Sign up

UCEPROTECT Delisting: Do Level 2 and 3 Listings Matter?

UCEPROTECT Delisting: Do Level 2 and 3 Listings Matter?

You run a blocklist check on your sending IP, and a monitoring tool lights up red:

Your IP 203.0.113.45 is listed on UCEPROTECTL3. Your IP 203.0.113.45 is listed on dnsbl.sorbs.net.

Before you do anything else: check your bounce logs. If no mailbox provider is actually citing either of those lists in a rejection message, you may have a monitoring problem rather than a deliverability problem.

This is the part most blocklist articles get wrong. They treat every listing as an emergency requiring immediate action. In reality, blocklists vary enormously in how much they matter. A Spamhaus SBL listing will cost you real inbox placement at Gmail, Outlook, and Yahoo. A UCEPROTECT Level 3 listing frequently costs you nothing at all — and a SORBS listing in 2026 definitively costs you nothing, because SORBS has been switched off since June 2024.

What UCEPROTECT Is and why you arelListed

UCEPROTECT-Network is a Swiss-operated DNSBL that runs three separate lists at different levels of aggregation. The distinction between them is the single most important thing to understand, because two of the three levels list you for other people’s behavior.

Level 1 — individual IP addresses

Level 1 (dnsbl-1.uceprotect.net) lists individual IPs, most often for hitting UCEPROTECT’s spamtraps. Spamtraps are not the only trigger: UCEPROTECT also lists at Level 1 for forwarding that breaks SPF, falsified SRS, port scans or attacks against their own servers, and — importantly — manual listing at the discretion of any UCEPROTECT-Orga member. So Level 1 is the level most likely to be a statement about you rather than your neighbours, but that manual-listing route means it is not automatically a verdict on your sending either. Per UCEPROTECT’s own policy, every Level 1 IP expires automatically seven days after the last spam from it hits their traps, free of charge.

Level 2 — the neighborhood

Level 2 (dnsbl-2.uceprotect.net) does not list IPs for sending spam. It lists IP allocations once enough Level 1 listings (“impacts”) accumulate inside that allocation. The threshold is not a fixed /24 — it scales with the size of the allocation: an allocation smaller than a /27 lists on a single impact, a /26 on two, a /25 on three, a /24 on four, and so on upward through /10 and beyond. UCEPROTECT therefore lists smaller allocations far more easily than large ones. Your IP can be spotless. If enough of your rack neighbors are not, the whole allocation goes on Level 2 and you go with it.

Level 3 — the entire ASN

Level 3 (dnsbl-3.uceprotect.net) escalates the same logic to the Autonomous System. Two conditions must be met together: the ASN’s SPAMSCORE must reach 50 or more and the ASN must have accumulated at least 50 Level 1 impacts within the last seven days, where SPAMSCORE is (Level 1 impacts ÷ total IPs announced by the ASN) × 100,000. When both are true, UCEPROTECT lists every IP that ASN announces. For a large hosting provider or cloud platform, that is potentially millions of addresses, listed because of a few hundred bad actors somewhere else on the network.

This is the crux, and it is worth stating flatly: a UCEPROTECT Level 2 or Level 3 listing is not evidence that you did anything wrong. It is evidence that you share infrastructure with someone who did. You can have perfect list hygiene, flawless authentication, and zero complaints, and still land on L3 the day you provision a server at a large host.

The paid delisting question

This needs to be handled precisely, because there is a lot of loose accusation online and the facts are more specific than the rhetoric.

What is documented on UCEPROTECT’s own site: listings expire automatically and for free once the triggering abuse stops — seven days after the last spamtrap hit for Level 1, and automatically for Level 3 “as soon as they are no longer matching Listing criterias of Level 3.” Alongside that free expiry, UCEPROTECT offers an optional express delisting for a fee, for listees who do not want to wait. UCEPROTECT describes this as “an optional offer only” — though it is worth knowing that the sentence does not stop there. It continues, in capitals, to warn listees that they forfeit their right to express delisting if they characterise the arrangement as blackmail, extortion or a scam, and it does so in deliberately crude and hostile terms. Anyone weighing the “optional offer” framing should read the full sentence on UCEPROTECT’s own site rather than the first clause alone.

