Blocklist Monitoring
A blocklisted IP silently breaks email delivery and erodes trust in your services - and you're usually the last to find out. DNS Watchdog checks every IP your records resolve to, daily.
Blocklists work in the background of the internet: mail servers consult them before accepting your email, security products consult them before letting users reach your site. Landing on one rarely comes with a notification - your mail just starts bouncing, your traffic quietly drops, and support tickets become your monitoring system.
DNS Watchdog closes that gap by checking every IP address your DNS resolves to against established threat-intelligence feeds - Spamhaus DROP, IPsum, and FireHOL Level 1, which itself aggregates sources including DShield and Feodo - with the feed data refreshed every six hours. Because the target list is derived from your live records, it automatically covers everything your estate actually uses, including addresses added yesterday.
A listed IP is raised as a Critical issue naming the lists it appears on, with the affected records and zones attached - so you can see immediately which services and sending domains are in the blast radius. The issue closes itself once the IP is delisted or your records move off it, and the whole loop from listing to delisting is captured in your change history.
How it works
- RefreshBlocklist feeds - Spamhaus DROP, IPsum, and FireHOL Level 1 - are pulled and consolidated every six hours, so checks always run against current data.
- ResolveEvery record across your zones is resolved daily and the resulting IPs deduplicated - the complete, current set of addresses your estate depends on.
- CheckEach IP is checked against the consolidated feeds, with listings attributed to the specific lists they came from.
- RaiseA listed IP becomes a Critical issue naming the blocklists involved, with the exact records and zones that resolve to it attached - and it reaches your alert channels the same day.
- Auto-closeOnce the IP is delisted or your records move off it, the next scan resolves the issue automatically.
What you get
- Every resolved IP checked against Spamhaus DROP, IPsum, and FireHOL Level 1
- Feed data refreshed every six hours
- Listings raised as Critical issues naming the specific blocklists
- Findings linked to the exact records and zones affected
- Issues auto-close once the IP is delisted or the record is moved
- Alerts routed to Slack, Teams, email, or webhooks
Why it matters
Find out first, not last
Nobody tells you when your IP gets listed - the internet just quietly starts treating you differently. Daily checks turn a slow-burning mystery into a same-day alert.
Blast radius in one view
Because listings are linked to the records that resolve to the IP, you immediately know which services, domains, and mail flows are affected - triage starts with answers.
Deliverability defended
One listed sending IP can undo months of careful email reputation work. Catching it on day one keeps the damage - and the recovery time - small.
Shared infrastructure covered
On cloud and CDN infrastructure, a neighbour's behaviour can taint an IP you use. Monitoring every resolved address means even reputation problems you did not cause are on your radar.
Common questions
Which blocklists do you check?
Spamhaus DROP, IPsum, and FireHOL Level 1 - the latter an aggregation of respected sources including DShield and Feodo. Together they cover hijacked networks, attack sources, and malware infrastructure, and the consolidated data is refreshed every six hours.
How do IPs end up on blocklists?
A compromised host sending spam or attack traffic, malware calling out from your network, a misconfigured mail server - or simply inheriting a bad-reputation address on shared cloud infrastructure. Often the listing is the first sign anything is wrong, which is exactly why it is worth monitoring.
What should I do when an IP is flagged?
First establish why: check the host for compromise or misconfiguration. Then either remediate and request delisting, or move the workload to a clean address. The issue stays open and visible until the daily scan confirms the listing is gone.