Skip to content
Reputation & KEV

IP & Domain Reputation Check

Monitors whether your IP addresses and domains are on blocklists and protects your reputation.

Multiple
reputation sources
Real-time
reputation and threat level
4 Levels
critical to low risk rating
History
query archive and reporting
Why it matters

How many blacklists is your domain or IP address on?

When your mail servers reach the outside world, global reputation lists are queried: if your IP is there, delivery is blocked — and you may never know it happened. A domain or IP involved in past attacks, spam, or abuse gets listed, and your emails fail silently at recipients. A domain you just bought may carry the old owner's reputation, or a cloud instance may be a remnant of a previous campaign. IP Reputation Check tells you in real time how external lists see your servers and domains: what you are registered for, which sources list you, what your risk level is, and who to contact to clean it up. This is not a vulnerability scan — it is a reputation and reachability check.

  • Blacklist membership blocking your email may go unnoticed; removal takes months.
  • You do not know your server's history, the old owner's behavior, or the previous tenant's activities.
  • A new domain bought without WHOIS history and reputation review starts you on a blocklist.
What it does

What it does.

Monitors domain and IP address

A domain is monitored for all IPs resolved by its A and MX records; an IP is monitored as itself. Lookups run each cycle, so DNS changes are automatically reflected.

Queries reputation sources

External sources that block SMTP delivery are queried. Each result captures: reputation score, threat level (critical/high/medium/low), list date, source name.

Counts actionable sources only

Policy lists (PBL) and informational sources (Tor, Barracuda) are not counted. Only sources reporting real threats (spam, abuse, attack history) increase risk.

Threat level classification

Each source assigns a threat level: critical (active attack), high (weak point), medium (suspicious activity), low (informational). Query results show which source reported what level.

Query history and trend

Every query is logged. Over time, you see how listing patterns change, which sources added or removed you. You notice when a list drops you or a new source adds you.

Bulk check

Every domain and IP in your company can be checked in one command. Result table shows: asset, source count, highest threat level, last check date.

Email alerts

If a listing is detected, an alert is sent. When the listing is resolved, you are notified. Alerts do not contain vulnerability details; they direct the right person/team to the cleanup contact.

How it works

From setup to report.

  1. 01

    Select the asset to monitor

    Choose a domain or IP address from your verified company records. If a domain is selected, its A and MX records are automatically resolved.

  2. 02

    Start with a query

    A first query runs against the selected asset. External reputation sources are queried in turn, results are logged: source, threat level, listing date.

  3. 03

    View the result table

    See how many sources list you, each source's threat level, and which source reports the highest risk. If no listings exist, a clean report is displayed.

  4. 04

    Review the history

    Compare against older queries. See which sources were removed and which were added. Trends emerge.

  5. 05

    Track the cleanup

    When a listing is detected, the cleanup process with the source is initiated. The listing persists until the next query and is shown in reports.

Technical details

The specifics.

Monitored assets
Domain (A and MX resolved IPs) or IP address (public IPv4 range)
Query sources
External blocklist and reputation databases that affect email delivery and standing
Threat levels
Critical (active attack), high (weak point), medium (suspicious), low (informational)
Source types
Counted: spam, abuse, attack history. Not counted: policy lists, Tor, informational sources
Query cycle
Manual trigger or automatic weekly/monthly; first query runs when asset is created
Reporting
Screen: query results, source list, threat level, last check date, trend. History: comparison with previous queries
Alerts
Email: listing detected, listing resolved. No details; redirection to cleanup contact
License
Package or single-service license. If expired, query cannot run (view-only)
FAQ

Frequently asked questions.

Is this a vulnerability scan?

No. IP Reputation Check is not a scan but a query to external blacklists. It does not penetrate your server, scan your network, or attack anything. It only answers 'how do external lists see your IP?' Nothing more.

How does a listing disappear?

It depends on the source. Stop sending spam and you may drop automatically in weeks; attack records are permanent; change a policy rule (e.g., ISP's PBL rule) and you may drop instantly. Each source has a different delisting process; the panel shows the cleanup contact.

My new domain is listed — why?

The previous owner may have been listed. A domain bought without WHOIS history check carries old reputation. After a query, you can initiate cleanup with the source, citing your WHOIS history (from whom you bought it, the old owner's records) as evidence.

IP & Domain Reputation Check starts today.

Create a free account and run your first scan within minutes.