SURBL Lookup

Please enter a single domain name or IP address to lookup in SURBLs.


Domain or IP:  

Only domain-legal characters a-z, 0-9, dot "." and dash "-" are allowed.


  1. SURBLs are lists of web sites that have appeared in unsolicited messages. Those web sites almost always use domain names. Only rarely are IP addresses used as web sites. Often the sites appearing as IP addresses are cracked phishing or malware sites.
  2. SURBLs are not lists of mail servers, mail senders, email addresses, open proxies or message sending IP addresses. They are lists of web sites.

  3. Please enter IP addresses in normal forward octet order. They will be checked and displayed in reverse octet order. This is a traditional way that IP addresses are represented in blacklists.
  4. Please do NOT use this web site for any automated lookups. Instead use DNS queries as described in the SURBL Implementation Guidelines.

SURBL Data Feed Request

SURBL Data Feeds offer higher performance for professional users through faster updates and resulting fresher data. Freshness matters since the threat behavior is often highly dynamic, so Data Feed users can expect higher detection rates and lower false negatives.

The main data set is available in different formats:

Rsync and DNS are typically used for mail filtering and RPZ for web filtering. High-volume systems and non-filter uses such as security research should use rsync.

For more information, please contact your SURBL reseller or see the references in Links.

Sign up for SURBL Data Feed Access.

  • Sign up for data feed access

    Direct data feed access offers better filtering performance with fresher data than is available on the public mirrors. Sign up for SURBL Data Feed Access.

  • Applications supporting SURBL

  • Learn about SURBL lists