Wordpress Website - Spamhaus blacklisting - To be removed
Budget: $30 – $250 USD
Just received a message from our host that our IP has been blacklisted and that they are not at all happy with it. We dont indulge in any spamming of any sort. We need to eliminate the reasons that lead to blacklisting and eventually get us out of the blacklisting
So the possible reasons for the blacklisting:
"the IP is listed in the CSS Blocklist (CSS). CSS listings are influenced by:
Email showing indications of unsolicited nature;
Poor email list hygiene;
Sending out bad email due to a compromise, insecure installation or misconfigured server;
Other indicators of low reputation or abuse.
Why was this IP listed?
CSS listings are influenced by:
Email showing indications of unsolicited nature;
Poor email list hygiene;
Sending out bad email due to a compromise, insecure installation or misconfigured server;
Other indicators of low reputation or abuse.
CSS listings are based on a wide range of inputs and are always the result of multiple events and heuristics.
What should be done about it?
If this is a shared server, please call your hosting company or ISP!
To solve this problem:
The reputation problem needs to be addressed and resolved, or
The compromise needs to be found and fixed, or
The misconfiguration must be corrected.
HELO/EHLO & DNS CHECKS:
You can test a server's HELO configuration by sending an email from it to. A bounce that contains the required information will be returned immediately. It will look like an error, but it is not. Examine the contents of this email.
If the HELO/EHLO value does NOT exist in DNS, that should be corrected
If the HELO/EHLO value is NOT correct, that should be fixed
If the HELO/EHLO is using a domain that does NOT exist, that should be corrected
If the HELO/EHLO IS what you expect it to be AND it exists in DNS, then there is a spambot or some other kind of malware! This needs to be found and removed.
NOTE: this check does not currently work on IPv6. This is only a syntax check, NOT a verification that the DNS problem has been resolved.
If the HELO configuration is correct and as expected, then there is another problem, probably malware.
MALWARE CHECKS:
Secure your firewall to not allow any packets outbound on port 25, except those coming from any email server(s) on your local network. Remote sending of email to servers or printers on the Internet will still work if web-based, or correctly configured to use port 587 using SMTP-AUTH.
Guest networks should also be secured - infected personal devices are a big issue!
NOTE: limiting port 25 outbound will only prevent the abusive connections from leaving your network and will not find or remove the malware. In order to do that, we suggest setting up network logging/packet logging to monitor anomalous traffic. This will help identify sources of malware if the scans do not find anything.
Perform complete scans with an up to date anti-virus/malware on all devices behind this IP on a scheduled basis.
Remember to check personal devices such as laptops, phones, tablets, as well as routers, etc. Malware can be on almost anything that is connected to the internet, including a smart doorbell.
Consider the router or firewall as a source of the problem if scans find no other devices.
So the possible reasons for the blacklisting:
"the IP is listed in the CSS Blocklist (CSS). CSS listings are influenced by:
Email showing indications of unsolicited nature;
Poor email list hygiene;
Sending out bad email due to a compromise, insecure installation or misconfigured server;
Other indicators of low reputation or abuse.
Why was this IP listed?
CSS listings are influenced by:
Email showing indications of unsolicited nature;
Poor email list hygiene;
Sending out bad email due to a compromise, insecure installation or misconfigured server;
Other indicators of low reputation or abuse.
CSS listings are based on a wide range of inputs and are always the result of multiple events and heuristics.
What should be done about it?
If this is a shared server, please call your hosting company or ISP!
To solve this problem:
The reputation problem needs to be addressed and resolved, or
The compromise needs to be found and fixed, or
The misconfiguration must be corrected.
HELO/EHLO & DNS CHECKS:
You can test a server's HELO configuration by sending an email from it to. A bounce that contains the required information will be returned immediately. It will look like an error, but it is not. Examine the contents of this email.
If the HELO/EHLO value does NOT exist in DNS, that should be corrected
If the HELO/EHLO value is NOT correct, that should be fixed
If the HELO/EHLO is using a domain that does NOT exist, that should be corrected
If the HELO/EHLO IS what you expect it to be AND it exists in DNS, then there is a spambot or some other kind of malware! This needs to be found and removed.
NOTE: this check does not currently work on IPv6. This is only a syntax check, NOT a verification that the DNS problem has been resolved.
If the HELO configuration is correct and as expected, then there is another problem, probably malware.
MALWARE CHECKS:
Secure your firewall to not allow any packets outbound on port 25, except those coming from any email server(s) on your local network. Remote sending of email to servers or printers on the Internet will still work if web-based, or correctly configured to use port 587 using SMTP-AUTH.
Guest networks should also be secured - infected personal devices are a big issue!
NOTE: limiting port 25 outbound will only prevent the abusive connections from leaving your network and will not find or remove the malware. In order to do that, we suggest setting up network logging/packet logging to monitor anomalous traffic. This will help identify sources of malware if the scans do not find anything.
Perform complete scans with an up to date anti-virus/malware on all devices behind this IP on a scheduled basis.
Remember to check personal devices such as laptops, phones, tablets, as well as routers, etc. Malware can be on almost anything that is connected to the internet, including a smart doorbell.
Consider the router or firewall as a source of the problem if scans find no other devices.