Operators spend thousands of dollars every year acquiring IPv4 space, only to find out the hard way that their new subnets came with a toxic past attached. A proper IP reputation scan done before you sign anything can be the difference between a clean, deployable block and months of cleanup nobody budgeted for. This guide walks through how to actually evaluate IPv4 reputation, which tools are worth your time, and which warning signs should make you walk away from a deal entirely.
Why an IP Reputation Scan Matters Before Purchase
IPv4 addresses carry history. If a /24 once hosted a spam operation, a botnet command server, or phishing infrastructure, that reputation sticks to the block — and it follows the block, not the previous owner. Email providers like Microsoft, Google, and Yahoo weigh IP history heavily in their filtering decisions. A blocklisted /24 can watch its email deliverability drop to nearly zero overnight.
Need IPv4 addresses?
Browse clean, RIPE-verified subnets at $0.50/IP/month.
How common is this? Industry estimates suggest that a substantial share of the IPv4 space offered on secondary markets carries at least one listing on a major DNS-based blocklist. And organizations like Spamhaus and the Spam and Open Relay Blocking System (SORBS) keep records that can outlive the transfer itself.
Step One: Checking DNSBLs and Blacklists
The foundation of any IP reputation scan is a thorough blocklist check. Start with the lists that matter most:
- Spamhaus (SBL, XBL, PBL, DROP/EDROP): The most commercially influential blocklist. A DROP listing is especially serious — it means the space is hijacked or has a history of abuse.
- Barracuda Reputation Block List (BRBL): Widely used by enterprise mail security appliances.
- SpamCop (SCBL): Reflects recent user-reported spam activity.
- SORBS: Known for listings that persist and are hard to remove. A real concern with used address space.
- PSBL, CBL/Abuseat, UCEPROTECT: Additional lists that mail receivers and network operators consult.
For anything bigger than a /24, checking IPs one by one stops being realistic. Most DNSBL providers offer zone-based queries that let you sweep an entire subnet efficiently, or you can use bulk lookup services that accept CIDR ranges.
Essential Reputation Tools and Services
Beyond DNSBLs, several services pull reputation data from multiple sources and add historical context:
| Tool / Service | What It Shows | Best For |
|---|---|---|
| MultiRBL.valli.org | Checks IPs against 100+ DNSBLs at once | Fast bulk scanning |
| Talos Intelligence (Cisco) | Cisco’s reputation scoring and categorization | Enterprise-grade assessment |
| Microsoft SNDS | Deliverability data for Outlook/Microsoft consumers | Email-heavy deployments |
| Google Postmaster Tools | Gmail reputation (post-acquisition) | Ongoing monitoring |
| AbuseIPDB | Crowdsourced abuse reports with confidence scores | Security-focused checks |
| RIPEstat / ARINwhois | Registration history, announcements, abuse contacts | Provenance verification |
| GreyNoise / Shodan history | Historical scanning and exposed-service data | Spotting botnet or scanner history |
Run a Sample Deployment Test
If the block is meant for sending email, consider leasing it or briefly routing it (if the seller allows) and setting up test infrastructure: configure rDNS/PTR records, publish SPF and DKIM, and send warmed-up test mail to seed accounts at the major providers. Deliverability behavior in those first few days reveals problems no static scan will catch.
Passive DNS and Historical Data Checks
Active blocklist queries only show you today’s picture. When you perform an IP reputation scan, historical context matters just as much:
- Passive DNS (e.g., Farsight DNSDB): Shows what domains previously resolved to the block. Domains tied to phishing, malware distribution, or bulletproof hosting are serious red flags.
- Historical WHOIS and RIPE database logs: Frequent transfers, short holding periods, or registration under obscure entities suggest the block has been shuffled by brokers who don’t care much about reputation hygiene.
- BGP history via RIPEstat: Gaps in announcements, origins from known abusers, or announcements from unusual geographies all deserve a closer look.
- Search engine cache and URL scanning databases (VirusTotal, URLhaus): Check whether the range has hosted malicious URLs or payloads.
Red Flags That Should Stop a Deal
Not every listing is disqualifying. But some patterns should make you pause — hard:
- Spamhaus DROP/EDROP listing: The space is hijacked or has a hijack history. Walk away.
- SORBS listings the seller calls “impossible to remove”: SORBS delisting is slow, but it is possible. An unwilling seller is telling you something.
- Recent flood of delisting requests: A block burned by a spam operation last month still carries lingering reputational weight.
- Price significantly below market: Clean, well-documented IPv4 commands premium pricing, so deep discounts often hide reputation problems. Reputable marketplaces such as IP4 Market verify both seller ownership and block history, which is why vetted listings there tend to price closer to true market value.
- Seller refuses escrow or third-party verification: Legitimate sellers welcome due diligence. Full stop.
Pre-Purchase Due Diligence Checklist
Before you close on any IPv4 acquisition, work through this:
- Sweep the entire block against the major DNSBLs (Spamhaus, Barracuda, SpamCop, SORBS, UCEPROTECT)
- Confirm the block isn’t on Spamhaus DROP/EDROP
- Review passive DNS history for malicious domains
- Verify clean WHOIS/RIR history and a legitimate chain of custody
- Check AbuseIPDB and VirusTotal for abuse reports
- Confirm the abuse contact and IRR/rPKI status are documented
- Use a trusted intermediary — a marketplace with escrow and verification, such as IP4 Market, protects both sides of the transaction
Frequently Asked Questions
Can a blacklisted IPv4 block be cleaned?
Yes, in most cases. Most DNSBLs delist addresses once abuse stops and remediation is demonstrated. But removal can take weeks, and some lists — SORBS comes to mind — are notoriously slow. Factor cleanup time into your deployment plan.
How long does IP reputation last after abuse ends?
Major receivers like Microsoft and Google typically evaluate reputation over rolling windows of 30–90 days, though severe or sustained abuse can influence filtering for much longer.
Should I scan reputation before leasing as well as buying?
Absolutely. Whether you lease or buy, you inherit the block’s reputation. Any reputable lessor or marketplace will support pre-contract reputation checks.
A disciplined IP reputation scan protects your deliverability, your brand, and your investment. Pair it with verified ownership records, escrow-protected transfers, and honest sellers — the standard you’ll find at IP4 Market — and IPv4 acquisition stops being a gamble and becomes what it should be: a predictable, strategic investment.
Need IPv4 space? Lease RIPE-verified /24–/22 subnets at a flat $0.50/IP per month — LOA + RPKI/ROA in minutes, instant company verification, automatic renewals. Browse available subnets →