The NordSpam Domain Name Blacklist (DBL) is a manually moderated blocklist (or blacklist) that lists domains involved in spam, phishing, and other online abuse, with a primary focus on protecting users in Nordic and European countries.
The NordSpam Domain Name Blacklist (DBL) is a type of blocklist known as a URIBL, which focuses specifically on listing domain names found within the body of spam emails, not the sending IP addresses. This blacklist is used by mail server administrators to identify and filter messages that contain links to malicious or spam-related websites.
According to its policy, NordSpam lists domains that are associated with unsolicited bulk email (UBE), phishing, online scams, ransomware, or other forms of internet abuse. To maintain accuracy and prevent false positives, all domains added to the reputation database are manually moderated. The organization does not disclose its exact listing criteria to prevent spammers from finding ways to circumvent the blacklist.
Technical information
The NordSpam DBL is an RFC5782 compliant DNS-based Blackhole List (DNSBL). Administrators can query it using the zone dbl.nordspam.com. A query can be performed using either an A record or a TXT record. If a domain is listed on this blocklist, a DNS query for the domain within the NordSpam zone will return a specific result. An A record query will return 127.0.0.2, and a TXT query will provide additional details about the listing. For example:
$ dig +short A test.dbl.nordspam.com 127.0.0.2 $ dig +short TXT test.dbl.nordspam.com "RFC5782 TEST-record."
The blacklist is operated by The NordSpam Project, a nonprofit organization. The project's main goal is to track and report spam and malicious activities that primarily target Nordic and European countries. The organization is privately funded and sponsored by a few companies, allowing it to offer its blocklist data free of charge for both commercial and non-commercial use. The NordSpam Project adheres to the best practice guidelines outlined in RFC6471 for operating its DNSBL services.
It is important to understand that NordSpam only provides reputation data; it does not directly block your emails. Mail server operators choose whether to use this data to filter incoming mail. If your domain is on this blacklist, you must request removal directly from NordSpam.
The delisting process is entirely manual and free of charge. Listings do not expire automatically, so you must take action to be removed. To request delisting for a domain, follow these steps:
Requests are typically processed within 1 to 48 hours. NordSpam may decline the removal request if they believe the actions taken are not sufficient to prevent future abuse.
The impact of being listed on the NordSpam DBL is generally considered low. This means it is not as widely used as some larger, more globally-focused blacklists. However, the impact is highly dependent on your audience. If you send emails to recipients primarily in Nordic or other European countries, being on this blocklist can cause significant email deliverability problems. Any mail server administrator using this list may choose to reject your emails or filter them directly to the spam folder, preventing your message from reaching the inbox.
19 resources
Besides Spamhaus, what blocklists are important for email marketers to monitor?
Does Spamhaus DBL list hostnames or root domains?
How does Spamhaus decide whether to list a subdomain or a whole domain on the DBL?
How to contact Spamhaus DBL and troubleshoot a domain listing?
What open 'bad domain' lists can I use to filter newsletter subscriptions from typo domains?
Why am I seeing Spamhaus DBL block messages for IP address lookups?