ZapBL: A List of Opinions, and How Yours Clears
ZapBL says it does not block email and is not calling anyone a spammer. What actually gets listed, why three neighbours can catch you, and the four-rung removal ladder.

ZapBL is a DNS blocklist whose operator describes it as a list of opinions rather than a blocking mechanism. Listings come only from mail reaching an administrator address, trap or catchall, with at least one level of review. Third-party reports are refused, and a slash 24 escalates once three listings accumulate inside it.
Key takeaways
- The operator states that ZapBL does not block email, is not calling anyone a spammer, and that any blocking is the receiver's own decision.
- Third-party reports are refused under any circumstances, so whatever caused a listing arrived in an administrator's own mailbox.
- Escalation to the surrounding slash 24 begins at three listings inside it, which is how a sender with no listing of their own ends up in a listed range.
- Removal runs as a ladder from automatic expiry through a self-service option to a written case, and only the registered whois contact for the block can file the last one.
Reviewed and updated September 2, 2026
A hosting provider's knowledge base tells its customers that ZapBL is a dead list nobody maintains, so nothing needs doing. The operator's own site serves a current policy page, a working lookup, two named zones and a footer carrying this year. Both of those were read on 2 September 2026, and only one of them is first-hand about the service.
That disagreement is the first thing to settle, because it decides whether the row on your report is worth an hour.
What ZapBL is, in its own words
The operator's framing is unusually precise and it is the whole basis for reading a listing correctly. Its home page says ZapBL "is a DNS-based realtime blocklist" and then immediately narrows what that means: ZapBL "does NOT block email", and is "merely a list of opinions of the administrators as to where they do not want to receive email from".
The policy page repeats the point in the first person plural. ZapBL and its administrators, it says, "are NOT calling anyone spammers", and are saying only that mail matching their definition of spam arrived from certain places and is no longer wanted. The last clause is the operative one: "If anyone is using our list to block email, it's their choice."
For the definition of spam itself the operator does not invent one. It quotes the technical definition published by Spamhaus, which turns on two conditions being true together: the message is equally applicable to many other potential recipients, so the recipient's identity and context are irrelevant, and the recipient has not verifiably granted deliberate, explicit and still-revocable permission for it to be sent.
That definition is worth sitting with if you run cold outbound, because the second half of it is the half a cold email fails by design. What keeps a targeted, relevant, single-message campaign out of that definition in practice is the first half: a message that is genuinely about this company and this person is not equally applicable to many other recipients. The house position on why that distinction is the whole game sits in what separates a cold email from spam.
What gets listed
The policy page is specific about how entries are created and by whom.
A listing follows when an administrator address receives spam, and the operator says those addresses are not only personal mailboxes but also dedicated spam traps and catchall addresses. Listings are created either manually by an administrator or by an automation under an administrator's direct control, with at least one level of review and confirmation.
Three further rules matter to a sender.
No third-party listings, at all. The operator writes that ZapBL "does NOT accept 3rd party listings under any circumstances". Nobody can report you onto this list. Whatever caused the listing arrived in an administrator's own mailbox.
Backscatter is mostly excluded, with one exception. The operator says its administrators will avoid listing backscatter, but that a system replying to spam or viruses with a rejection report announcing that it detected spam or a virus will be listed, on the reasoning that almost all such mail carries a forged sender and the reply only reaches an uninvolved third party. That mechanism is the same one worked through in bounces for mail you never sent, read from the other side.
Domains can be listed as well as addresses. The operator says domains advertised in spam may be listed, and that its administrators will make every effort not to list shared hosting domains.
Escalation, which is where a clean sender gets caught

The policy publishes a threshold, and it is small. Escalations happen when a number of listings inside the same slash 24 is reached, and the operator states it plainly: "The threshold for a /24 is currently 3 (three)." It adds that escalations expand gradually with further spam, up to the size of the block recorded in the whois allocation, and that listings for supplementary services, meaning addresses providing only web, mail-exchange or DNS services to a sender, do not count toward the threshold.
Three listings inside a slash 24 is a low bar in a shared hosting range. It is the reason a sender who has never had a message reach an administrator address can still find the range around them listed.
