Real-Time Threat Intelligence
Defend Your Mail Server With Live Incident Telemetry.
A high-frequency RFC 5782 DNSBL zone (bl.testonemail.com) aggregating active Postfix & Dovecot SASL brute-force probes, DMARC domain impersonators, and 24/7 Guardian reputation defense.
Blocklist Lookup
Check an IP on bl.testonemail.com
Enter any IPv4 address to check its current reputation, strike history, and automated expiration.
1. Postfix MTA Integration
Add reject_rbl_client bl.testonemail.com to your smtpd_recipient_restrictions in /etc/postfix/main.cf:
smtpd_recipient_restrictions =
permit_mynetworks,
permit_sasl_authenticated,
reject_unauth_destination,
reject_rbl_client bl.testonemail.com
2. Postscreen Integration
If using Postscreen for pre-greeting screening, weight TestOneMail in /etc/postfix/main.cf:
postscreen_dnsbl_sites =
zen.spamhaus.org*3,
b.barracudacentral.org*2,
bl.testonemail.com*2
3. Command-Line DNS Test
Verify your DNS resolution using the standard RFC 5782 test loopback:
dig A 2.0.0.127.bl.testonemail.com +short
# Output should return: 127.0.0.2
24/7 Blocklist Guardian
Continuous reputation monitoring for your mail servers. Get alerted immediately the moment your IP appears on any blocklist, with automated 30-minute escalation.
- 12-hour routine scans
- 1-hour incident escalation
- 32 DNSBL zones monitored
- Instant email alert notifications
- 6-hour routine scans
- 30-minute incident escalation
- High-priority DNSBL queue
- On-demand instant re-scans
- 1-hour routine scans
- 30-minute incident escalation
- Maximum deliverability defense
- Unlimited manual scans
Server Monitor
DNSBL Zone Results (32 Monitored Lists)
| Blocklist | Zone | Status |
|---|
Request Delisting or Contest a Listing
Level 1 (transient/first-time offenders) are granted instant self-service delisting with a 30-day cooldown. Repeat offenders or DMARC spoofers are forwarded to the security team for verification.
Fail2ban Client Addon & Log Exporter
Feed blocked attackers directly from your remote mail servers into the TestOneMail RBL network in real time. Features automated log sanitization, password scrubbing, and zero external dependencies.
curl -sSL https://blacklist.testonemail.com/install.sh | sudo bash -s -- --key sq-rbl-key-9f82a17c4b
Installs /usr/local/bin/testonemail-reporter (Python 3, zero-pip), sets up /etc/testonemail/reporter.json, installs action.d/testonemail.conf, and performs a live connectivity selftest.
2. Enable the Action in Your Jails
Attach testonemail to your active mail jails in /etc/fail2ban/jail.local:
# /etc/fail2ban/jail.local
[postfix-sasl]
enabled = true
action = %(known/action)s
testonemail
[dovecot]
enabled = true
action = %(known/action)s
testonemail
[postfix-pregreet]
enabled = true
action = %(known/action)s
testonemail
Reload Fail2ban to apply changes immediately:
sudo fail2ban-client reload
Automatically redacts passwords, plain auth strings, base64 hashes, and sensitive credentials from log matches before transmission.
Built on native Python 3 standard library (no pip packages or virtualenvs). Runs cleanly on Debian, Ubuntu, AlmaLinux, Rocky, and RHEL.
Enforces a strict 5s socket timeout and 5-minute local deduplication cache. Never blocks, delays, or throws errors to Fail2ban.