UCEPROTECT DNSBL Level 3

UCEPROTECT Level 3 blocks entire ASNs containing spam sources. Because of its broad scope, this blacklist or blocklist has a low impact on deliverability.
Updated on 17 Jun 2026: We updated this guide with UCEPROTECT's Level 3 scoring details and clearer guidance for ASN-based listings.
Summarize with
Check if you are listed on UCEPROTECT DNSBL Level 3
And 143 other blocklists.















What is UCEPROTECT DNSBL Level 3?
UCEPROTECT DNSBL Level 3 is the broadest level in UCEPROTECT's three-tier blocklist (blacklist) system. Instead of listing only one sending IP address, Level 3 lists every IP assigned to an Autonomous System Number (ASN) when that network meets UCEPROTECT's Level 3 policy. An ASN identifies a routing domain, commonly an ISP, hosting provider, or large sender network.
The policy behind this approach is aggressive and intentional. UCEPROTECT describes Level 3 as a hardline DNSBL because it creates collateral damage: legitimate senders inside the listed ASN can be blocked because of other senders on the same provider. The goal is to pressure providers and carriers to remove abuse across their networks.
The three levels work like this:
- Level 1 lists single IP addresses observed sending spam to UCEPROTECT spam traps. These listings are temporary and expire automatically when abuse stops.
- Level 2 lists allocations, subnets, or IP ranges that contain multiple Level 1 sources. This signals that the provider responsible for the range is not containing abuse.
- Level 3 lists the full ASN when the network's spam score and impact count meet UCEPROTECT's policy. This effectively blocklists every IP address belonging to that provider.
The project's blacklists are rebuilt hourly. UCEPROTECT's query page also tells users to test IP addresses and providers to test AS numbers, with manual queries only.
How UCEPROTECT Level 3 scoring works
UCEPROTECT calculates Level 3 at ASN level using a SPAMSCORE. The score compares Level 1 impacts inside the ASN with the total number of IPs assigned to that ASN.
SPAMSCORE formula
(Level 1 impacts from the ASN / total IPs in the ASN) * 100000
UCEPROTECT policy says Level 3 can list all IP space assigned to an AS number when the SPAMSCORE reaches 50 or higher, subject to its impact rules. The active DNSBL lookup zone for this level is dnsbl-3.uceprotect.net.
Provider protection affects how repeated spam from the same source adds weight:
- For a new Level 1 listing, further impact from that IP is not counted for 4 hours.
- If abuse continues after 24 hours, the protection window drops to 1 hour.
- If abuse continues after 48 hours, the protection no longer applies and every impact can count.
- UCEPROTECT can also list an ASN manually and permanently when it believes the ASN was created for spamming, evasion, botnet activity, or malware distribution.
Who runs UCEPROTECT DNSBL Level 3?
The UCEPROTECT project is run by UCEPROTECT-Orga, which describes itself as an anonymous, invitation-only group of technicians who handle mail abuse. Their stated mission is to stop email abuse globally by pushing administrators and providers to secure their networks.
Their system is largely automated. The core database is fed by servers that operate spam traps. When a spam email hits one of these traps, the sending IP address is automatically added to the Level 1 blocklist, which can then escalate to Level 2 and Level 3 if abusive behavior continues or spreads within the network. Trusted reporting systems and UCEPROTECT-Orga members can also feed or manually adjust listings.
How do I get removed from UCEPROTECT DNSBL Level 3?
Getting removed from a Level 3 blacklist is harder than removing a single IP because the listing belongs to the provider's ASN, not just your server. The practical path is to ask the provider to fix the abuse sources that created the Level 2 and Level 3 pressure.
According to UCEPROTECT, Level 1 entries expire automatically and free of charge 7 days after the last abusive email was detected. A Level 3 listing falls away only when the related ASN score and associated listings fall below UCEPROTECT's threshold. This counters the common myth that payment is required for removal.
UCEPROTECT offers optional paid express delisting for senders that do not want to wait, but this option is not always available. Express delisting is not possible under these circumstances:
- The owner of the IP or the ISP has opted out of express delisting.
- Abuse has been seen from IPs listed in Level 1 or the backscatterer blacklist within the last 3 hours.
- A network is on the Level 2 blocklist and the listing limit has been exceeded by a factor of 10 or more.
- An AS is on the Level 3 blacklist (blocklist) and it is in the top 5 of the Level 3 charts.
- The number of Level 2 or Level 3 listings is still increasing.
Before requesting any kind of removal, fix the underlying cause first. Check for compromised accounts, open relays, malware, webform abuse, and unauthorized outbound SMTP. Use UCEPROTECT's query page manually to check the current IP or ASN status.
Suped's product can help verify SPF, DKIM, and DMARC results at the same time, so you do not confuse a UCEPROTECT provider listing with an authentication failure.
What's the impact of being listed on UCEPROTECT DNSBL Level 3?
The broad deliverability impact of UCEPROTECT DNSBL Level 3 is usually low compared with blocklists that major receivers enforce widely. The local impact is severe when a recipient's mail server uses Level 3 to reject SMTP traffic. A listed ASN means every customer in that ASN inherits the same blacklist or blocklist result.
Even if your own sending practices are clean, your emails can be blocked because your ISP or hosting provider has a poor reputation according to UCEPROTECT. The result depends on how many of your recipients' mail servers use dnsbl-3.uceprotect.net and whether they reject mail directly or use the listing as one signal in a broader filtering decision.
Do not treat a Level 3 listing as proof that your own server sent spam. Treat it as an infrastructure risk: confirm the rejection text, ask your provider about ASN-level remediation, and move critical sending to clean infrastructure if the provider cannot resolve the abuse quickly.
Related UCEPROTECT blocklists
UCEPROTECT DNSBL Level 1
Organization
UCEPROTECT
Zone
dnsbl-1.uceprotect.net
Type
IP
Impact
Medium
Delisting
Manual
UCEPROTECT BACKSCATTERER Blacklist
Organization
UCEPROTECT
Zone
ips.backscatterer.org
Type
IP
Impact
Low
Delisting
Automatic
UCEPROTECT DNSBL Level 2
Organization
UCEPROTECT
Zone
dnsbl-2.uceprotect.net
Type
IP
Impact
Low
Delisting
Manual