What UCEPROTECT actually charges

UCEPROTECT charges 89 CHF per IP (Level 1), 249 CHF per allocation (Level 2) and 449 CHF per ASN (Level 3). The figures are published only as images to defeat scraping; they have been unchanged since 2022, but confirm on their site before acting. Express delisting is also excluded in several cases, including ASNs exceeding thresholds by 10x, providers it places in what it calls the “TOP 5 OF THE WORST SPAMMER HOSTERS,” and parties it suspects of collaborating with spammers.

What the industry says: RFC 6471

How the industry regards it: RFC 6471, a 2012 IRTF Anti-Spam Research Group document, explicitly discourages charging the listed party for removal. It’s informational, not a standard — a statement of good practice, not a binding rule. Its “Conflict of Interest” section says paid delisting from a negative-connotation DNSBL “steers perilously close to notions of extortion, blackmail, or a ‘protection racket’,” that such lists “MUST not charge fees… for delisting,” and recommends against using ones that do. The distinction it draws: charging users for access is normal; charging the listed party for removal is the problem.

The paid-removal model has drawn published criticism from vendors and hosts in the email industry — security vendor TitanHQ and hosting provider InMotion Hosting have both advised readers to treat UCEPROTECT listings with scepticism and to avoid paying for removal. Those are stated opinions from interested parties rather than neutral findings, and should be read as such. By contrast, Spamhaus states plainly that “there is never any charge or fee associated with removing any Spamhaus listing,” and that any offer to remove a Spamhaus listing for a fee is a scam.

The bottom line: don’t pay

The practical recommendation: do not pay. For a Level 1 listing, fix the sending problem and wait out the seven days. For Level 2 or Level 3, paying is doubly pointless — you would be paying to remove a listing you did not cause, on a range you do not control, which UCEPROTECT can relist the moment another tenant on the same network misbehaves.

SORBS: Verify before you panic

SORBS (Spam and Open Relay Blocking System) ran for over two decades and maintained 18 separate zones under *.dnsbl.sorbs.net and *.rhsbl.sorbs.net — open relay, open proxy, dynamic IP ranges, spam.dnsbl.sorbs.net, badconf.rhsbl.sorbs.net, the nomail zones, and a widely misunderstood backscatter zone that listed servers sending bounce messages to forged return addresses.

Proofpoint acquired SORBS in 2011 and ran it as a free service. On June 5, 2024, Proofpoint decommissioned it. Proofpoint emptied all 18 zones.. In a statement given to The Register on 7 June 2024, Proofpoint said that “the decision to sunset a product is never an easy one,” and that “SORBS was decommissioned on June 5, 2024, and the service no longer contains reputation data.” Those quotes come from that press statement rather than a Proofpoint publication — proofpoint.com’s own SORBS product page now returns a 404. As of this writing there has been no relaunch.

The shutdown has since gone further than empty zones. Today sorbs.net has no nameservers at all: queries against any SORBS zone return NXDOMAIN rather than a result. The domain itself remains registered through MarkMonitor until January 2027, but nothing answers behind it.

Two consequences follow, and both are actionable:

  • If a checker still reports you as SORBS-listed, the checker is wrong. Because the zones now return NXDOMAIN, a correctly written checker will report not-listed or a lookup error — never “listed.” Any tool still showing a SORBS listing is displaying a cached or hardcoded result from before the shutdown. This is a false positive. Ignore it.
  • If your own mail server still queries any sorbs.net zone, remove it from your configuration. You are adding a DNS lookup to every inbound connection for a service that returns nothing.

The general lesson: blocklists die, change hands, and change policy. Verify a list’s current operational status before you spend an afternoon on a delisting request.

