Real-Time Threat Intelligence
Defend Your Mail Server With Live Incident Telemetry.
A high-frequency RFC 5782 DNSBL zone (bl.testonemail.com) aggregating active Postfix & Dovecot SASL brute-force probes, DMARC domain impersonators, and 24/7 Guardian reputation defense.
Blocklist Lookup
Check an IP or Domain on bl.testonemail.com
Enter any IPv4 address or domain name to check its reputation, resolved IP addresses, strike history, and automated expiration.
1. Postfix MTA Integration
Add reject_rbl_client bl.testonemail.com to your smtpd_recipient_restrictions in /etc/postfix/main.cf:
smtpd_recipient_restrictions =
permit_mynetworks,
permit_sasl_authenticated,
reject_unauth_destination,
reject_rbl_client bl.testonemail.com
2. Postscreen Integration
If using Postscreen for pre-greeting screening, weight TestOneMail in /etc/postfix/main.cf:
postscreen_dnsbl_sites =
zen.spamhaus.org*3,
b.barracudacentral.org*2,
bl.testonemail.com*2
3. Command-Line DNS Test
Verify your DNS resolution using the standard RFC 5782 test loopback:
dig A 2.0.0.127.bl.testonemail.com +short
# Output should return: 127.0.0.2
24/7 Blocklist Guardian
Continuous reputation monitoring for your mail servers. Get alerted immediately the moment your IP appears on any blocklist, with automated 30-minute escalation.
- 12-hour routine scans
- 1-hour incident escalation
- 32 DNSBL zones monitored
- Instant email alert notifications
- 6-hour routine scans
- 30-minute incident escalation
- High-priority DNSBL queue
- On-demand instant re-scans
- 1-hour routine scans
- 30-minute incident escalation
- Maximum deliverability defense
- Unlimited manual scans
Server Monitor
DNSBL Zone Results (32 Monitored Lists)
| Blocklist | Zone | Status |
|---|
Request Delisting or Contest a Listing
Level 1 (transient/first-time offenders) are granted instant self-service delisting with a 30-day cooldown. Repeat offenders or DMARC spoofers are forwarded to the security team for verification.
RFC 5782 Return Codes & Escalation Policy
TestOneMail RBL operates as an RFC 5782 compliant DNSBL zone at bl.testonemail.com. Queries return standard IPv4 loopback addresses indicating the offense level and duration.
| Return Code | Offense | TTL | Classification & Delist Eligibility |
|---|---|---|---|
127.0.0.2 |
Level 1 | 3 Days | Transient / First-Time Offender. Minor authentication failures or isolated probes. Eligible for instant automated self-service delisting. |
127.0.0.3 |
Level 2 | 14 Days | Repeat Offender. Multiple distinct attack spikes or repeated relistings. Requires human verification before removal. |
127.0.0.4 |
Level 3 | 30 Days | Severe Spoofer / DMARC Abuser. Confirmed unauthorized domain spoofing or high-volume abusive spam. Administrative review required. |
DNS Query Protocol
To check whether IPv4 address 198.51.100.25 is listed, reverse the octets and append the zone:
dig 25.100.51.198.bl.testonemail.com A +short
TXT Record Information
TXT queries on listed IPs return human-readable remediation notes with a direct lookup link:
dig 25.100.51.198.bl.testonemail.com TXT +short
# Output: "Listed on TestOneMail RBL: https://blacklist.testonemail.com?ip=198.51.100.25"
Automated Decay & Cooldown Policy
A background decay engine cycles every 10 minutes to auto-expire listings that have served their TTL without new infractions. Delisted IPs enter a 30-day cooldown period during which subsequent offenses are escalated immediately to Level 2.