- Names an address an administrator received unwanted mail from
- Can escalate to the surrounding block once three listings accumulate in a slash 24
- Supplementary service addresses do not count toward that threshold
- A single response code, so the answer says listed and nothing more
- Names a domain advertised inside a message rather than the sender of it
- The operator says it tries not to list shared hosting domains
- Reaches your sending domain, your links and your tracking host alike
- Survives every change of sending infrastructure, because it is a name
Finding out whether you are listed
Use the operator's lookup rather than an aggregated row, because it is the live answer and because it is also where a self-service removal option appears when one is available.
The mechanics are ordinary and the operator publishes them. The address zone is queried by reversing the octets of the address and prefixing them to the zone name, exactly as every address-based list works. The domain zone is queried by prefixing the name itself. The operator says there is a single response code in use for the address list, so the answer carries no sublist information: a listing is a listing, and the reason has to come from the lookup rather than from the code.
Two things worth knowing before automating anything against it. The operator's statistics page sits behind a captcha, so there is no scriptable volume figure and none is claimed here. And the usage page publishes free-use terms with a guidance figure: above roughly a hundred thousand queries a day the operator suggests running a local mirror and asks to be contacted, while imposing no restriction on organisation size or user count.
Removal, which is a ladder rather than a form

The operator publishes four rungs and they are worth knowing in order, because most senders never need to climb past the first.
Expiry. In the operator's own words, "Most listings expire after a certain period of time." It adds that an administrator may set a flag to prevent a particular listing from expiring.
Self-service. Some listings can be removed through the lookup tool, and the operator says the removal option appears there when it is available. That is the cheapest route and it costs one lookup to discover.
A written case. Where a listing does not expire, shows no removal option, or cannot be publicly delisted, the operator asks for a motivation submitted through its contact route. It adds a condition that decides who can send it: communications are accepted only from the registered contact for the address block as recorded in the whois information, and an end user is told to have their internet service provider do it for them.
Express delisting. The operator says this is available with manual review, through the same contact route. It publishes the existence of the option rather than terms, and nothing further about it is asserted here.
That whois condition is the one to read twice. A sender on shared or provider-owned infrastructure is not the registered contact for the block, which puts the third rung out of reach and makes the conversation one to have with the provider. The same constraint appears on other range-oriented lists, including the UCEPROTECT Level 2 allocation list.
- Step 1Wait for expiry
Most listings expire after a period, unless an administrator has flagged one not to
- Step 2Try the lookup
A removal option appears in the lookup tool when one is available for that entry
- Step 3Submit a motivation
For listings that do not expire, show no option, or cannot be publicly delisted
- Step 4Prove you can ask
Only the registered whois contact for the block is accepted, so an end user goes through their provider
- Step 5Express delisting
Offered through the same contact route, with manual review
What it means for a cold outbound programme
Take the dead-list claim first, because it is testable and the answer changes the rest.
A hosting provider's knowledge base and several pages repeating it say the service is unmaintained. Against that, the operator's own site served every path tried on 2 September 2026, publishes a policy carrying a current copyright range, and runs a lookup. Independent blocklist directories report the zone as active. That is not proof of a maintained listing pipeline, and nothing here claims one, but it is enough to say that treating the row as automatically meaningless rests on a third-party assertion rather than on anything the operator publishes.
The practical order is unchanged by any of that.
Check at the operator and take the self-service option if it appears. One lookup answers both whether you are listed and whether you can clear it yourself.
Establish whose block it is. If you send through a provider, you are not the whois contact, the escalation threshold means the listing may be about neighbours, and the useful action is a conversation about address space rather than a delisting request.
Weight the row against your own bounce strings. The operator says outright that it does not block email and that any blocking is the receiver's decision. Whether receivers your prospects sit behind have made that decision is answerable from refusals you have actually received, and the order to work a multi-list report in puts that test first.
The architecture underneath is the same one that makes any of these rows cheap. Separate sending domains, one purpose per domain, links and tracking hosts on names you control, and enough spare warmed capacity that an address inside a listed block is left rather than argued over. That set is worked through in email domain reputation.