How to confirm a listing is actually hurting you

The question is not “am I listed.” Anyone sending at volume is listed somewhere. The question is “is a mailbox provider I actually send to consulting this list, and is my mail being rejected because of it.”

That is answerable from your bounce logs in about five minutes.

Grep your bounce data for the list name

Real DNSBL rejections almost always name the list in the SMTP response. Search your bounce logs for these strings:

  • uceprotect — an actual L1/L2/L3-driven rejection will typically include a uceprotect.net URL
  • spamhaus, sbl, css, xbl, pbl — often with an SBL reference number
  • barracuda, b.barracudacentral.org
  • spamcop, bl.spamcop.net
  • invaluement, ivmSIP, ivmURI
  • sorbs — if you find recent hits here, a receiving server has stale configuration; the list is empty

Also look at the volume and destination of matching bounces. Ten rejections a week from small self-hosted domains is noise. Thousands of rejections from a provider that represents a meaningful share of your list is a problem.

Check whether it correlates with your actual placement

If your inbox placement at Gmail, Microsoft, and Yahoo is stable, your complaint rate is flat, and Google Postmaster Tools shows normal reputation — but a checker says UCEPROTECTL3 — the listing is not affecting your business. Major consumer mailbox providers run their own internal reputation systems as the primary signal. Those matter far more than any public DNSBL.

Blocklist impact reference table

Save this. It is the fastest way to triage any listing alert.

Blocklist What it lists Who consults it Real-world delivery impact Removal process Charges to delist?
Spamhaus SBL / CSS IPs and ranges linked to spam sources Very widely deployed — including major consumer and enterprise filters Severe. Treat as an incident Self-service or manual review at check.spamhaus.org; ISP must request for some listings No — free, explicitly
Spamhaus XBL Compromised/exploited hosts, botnet traffic Same broad deployment as SBL Severe. Usually means a machine is infected or relaying Self-service after remediation No
Spamhaus PBL Ranges the owner says shouldn’t send direct mail Broad Moderate. A policy statement that the range shouldn’t send direct-to-MX; trivially fixed. Clear it last if you are also on SBL, CSS or XBL Self-service, or ask your provider to correct the range designation No
Spamhaus DBL Domains, not IPs Broad Severe. Survives an IP change — you cannot outrun it check.spamhaus.org only No
Barracuda BRBL Individual IPs Any mail server that registers to query the public zone; most are not Barracuda customers. Significant in mid-market and enterprise Moderate to high if your audience is business inboxes Manual form at barracudacentral.org/rbl/removal-request; documented processing within 12 hours with a valid explanation No
SpamCop (bl.spamcop.net) IPs, from user reports and traps Moderate deployment; some providers use it as one input among several Low to moderate. Highly transient by design Automatic expiry, typically 24–48h with no new reports No
Invaluement (ivmSIP / ivmURI) IPs and URIs; strong on snowshoe spam Corporate and appliance filters; subscription-based access Moderate. Well-regarded, low false-positive reputation Contact via invaluement.com No fee to delist (access is paid, which is normal)
SURBL / URIBL Domains and URLs inside message bodies — not sending IPs Broad, as a content signal Moderate to high. Often a link domain or shortener you don’t control Self-service lookup and removal request per list No
UCEPROTECT Level 1 Individual IPs hitting their spamtraps Limited. Small self-hosted servers and some regional filters Low. A genuine signal worth investigating, but rarely the cause of real volume loss Auto-expires 7 days after last trap hit, free Optional paid express removal offered
UCEPROTECT Level 2 Whole IP allocations (/24 and similar) Very limited Very low. Lists you for neighbors’ behavior Clears when the range’s L1 listings drop below threshold Optional paid express removal offered
UCEPROTECT Level 3 Every IP in an entire ASN Very limited. Widely filtered out or ignored by mainstream operators Negligible for most senders. Cannot be resolved by you Only the ASN operator can act; auto-clears when the ASN’s score drops Optional paid express removal offered
SORBS (all 18 zones) Formerly: open relays, proxies, dynamic ranges, backscatter Nobody — decommissioned June 5, 2024 None. Zones are empty N/A — no delisting exists or is needed N/A
Proofpoint PDR (Dynamic Reputation) IPs, by dynamically scored sending reputation Sites filtering with Proofpoint; publicly queryable as a DNSBL, not internal-only Moderate to high if you send to enterprise inboxes Self-service lookup and removal request via Proofpoint’s IP removal portal No
Provider-internal reputation (Google, Microsoft, Yahoo) Your IP and domain sending behavior The provider itself — this is the real gatekeeper Highest of anything on this list Behavioral. Fix engagement and complaints; some offer a mitigation form No

Deployment breadth for smaller lists is inherently hard to measure — no operator publishes its subscriber list. The ratings above reflect general industry consensus, not a measured survey.

How to Decide Whether to Act, and What to Do

Work through this in order. Most listings resolve at step 2 with no action required.

Step 1: Identify which list and which level

“UCEPROTECT” alone is not a diagnosis. L1 is about you; L2 and L3 are about your neighborhood. Get the specific zone before deciding anything.

Step 2: Check the bounce logs for the list being cited

Grep as described above. If the list is not appearing in real rejection strings, stop here. You are not being blocked by it. Do not submit a delisting request, do not pay a fee, do not rebuild your sending infrastructure. Note it and move on.

Step 3: If it is a Spamhaus, Barracuda, SURBL, or Invaluement listing, treat it as real

These correlate with actual rejections. Follow the standard order — stop the bad traffic, find the root cause, clean the list, then request delisting. Requesting removal while the triggering behavior continues gets you relisted immediately and burns credibility for future requests. Spamhaus in particular evaluates whether the underlying problem was solved, not whether you asked nicely.

Step 4: If it is UCEPROTECT L1, fix the cause and wait

A Level 1 listing means you hit a spamtrap. That is worth knowing even if the listing itself is low-impact — it usually points to a stale segment or purchased data. Suppress the affected segment, verify the list, and let the seven-day expiry run.

Step 5: If it is UCEPROTECT L2 or L3, contact your provider — not UCEPROTECT

You cannot remove yourself from a listing that covers your host’s entire allocation or ASN. Open a ticket with your hosting provider or ESP, tell them the range or ASN is listed, and let them decide whether it warrants action on their side. Most large providers already know and have made a considered decision not to engage. That is a legitimate position, not negligence.

If L2/L3 listings genuinely correlate with rejections in your logs — rare, but check rather than assume — the real fix is moving to an IP range with better neighbors, which again is a conversation with your provider.

Step 6: Fix your monitoring

If your alerting tool paged you for a dead list or a Level 3 listing, tune it. Alerts that fire on things you cannot and should not act on train you to ignore alerts that matter. Configure your monitor to page loudly on Spamhaus and Barracuda, and log quietly on everything else.

How to Prevent the Listings That Actually Matter

Spamtraps drive both Spamhaus SBL and UCEPROTECT L1, so one set of habits covers both. The two worth calling out specifically here:

  • Recycled traps are old real addresses. Purchased data and unsunset contacts are how you hit them. Suppress after 90 days of non-engagement at business domains, 180 at consumer domains, and verify any list that is imported or older than six months.
  • Do not send backscatter. Reject invalid recipients during the SMTP transaction rather than accepting the message and generating a bounce to what is usually a forged return address. The SORBS backscatter zone that policed this is gone, but the behavior still damages your standing with providers running their own systems.

Shared IP vs. Dedicated IP: Who Fixes What

On a shared pool, L2/L3 exposure is entirely your ESP’s domain — the allocation and ASN belong to them.

