Spamhaus SBL, XBL, and PBL are three of Spamhaus's blocklists, and they list IP addresses — SBL for known spam sources, XBL for compromised machines, and PBL for IP ranges that shouldn't send mail directly. There's also the DBL, which lists domains, and that's the one that matters most if you send cold email, because it's the part of your setup you actually own.
Getting a "you're on Spamhaus" bounce without knowing which list leads people to fix the wrong thing. So here's each list in plain terms, who each one is really about, and which ones you can do something about.
The Spamhaus lists, one by one
Spamhaus runs several lists. A mail server usually checks a combined one and tells you "listed on Spamhaus" without saying which. Here's what's underneath:
| List | What it lists | What lands you on it | Whose problem it usually is |
|---|---|---|---|
| SBL (Spamhaus Blocklist) | IP addresses | IPs Spamhaus judges to be spam sources | Your ESP (shared IP) |
| CSS (Composite Sending System) | IP addresses | Auto-detected low-reputation / snowshoe sending | Your ESP |
| XBL (Exploits Blocklist) | IP addresses | Compromised, hijacked, or malware-infected IPs | Your ESP, or a hacked server |
| PBL (Policy Blocklist) | IP ranges | Ranges that shouldn't send mail directly (residential, dynamic) | Your ESP or ISP — policy, not spam |
| ZEN | IP addresses | A combined lookup returning SBL + CSS + XBL + PBL | (whichever underlying list) |
| DBL (Domain Blocklist) | Domains | Domains seen in spam or with bad reputation | You — your sending or link domain |
The single most useful distinction on that table is IP versus domain.
Why the IP lists usually aren't yours to fix
Here's the part that saves cold senders a lot of wasted effort. When you send through Instantly, Smartlead, or any shared-infrastructure platform, the sending IP belongs to that provider, not you. Hundreds of senders share those IP pools.
So if your mail bounces with an SBL, XBL, CSS, or PBL reference, the listed IP is almost always your provider's — which means the provider is the one who has to get it delisted, and there's little you can do beyond reporting it to their support and pausing sending so you're not adding to whatever triggered it. Chasing a Spamhaus removal form for an IP you don't control is time you won't get back.
The exceptions are narrow: you run your own mail server on a static IP (then an SBL or PBL listing is genuinely yours, and the PBL in particular has a straightforward self-service removal at Spamhaus), or an XBL listing points at a server you own that's actually been compromised — in which case the listing is a symptom and the hacked box is the disease.
The one that's actually yours: the DBL
The DBL lists domains, and your sending domain (and the domains you link to inside your emails) are yours. This is the Spamhaus listing a cold email sender can and must act on.
A domain lands on the DBL when it shows up in enough spam, hits spam traps, or otherwise earns a bad reputation. Because it's tied to the domain rather than a shared IP, a DBL listing follows you across every mailbox and every campaign on that domain — and it doesn't get diluted by pool-mates the way an IP listing does. That's exactly why it hurts more and why it's the priority.
If your domain is on the DBL, the fix isn't a form — it's finding and killing the root cause (usually a dirty list or a spam-trap hit), then requesting removal. Rushing the removal request without fixing the cause earns a re-listing that's harder to clear. The full order of operations is in the guide to fixing a blacklisted domain.
How to tell which list you're on
Two quick checks:
- Look up the specific address. Enter your sending domain, and your sending IP, at check.spamhaus.org. It tells you which list, if any. The step-by-step version is here.
- Read the bounce. Rejection messages often name the list directly — "listed on Spamhaus DBL" or a ZEN reference with the IP. That tells you domain versus IP before you even open a browser.
Or run the domain through the free deliverability checker, which checks Spamhaus and SURBL alongside your SPF, DKIM, and DMARC in one pass — useful because authentication gaps and listings tend to show up together.
What to do once you know
- DBL (your domain): fix the cause, then request removal. This is the one that's on you. Full removal steps.
- SBL / CSS / XBL / PBL on your ESP's IP: pause sending, report it to your provider, and let them handle the pool. Switching domains won't help — it's the shared IP.
- PBL / SBL on your own static IP: use Spamhaus's self-service removal, and make sure you're sending through a proper mail server, not direct from a dynamic address.
Knowing which list you're on turns "I'm blacklisted, panic" into a specific, sized problem. And the best position is not needing the lookup at all — catching the bounce-rate creep and reputation slip days before a listing happens, which for an agency watching many sending domains is what tools like ColdOps monitor for across every client workspace at once.
Frequently asked
What's the difference between Spamhaus SBL, XBL, and PBL?
Why is my IP on the Spamhaus PBL?
What is Spamhaus ZEN?
Which Spamhaus list matters most for cold email?
Keep reading
Email Deliverability Monitoring Tools: What to Watch
What email deliverability monitoring tools track, the signals that matter, when manual checking breaks down and how to choose a tool that fits your sending setup.
ReadDeliverabilityShould you turn off open tracking in cold email?
Should you turn off open tracking in cold email? For most campaigns, yes. How the pixel costs placement, what you lose, and what to measure instead.
ReadDeliverabilityGoogle Retired Domain Reputation in Postmaster Tools
Google removed the Domain and IP Reputation dashboards in Postmaster Tools v2. Here is what replaced them, the arithmetic that decides whether your domains report at all, and what to watch instead.
Read