The Abusix nod List (Newly Observed Domains) is an informational blocklist that tracks all newly observed domains sending email, providing a useful signal for email scoring rather than acting as a traditional blacklist indicating malicious intent.
The Abusix nod (Newly Observed Domains) List is a domain-based blocklist that contains all newly observed domains, with each entry being wildcarded. Its primary purpose is to identify domains that have only recently started being used in email traffic. According to Abusix, being on this list does not definitively mean a domain is malicious. Instead, it serves as an informational tool for mail servers, which can use this data for email scoring or as part of broader meta-rules to assess the trustworthiness of an incoming message. The data for this blacklist is sourced from Farsight Security’s extensive real-time Passive DNS sensor network.
Technically, this blocklist (blacklist) has a very short listing duration of just 25 hours. If a domain is listed, queries will return the code 127.0.1.2. A key feature is its use of wildcards, which means if 'example.com' is listed, all its subdomains like 'mail.example.com' are also implicitly included. This simplifies the lookup process for mail administrators, as they do not need to normalize domain names before checking them against the blacklist.
The nod List is operated by Abusix, a company specializing in network abuse management, email security, and threat intelligence. Abusix positions itself as more than just a blacklist provider, focusing on comprehensive solutions to create a safer internet. Their vision targets the primary vectors for cyberattacks, email and network traffic, by providing services that stop threats before they can reach end-users.
Given the list's automatic 25-hour expiration policy, a listing on the nod List will resolve itself in just over a day. However, if deliverability issues are urgent, you can request removal. Delisting is free but requires creating an account, a measure to prevent abuse of the system.
To request delisting, visit the Abusix Lookup and Delisting page. You will need to enter the domain, and if it is listed, follow the on-screen instructions to sign up for a free account and submit the removal request. Delists are processed immediately, though it may take up to five minutes for the change to propagate to all services that use the list.
The impact of being on the Abusix nod List is generally considered medium. Since the blocklist's policy states that a listed domain is not necessarily malicious, many receiving mail servers will not use it to outright block email. Instead, a listing is more likely to contribute negatively to an email's overall spam score. This can increase the chances of messages being filtered into the spam or junk folder.
However, the exact impact depends entirely on how a specific mail provider has configured its filters. Some systems may treat a listing on this blacklist as a reason for temporary rejection, leading to bounced emails. The short 25-hour listing duration helps to limit any sustained impact, assuming the domain does not exhibit other behaviors that would cause it to be added to other, more severe blocklists.
Organization
Zone
Type
Impact
Delisting
Organization
Zone
Type
Impact
Delisting
Organization
Zone
Type
Impact
Delisting
Organization
Zone
Type
Impact
Delisting
Organization
Zone
Type
Impact
Delisting
Organization
Zone
Type
Impact
Delisting
19 resources
Do blacklists exist for newly registered domain names?
How impactful are Abusix blacklisted IPs from a shared IP pool?
How to handle a domain listed on Abusix or request delisting?
What is the distinction between Abusix 'black' and 'black_css' abuse lists?
What open 'bad domain' lists can I use to filter newsletter subscriptions from typo domains?
Why is my AWS hostname blacklisted in Abusix and how do I resolve it?