On a dedicated IP, Level 1 is yours to solve. Levels 2 and 3 still are not: they follow your hosting provider’s ASN, so a dedicated IP inside a poorly-run network just gives you a clean address in a dirty neighborhood. The variable to control is which network you sit on, not which IP.

How Mailercloud Handles Blocklists

At Mailercloud we deliver over a billion emails a month, so we monitor blocklist activity continuously — and we triage it rather than react to it. The lists that correlate with real rejections get immediate incident handling; the ones that do not get logged. We manage IP range and ASN reputation at the infrastructure level, isolate problem senders before they affect shared pools, and handle delisting where delisting is genuinely warranted.

If you are staring at a blocklist alert and cannot tell whether it matters, talk to our deliverability team — or start free with Mailercloud.

FAQ: UCEPROTECT and SORBS Listings

Should I pay for UCEPROTECT express delisting?

Generally no. Listings expire for free once the underlying abuse stops — seven days after the last spamtrap hit for Level 1. For Level 2 and Level 3 you would be paying to clear a listing caused by other tenants on your network, which can return as soon as another tenant misbehaves. RFC 6471 explicitly recommends against using DNSBLs that charge listed parties for removal.

How do I get off UCEPROTECT Level 3?

You cannot, directly. Level 3 lists an entire ASN, and only the ASN operator — your hosting provider or ESP — can change the conditions that caused it. Open a ticket with them. In most cases the correct answer is that the listing does not warrant action, because Level 3 is not consulted by the mailbox providers that determine your delivery.

Is SORBS still active in 2026?

No. Proofpoint decommissioned SORBS on June 5, 2024, and all 18 zones were emptied of data. There has been no relaunch. If a monitoring tool still reports a SORBS listing, that tool has not been updated. Remove any sorbs.net zones from your own mail server configuration.

What is backscatter and does it still get me listed?

Backscatter is bounce messages sent to forged return addresses — it happens when your server accepts a message for a non-existent recipient and then generates a bounce to the (spoofed) sender. SORBS ran a dedicated backscatter zone before it shut down. The zone is gone, but the behavior still damages your reputation with providers that run their own systems. Reject unknown recipients during the SMTP transaction instead of accepting and bouncing.

Which blocklists actually matter?

Spamhaus above all — SBL, CSS, XBL, PBL, and DBL — because its data is consulted extremely widely. Then Barracuda BRBL if you send to business inboxes, SURBL and URIBL for link reputation, and Invaluement for snowshoe detection. Above all of them sit the mailbox providers’ own internal reputation systems at Google, Microsoft, and Yahoo, which no public list can substitute for and which are ultimately what decide whether you reach the inbox.

Why does a blocklist checker show me on ten lists?

Because most checkers query 50 to 100 zones indiscriminately, including obscure, abandoned, and dead ones, and weight them all equally. The count is meaningless. What matters is whether any list appears in an actual SMTP rejection in your bounce logs.

Does a UCEPROTECT listing affect Gmail or Outlook delivery?

Almost never. Gmail, Outlook, and Yahoo rely on their own internal reputation systems, and UCEPROTECT Level 2 and 3 are widely filtered out or ignored by major operators. Unless a UCEPROTECT URL is actually appearing in your bounce-log rejections, a listing there isn’t what’s affecting your inbox placement.

How do I know if a blocklist is actually blocking my email?

Check your bounce logs, not a blocklist checker. Real DNSBL rejections name the list in the SMTP response, so grep your bounces for the list name (spamhaus, uceprotect, barracuda, and so on). If the list isn’t cited in an actual rejection — and your Gmail/Outlook placement and complaint rate are stable — it isn’t blocking you.

Amar

Amar

Amar CP is the Co-Founder and Sales Director at Mailercloud, where he leads partnerships, alliances, and customer growth. With over a decade of experience in application development, database architecture, and scaling web systems, Amar brings a rare blend of engineering depth and go-to-market expertise to email marketing. He writes about email deliverability, marketing automation, and helping small businesses grow smarter with data-driven campaigns.

Related Articles