Public infrastructure Public beta

A Belgian DNSBL built for clarity and restraint.

IBCSC consolidates permitted anti-abuse signals into one simple zone. Blocking decisions stay deliberately strict while contextual signals remain separate.

Start in observation mode before enabling automatic rejection.

Zones in the research registry
36
Permitted candidates
04
Blocking-eligible signal
01
Context signals
03

Check an IPv4 address

Results come from the latest valid local snapshot. Your browser does not query 36 operators directly.

A DNSBL result is a reputation signal, not proof of abuse. Combine it with logs, SPF, DKIM, DMARC and your local policy.

Ready for a lookup

Enter the public address of the mail server you want to check.

Configure your server

Start in observation mode. Enable rejection only after measuring the impact on legitimate traffic.

Postfix
# main.cf: observe first
smtpd_recipient_restrictions =
    permit_mynetworks,
    permit_sasl_authenticated,
    reject_unauth_destination,
    warn_if_reject reject_rbl_client dnsbl.ibcsc.be

Observe

Postfix uses warn_if_reject. Exim adds a header and an ACL variable for your spam score. Neither example rejects the message.

Decide

Hard rejection remains a local choice. Test exemptions, trusted relays and your appeal process.

Read the DNS response

After the positive RFC control succeeds, NXDOMAIN means the address is not listed. SERVFAIL or a timeout provides no verdict. Never treat an outage as a clean or listed result.

Read RFC 5782

36 zones researched, not 36 zones republished

This registry documents the initial research catalog. Only permitted, healthy sources present in a fresh snapshot may contribute to the service.

36Source
4Candidates
8Permission required
13Legacy or withdrawn
11Under review

Eligible datasets

These four datasets are documented as candidates under the cited source permission. Display here is not proof of activation: only presence in a fresh, healthy snapshot allows a dataset to contribute.

Candidates dnsbl-1.uceprotect.net
Operator
UCEPROTECT
Role
Precise blocking

Technical candidate. Activation depends on snapshot health.

Candidates dnsbl-2.uceprotect.net
Operator
UCEPROTECT
Role
Context only

Technical candidate. Activation depends on snapshot health.

Candidates dnsbl-3.uceprotect.net
Operator
UCEPROTECT
Role
Context only

Technical candidate. Activation depends on snapshot health.

Candidates ips.backscatterer.org
Operator
Backscatterer
Role
Context only

Technical candidate. Activation depends on snapshot health.

The other 32 zone names are not reproduced publicly, in accordance with the terms of the initial research catalog. Read the catalog terms.

Reduce false positives

Strict decision

Only exact, fresh L1 records can be eligible for listed status. Network-level and backscatter signals remain watch-only.

Correction and removal

Result details identify the source. Correction starts with that operator. IBCSC then removes the signal at the next valid synchronisation.

Licences respected

A zone requiring registration, a key, a contract or mirror approval stays disabled until those conditions are met.

Fail safely

A missing or stale snapshot makes the service unavailable. It never turns a clean address into a listed one.

UCEPROTECT data: Copyright © 2001-2021 UCEPROTECT-Network. Backscatter data: Copyright © 2007-2021 UCEPROTECT-Network. Software notice: © 2001-2026 Admins WebSecurity GbR (http://www.admins.ws), created and published by UCEPROTECT-Network. Permission is granted to use, copy, modify and distribute the data for any purpose, provided both copyright and permission notices remain in all copies.

Read the UCEPROTECT permission