but we have found over the years that the list you would be tempted to skip is usually the very one that a reviewer decides to consult.
The results are presented at three different levels. At the level of your organization as a whole there is a health score, which is nothing more complicated than the share of checked IPs that came back clean everywhere. Each range then carries a score of its own as well, together with its listed and clean counts and a timestamp that shows when the range was last checked. The third level is the individual IP address, and this is the level where you will find yourself spending your time whenever something has gone wrong. Every address keeps its complete record: which lists were checked, what each of them had to say, the stated reason where the operator publishes one, and a link that takes you straight through to that operator's removal form.
It is also worth knowing that listed IPs are always sorted to the top of every range view, so the triage work begins the moment you open the page. We have seen a single compromised host drag its neighbouring addresses onto several lists over the course of one weekend, and in a situation like that the last thing you want is to go hunting through hundreds of addresses to find the problem ones yourself. The trend charts, which cover 7 to 90 days and are fed by every health snapshot, deserve a mention here as well, because in many cases they will start to sag weeks before the first bounce report ever reaches anyone's inbox.
From scan to clean.
Everything described below can be found under the Reputation section of the portal.
Scan the range
To begin, open a range and start a scan. The scan runs in the background, and because a /24 comes down to 256 IP addresses being checked against 12 separate lists, you should give it a minute or so to do its work; the page refreshes on its own as the results come in. If you are only worried about one particular address, there is no need to wait for a full range scan, since a single IP can be checked on the spot.
Triage the listed IPs
Any IPs that turned out to be listed will have sorted themselves to the top of the list for you. When you open one of them, everything you need has been gathered together on a single page: the lists that flagged the address, the stated reason where the operator provides one, and the last ten checks that were run for that address.
Fix the cause, then delist
It is very important that you fix the underlying cause before you file anything at all. Whatever it was that earned the listing, whether a compromised host, an open relay or a tenant sending out spam, it has to stop first. Once it has genuinely stopped, use the per-list delisting link that the portal provides for each entry. If you file for removal while the behavior is still going on, you can expect to find the address back on the list within a matter of days.
Re-scan and watch the trend
A range becomes scannable again every 8 hours. We would recommend running a fresh scan after a delisting, so that you can see for yourself that the removal has actually taken effect. Once things have settled down again, you can leave most of the day-to-day watching to the 7 to 90 day trend chart.
Clean IPs move faster everywhere.
Reputation reaches well beyond email, although email is where most people first run into it. Cloud providers screen BYOIP ranges before they will accept them, and one listed block can hold up an AWS or Azure onboarding for weeks at a time. Mail providers, for their part, tend to throttle first and ask questions later, if they ask them at all. And when a block is headed for resale or lease, a documented clean history is worth real money, which is one of the reasons reputation is among the core checks in Tixx by Prefixx, our pre-transfer quality control.
Or let us do the delisting
Scanning is included with every Prefixx client account, at no additional charge. For leased ranges on the white-glove tier we go a good deal further and take the delisting work off your plate entirely: our team files the removals, handles the correspondence with the blacklist operators, and confirms that the address has in fact come off the list. You will simply hear from us when the range is clean again.
White-glove details →Reputation: common questions
Each range can be scanned once every 8 hours. The scans are drawn from your organization's daily pool of credits, which holds 25 credits per day by default, is shared with the geolocation and BGP tools, and resets itself at midnight. The reason for the cooldown is a practical one: the blacklist operators rate-limit lookups on their side, and three scans per day for a given range has proven to be more than enough to keep track of a delisting in progress.
No, and this is a mistake that we see rather often. Blacklists list behavior, whether that behavior comes from a compromised machine, an open relay, or a customer sending spam through your network. If you file for removal while the behavior is still going on, most lists will simply re-add the address in short order, and some of them escalate. Once the source has genuinely been dealt with, use the per-list link that the portal gives you. Every operator runs its own process: some offer instant self-service removal, while others involve a human reviewer and a waiting period.
That depends entirely on who happens to be checking you at the time. Spamhaus ZEN and Barracuda carry the most weight with the mail providers, a CBL listing usually points to a compromised host somewhere, and UCEPROTECT Level 1 concerns itself with individual misbehaving IPs. We scan all twelve of them regardless, for the simple reason that you do not get to choose which list a cloud review or a buyer's due diligence will end up consulting. The health score treats all of the lists equally, so a clean result really does mean clean everywhere.
Know your listings before your customers do.
Full-range blacklist scanning, health scores and trend charts are all free for Prefixx clients.
Explore related services
White-Glove Service
IP reputation monitoring, blacklist scanning, geo-location correction, DNS management and abuse processing.
Learn more →Lease IPv4
Short- and long-term IPv4 rentals provisioned in as little as 24 hours with LOA, RPKI and reverse DNS support.
Learn more →BYOIP
Deploy your own or leased IPv4 addresses on bare metal or cloud. We prepare the LOA, ROA and route objects for you.
Learn more →Contact us to discuss your IPv4 needs today
No hidden fees, free consult. A broker replies within one business day.