Key Findings
(104 of 1,247 domains)
simultaneously
had no DMARC enforcement
common single blacklist
Blacklist Distribution
Of the 1,247 domains checked, 104 (8.3%) appeared on at least one of the five major blacklists queried. Spamhaus was the most common listing. Multiple-listing (appearing on two or more simultaneously) affected 26 domains (2.1%).
Domains listed per blacklist (% of 1,247 total)
Note: domains can appear on more than one blacklist. Percentages are of total 1,247 domains, not of total listings.
Blacklisting vs DMARC Policy
We cross-referenced blacklisted domains against DMARC policy from our August 2026 DMARC Enforcement Report. The pattern is clear: domains without DMARC enforcement are significantly over-represented among those appearing on blacklists.
DMARC policy of blacklisted domains (104 total)
Compared to full 1,247-domain dataset in brackets
Blacklisting vs DKIM Configuration
Cross-referencing with DKIM data from our September 2026 DKIM Selector Report, blacklisted domains show notably weaker DKIM configuration than the overall dataset.
DKIM status of blacklisted domains (104 total)
Compared to full 1,247-domain dataset in brackets
Blacklisted domains are 49% more likely to have no DKIM and 63% more likely to be using a deprecated RSA-1024 key compared to the broader dataset. While this is correlation rather than causation, weak email authentication is a common characteristic of domains that end up on blacklists.
What Gets a Domain Blacklisted
Blacklisting happens when a sending IP or domain is flagged by a blocklist operator for one or more of the following:
- High spam complaint rates — recipients marking mail as spam at rates above provider thresholds
- Sending to spam traps — email addresses used specifically to catch unsolicited mail
- Lack of list hygiene — sending to invalid or unengaged addresses repeatedly
- Shared IP abuse — on shared hosting, another tenant's behavior can affect your IP reputation
- No authentication — some blacklists factor in missing or misconfigured DMARC/SPF as a risk signal
Authentication does not guarantee inbox placement, but its absence correlates with higher blacklist rates. The 66.3% figure for blacklisted domains lacking DMARC enforcement suggests that domains without authentication infrastructure are either being used to send unsolicited mail, or are being spoofed by third parties in ways that damage the domain's reputation.
How to Check if Your Domain is Blacklisted
The InboxGreen free checker queries the major DNS-based blacklists as part of its standard domain scan. If your domain appears on a blacklist, the result page links to the relevant removal request process for each list. See also: Domain Blacklisted: What It Means and How to Recover and Spamhaus Listed: Recovery Steps.
Methodology
The 1,247 domains in this dataset were selected from a cross-industry sample of active domains with MX records, first scanned for our June 2026 Email Authentication Report. Each domain was queried against five DNS-based blacklists in September 2026: Spamhaus SBL, Barracuda BRBL, SpamCop SCL, SORBS DUHL, and UCEPROTECT Level 1. Queries targeted the domain name (not IP address). The dataset does not include domains without MX records or parked domains. Full methodology at inboxgreen.email/methodology.
September 2026 · DKIM coverage, key lengths, and alignment gaps across 1,247 domains.
August 2026 · DMARC policy distribution and enforcement gaps.
July 2026 · Common SPF errors and how often they occur.