Blacklisted in Spamhaus

Our main domain for mailservers has been blacklisted by Spamhaus.
I have not received any complaints prior to this (24 hours ago).
Spamhaus do not let me delist, the domain has been flagged for manual delist (whatever that is), and I did that 24 hours ago, but until now, nothing from Spamhaus.

Anyone knows how to get out of that blacklist, or to get sem response from Spamhaus?

Hemil AquinoNetwork EngineerCommented:
Go to this website and check your ip address, if you see any signs of block, just click on that specific provider and they will tell you what to do to white list your ip
dk_jbAuthor Commented:
Hi Hemil,

Done that, alle green.
Just on Spamhaus all my IP's and my domain are blacklisted.

Hemil AquinoNetwork EngineerCommented:
Do you see something like this?

Your IP is listed in the PBL
Hemil AquinoNetwork EngineerCommented:
Keep in mind this

THE PBL IS NOT A BLACKLIST. You are not listed for spamming or for anything you have done. The PBL is simply a list of all of the world's dynamic IP space, i.e: IP ranges normally assigned by ISPs to broadband customers routers/modems (DSL, DHCP, PPP, cable, dialup). It is perfectly normal for these IP addresses to be listed on the PBL. In fact all dynamic IP addresses in the world should be on the PBL. Even static IPs which do not send mail should be listed in the PBL.

PBL listings do not prevent you sending email unless your email program is not authenticating properly when it connects to your ISP or to your company's mail server. This can happen if you have changed something in your email program's settings, forgotten to turn on 'SMTP Authentication' or if you have switched 'SMTP Authentication' off by mistake.

If you are using a normal email program such as Outlook, Entourage, Thunderbird or Apple Mail and you are being blocked by a Spamhaus PBL listing when you try to send email, the reason is simply that YOU NEED TO TURN ON 'SMTP AUTHENTICATION' in your email program's account settings. That will immediately solve the problem for you. See: How do I turn on SMTP Authentication?
dk_jbAuthor Commented:
Hi Hermil,

In Spamhaus, my domain is listed in the DBL

My IP's, for all my mailservers  is listed in the SBL (alle have hostnames on the same domains.

Got any spare public IP's?
When this happens to me ,I find out what the issues are (they do give you a clue)change the public IP addresses and wait for the other IP's to clear.
It's not just spam they flag you for,if you have an infected pc and it is doing bad things ,they will blacklist your IP.
dk_jbAuthor Commented:
Hi Pgm554,

I did that, but had to change hostnames to anothother domain, on the mailservers, because not only the IP's were blacklisted, the domain was.

Last evening, suddenttly, Spamhaus removed the blacklist, but I never got any response from them.

Hemil AquinoNetwork EngineerCommented:
You might be interested in this:

Is there a way to report spam to Spamhaus?
No. Spamhaus DNSBLs are not based on spam reported to us (we have our own systems for detecting and identifying spam, proxies, etc.). Please DO NOT forward your spam to any address, we can not do anything with spam you send us, except bin it ourselves (we block people who do forward spam to us from connecting to our mail servers again).
The only public DNSBL system you can currently report spam to is SpamCop.

You can also report your spam (by forwarding it complete with full headers) to the U.S. government's spam-evidence database run by the FTC at:

Many ISPs and webmail providers have spam reporting addresses for spam received by their users. Often it is as simple as clicking a "This Is Spam" button. Those reports help the ISP build their own spam filters, and sometimes are aggregated for reports to the spammer's host network via feedback loops.

Some places where you can learn about more about spam and how to report it include: The Great Granddaddy of all anti-spam sites The Network Abuse Clearinghouse (abuse addresses) (how to view full headers) (archived) header-reading tutorial (archived) basics of Simple Mail Transport Protocol (SMTP, or e-mail)
Also see our Online Scams FAQ for other groups fighting against the scams found in spam.
David FavorLinux/LXD/WordPress/Hosting SavantCommented:
Sometimes records get wedged in Spamhaus for seemingly no reason + stay there for long periods of time, again seemingly for no reason.

You might switch over to using MailGun till your IP is cleared in Spamhaus.

Also, best you understand why your IP got blacklisted.

There's a Linux Kernel zero day which may be biting you. I had several clients get hit with this a year ago.

The zero day allows crafty hacks to exploit systems + integrate those systems into a Bot network used for sending SMTP spam.

You can test this theory by setting up a iptables rule to log + drop all outgoing SMTP packets + then temporarily stop your MTA.

If you see a huge amount of outgoing port 25 traffic with your MTA down, your machine is infected.

I'm a fairly advanced Server Savant + never found a way to cleanse this hack 100%. The only way I found to fix this, was to move all code off infected machine + reinstall OS from scratch + then reinstall all code.

I've had to do this with... 3-4 machines over the past 2 years. Once they get hit, they seem permanently infected.
dk_jbAuthor Commented:
Hi David,

I don't see, what swithing from Spamhaus to something else would help.
It's the recieving mailserver (not mine), that rejects the mail.

I aleways checkh all outgoing connects for unusual patterns, but.... Nothing.

spamhaus will automatically deblacklist you from xbl or sbl after about a day to a maximum of a week ... if you stop sending spam. changing your outgoing ip will work for a short time.

dk_jbAuthor Commented:
