IP & Domain Reputation Check
Monitors whether your IP addresses and domains are on blocklists and protects your reputation.
- Multiple
- reputation sources
- Real-time
- reputation and threat level
- 4 Levels
- critical to low risk rating
- History
- query archive and reporting
How many blacklists is your domain or IP address on?
When your mail servers reach the outside world, global reputation lists are queried: if your IP is there, delivery is blocked — and you may never know it happened. A domain or IP involved in past attacks, spam, or abuse gets listed, and your emails fail silently at recipients. A domain you just bought may carry the old owner's reputation, or a cloud instance may be a remnant of a previous campaign. IP Reputation Check tells you in real time how external lists see your servers and domains: what you are registered for, which sources list you, what your risk level is, and who to contact to clean it up. This is not a vulnerability scan — it is a reputation and reachability check.
- Blacklist membership blocking your email may go unnoticed; removal takes months.
- You do not know your server's history, the old owner's behavior, or the previous tenant's activities.
- A new domain bought without WHOIS history and reputation review starts you on a blocklist.
What it does.
Monitors domain and IP address
A domain is monitored for all IPs resolved by its A and MX records; an IP is monitored as itself. Lookups run each cycle, so DNS changes are automatically reflected.
Queries reputation sources
External sources that block SMTP delivery are queried. Each result captures: reputation score, threat level (critical/high/medium/low), list date, source name.
Counts actionable sources only
Policy lists (PBL) and informational sources (Tor, Barracuda) are not counted. Only sources reporting real threats (spam, abuse, attack history) increase risk.
Threat level classification
Each source assigns a threat level: critical (active attack), high (weak point), medium (suspicious activity), low (informational). Query results show which source reported what level.
Query history and trend
Every query is logged. Over time, you see how listing patterns change, which sources added or removed you. You notice when a list drops you or a new source adds you.
Bulk check
Every domain and IP in your company can be checked in one command. Result table shows: asset, source count, highest threat level, last check date.
Email alerts
If a listing is detected, an alert is sent. When the listing is resolved, you are notified. Alerts do not contain vulnerability details; they direct the right person/team to the cleanup contact.
From setup to report.
- 01
Select the asset to monitor
Choose a domain or IP address from your verified company records. If a domain is selected, its A and MX records are automatically resolved.
- 02
Start with a query
A first query runs against the selected asset. External reputation sources are queried in turn, results are logged: source, threat level, listing date.
- 03
View the result table
See how many sources list you, each source's threat level, and which source reports the highest risk. If no listings exist, a clean report is displayed.
- 04
Review the history
Compare against older queries. See which sources were removed and which were added. Trends emerge.
- 05
Track the cleanup
When a listing is detected, the cleanup process with the source is initiated. The listing persists until the next query and is shown in reports.
The specifics.
- Monitored assets
- Domain (A and MX resolved IPs) or IP address (public IPv4 range)
- Query sources
- External blocklist and reputation databases that affect email delivery and standing
- Threat levels
- Critical (active attack), high (weak point), medium (suspicious), low (informational)
- Source types
- Counted: spam, abuse, attack history. Not counted: policy lists, Tor, informational sources
- Query cycle
- Manual trigger or automatic weekly/monthly; first query runs when asset is created
- Reporting
- Screen: query results, source list, threat level, last check date, trend. History: comparison with previous queries
- Alerts
- Email: listing detected, listing resolved. No details; redirection to cleanup contact
- License
- Package or single-service license. If expired, query cannot run (view-only)
Frequently asked questions.
Is this a vulnerability scan?
No. IP Reputation Check is not a scan but a query to external blacklists. It does not penetrate your server, scan your network, or attack anything. It only answers 'how do external lists see your IP?' Nothing more.
How does a listing disappear?
It depends on the source. Stop sending spam and you may drop automatically in weeks; attack records are permanent; change a policy rule (e.g., ISP's PBL rule) and you may drop instantly. Each source has a different delisting process; the panel shows the cleanup contact.
My new domain is listed — why?
The previous owner may have been listed. A domain bought without WHOIS history check carries old reputation. After a query, you can initiate cleanup with the source, citing your WHOIS history (from whom you bought it, the old owner's records) as evidence.
Other CyCastle services.
IP & Domain Reputation Check starts today.
Create a free account and run your first scan within minutes.