The short version

ZapBL describes itself as a list of opinions rather than a blocking mechanism, states that it is not calling anyone a spammer, and says explicitly that using the list to block mail is the receiver's own choice. Its definition of spam is quoted from Spamhaus and turns on a message being equally applicable to many recipients and lacking verifiable permission.
Listings come only from mail reaching an administrator address, trap or catchall, with at least one level of review, and the operator refuses third-party reports under any circumstances. Escalation to the surrounding slash 24 begins at three listings inside it, which is how a sender with no listing of their own ends up in a listed range.
Removal runs as a ladder: most listings expire, some can be cleared through the lookup tool, and anything beyond that needs a written case from the registered whois contact for the block, with express delisting offered under manual review. A sender on provider infrastructure is not that contact.
The claim circulating in hosting knowledge bases that the list is dead is a third-party assertion. The operator's own surfaces served on the day this was written, and independent directories report the zone as active.
If you would rather send from address space chosen for outbound, on domains and tracking hosts you control, we plan the first campaign for free.
The self-description, the spam definition the operator attributes to Spamhaus, the listing criteria, the refusal of third-party listings, the backscatter exception, the slash 24 escalation threshold, the two zone names, the single response code, the free-use terms and the four-rung delisting ladder are taken from zapbl.net's own home, policy and usage pages, fetched 2 September 2026. The statistics page is behind a captcha and no volume figure is claimed. Verify current list behaviour with the operator before relying on it.
Frequently asked questions.
Frequently asked questions- Is ZapBL still maintained?
- Hosting knowledge bases circulate a claim that the list is dead. Against that, the operator's own site served every path tried on 2 September 2026, publishes a policy page carrying a current copyright range, and runs a lookup, while independent blocklist directories report the zone as active. That is not proof of a maintained listing pipeline, but the dead-list claim rests on a third-party assertion rather than on anything the operator publishes.
- How do I get delisted from ZapBL?
- Start at the operator's lookup, because a self-service removal option appears there when one is available for that entry. Most listings expire on their own. Anything that does not can be appealed with a written motivation, but the operator accepts communications only from the registered whois contact for the address block, so a sender on provider infrastructure has to go through the provider.
- Why am I listed when nobody reported me?
- Nobody could have. The operator refuses third-party listings under any circumstances, so the mail that caused the listing reached an administrator address, a dedicated trap or a catchall directly. The other possibility is escalation: three listings inside the same slash 24 pull the surrounding block in, which can name an address that never sent anything.
- Does ZapBL list domains as well as IP addresses?
- Yes. The operator publishes an address zone queried by reversing the octets and a domain zone queried by prefixing the name. Domains advertised inside spam may be listed, though the operator says it makes every effort not to list shared hosting domains. A domain listing reaches your sending domain, your links and your tracking host alike.
About the author.
Tim Carden is CMO / CTO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Studied at McGill University.
Tim Carden · CMO / CTO
Connect on LinkedIn →Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
Backscatterer Blacklist: Two Causes, One Four-Week Clock
Backscatterer lists addresses for misdirected bounces and for sender callouts, never for spam. The listing expires after four weeks, so the work is finding the system.
Suomispam Reputation: Read the Code Before You File
Suomispam publishes four zones and four listing classes, and the response code names which one you have. Two pieces of common delisting advice will not move it.
Woody's SMTP Blacklist: The Delisting Route Refuses
Every page about this list tells you to file a delisting request. Measured on 2 September 2026, the operator's removal endpoint returned HTTP 403.
UCEPROTECT Level 2: Listed for the Neighbours
Level 2 lists allocations rather than senders. The escalation thresholds, the provider grace windows, and why the free removal is automatic and the paid one optional.
ivmSIP and ivmSIP/24: Which One Listed Your IP
invaluement publishes two IP lists and the search results merge them. One names your address, the other names the range around it, and only one is yours to fix.
RATS-Dyna: The Listing Your Reverse DNS Caused
RATS-Dyna lists addresses whose reverse DNS looks residential. The operator says a sender who does not run their own mail server should never need to delist.