Back to all experiments

Experiment 003, infrastructure

Our blocklist checker said clean. It was lying.

Every tool we had said our sending domains were fine. We checked by hand, and most of them were on Spamhaus.

The day we checked by hand

On 4 August we ran the Spamhaus domain blocklist query ourselves, one domain at a time, against sending domains that every dashboard showed as healthy.

DomainsDashboardSpamhaus DBL, queried by hand
Our sending domainsCleanMost listed

The dashboard was not wrong on purpose. It was asking a different question, and so was our own first script.

Why a checker can say clean

Spamhaus answers a blocklist query with a code. A listing is one kind of code. But if you ask through a public DNS resolver, or ask too often, it answers with a refusal code instead, and a refusal looks exactly like clean to anything that only checks for a listing.

listed: 127.0.1.x    refused: 127.255.255.254    clean: no answer

So every check starts with a control query. dbltest.com is a domain Spamhaus keeps listed on purpose. If that query does not come back listed, nothing else in the run means anything. Our own daily script learned this the hard way: on 2 October it flagged a healthy domain as listed because one query in the middle of the run was refused. We fixed it the same day. Tools include ours.

The second surprise

Once we could read the list properly, it did not track delivery either.

DomainHistorySpamhaus
Our most burned domain0.03% reply rate, thousands of sendsClean
A domain that never sent a campaignWarmup onlyListed

A clean listing is not a health signal. A listing is a kill signal. Those are different things, and a checker that reports one green light cannot tell you either.

The list that does not matter

There is a second blocklist, SURBL, that our provider's panel checks. Some of our domains sit on it today; the panel calls everything else clean. We measured what a SURBL listing costs: about one rejected email per 1,000 sends, from a few corporate gateways. Gmail and Microsoft 365 do not use it. So we track it and ignore it.

What we do now

Our own rule, not a vendor's: a Spamhaus listing retires the domain, SURBL does not, and no panel is trusted on its own. Every run starts with the control query. A domain is reused only after a clean Spamhaus answer and a real read of its delivery. No third party tool gets the final word, including the one we wrote.

To be clear: we do not know what caused those listings in August, and we do not blame our DNS host or our warmup for them. The rule is about reading the list correctly, not about what put us on it.

Try this

dig +short dbltest.com.dbl.spamhaus.org A

If the answer is not 127.0.1.2, your resolver is being refused, and every clean result you have seen from it was a refusal too.

Want this for your outbound?

We test on our own sends first, then run it for you.

Book a 30 minute call