0 min left
IP Blacklisted Mid-Campaign - Emergency Playbook

IP Blacklisted Mid-Campaign - Emergency Playbook

BulkEmailSetup
BulkEmailSetup Team
October 3, 2026
10 min read

When your IP gets blacklisted during a campaign, pause the queue within 5 minutes, disable retries, and read the bounce text to identify which list hit you, because Spamhaus SBL or CSS means Gmail and Microsoft are rejecting outright while UCEPROTECT Level 1 barely dents delivery. Do not delist and resume the same queue: a repeat listing inside 48 hours runs far longer, and the cause is almost always still in your unsent half. Fix first, delist second, finish third.

The first 15 minutes when your IP is blacklisted during a campaign

Stop everything and gather evidence. Nothing else.

  1. Pause the queue. In Postfix that is postsuper -h ALL. In Mautic, Interspire or Mailwizz, pause the campaign, then confirm the MTA queue is actually holding and not just the app.
  2. Disable retries. Set the retry interval on deferrals to hold rather than resend. Every retry is another logged rejection at the receiver, and repeated hits keep a Spamhaus CSS listing alive.
  3. Copy 10 bounce lines. The exact wording, including the URL the receiver quotes. The URL names the list.
  4. Note the numbers. Sent so far, remaining, time of first rejection. You will need the timestamp to find the segment that caused it.
  5. Run a direct lookup. Check the IP at Spamhaus and the Barracuda and UCEPROTECT lookup pages. A Gmail 421 can be throttling with no listing at all.

Do not email support yet. Do not touch DNS. Do not swap IPs.

Reading the bounce text to identify the list

The rejection line usually names the list. Match it here.

Bounce wordingListWho rejectsSeverity
550 5.7.1 ... blocked using zen.spamhaus.org with SBL referenceSpamhaus SBLGmail, Microsoft, most gatewaysCritical, manual removal
... listed in Spamhaus CSS or css.spamhaus.orgSpamhaus CSSSame as SBLHigh, self-service, relists fast
... xbl.spamhaus.org or cbl.abuseat.orgSpamhaus XBLMost gatewaysCritical, means compromise
554 ... b.barracudacentral.orgBarracuda BRBLCorporate gateways, some ISPsMedium, form removal
550 ... dnsbl-1.uceprotect.netUCEPROTECT L1Small share of receiversLow, expires in 7 days
550 ... dnsbl-2/3.uceprotect.netUCEPROTECT L2/L3Small shareLow, your neighbours, not you
550 5.7.1 ... S(3140) or Unfortunately, messages from [IP] weren't sentMicrosoft internalOutlook, Hotmail, Live onlyMedium, Microsoft form
... bl.spamcop.netSpamCopSome ISPs and hostsLow, auto-expires in 24 hrs
421 4.7.0 ... unusual rate of unsolicited mailnone, Gmail throttleGmailNot a listing, slow down

Severity is a function of who queries the list. Spamhaus is queried by nearly every large receiver, so an SBL or CSS listing takes 80 to 95% of your deliveries with it. UCEPROTECT Level 1 usually costs under 5% of a consumer list. The per-list fix is in how to get delisted, the Spamhaus CSS guide, the UCEPROTECT guide, and the Microsoft S3140 fix. This article is about the campaign.

What to do with the unsent half

Hold it. Decide once you know the cause.

OptionWhen it is rightWhen it is wrongDelivery to expect
Hold the queue 24 to 72 hoursDefault. Cause unknown, or listing is SpamhausTime-critical send (event tomorrow)Full, once delisted and the bad segment is gone
Move to a second warmed dedicated IPCause found and suppressed, second IP already warmCause not found yet, or second IP is cold60 to 70% of that IP's normal daily rate
Finish on a shared relay (SES, SendGrid, Postmark)Transactional or time-critical and cause foundMarketing to a list you have not cleanedNormal, but you have now exported your problem

The mistake that turns one listing into two is option two or three with the cause still in the queue. The trap addresses that got IP one listed will get IP two listed by evening, and SendGrid will suspend you for the same traffic. Move the queue after the segment is gone, never before.

The first 24 hours, hour by hour

HourActionWhat you are looking for
0 to 0.25Pause queue, kill retries, copy bounces, direct lookupsWhich list, when it started
0.25 to 1Pull the sent log, sort by hour, find the first rejection timestampThe batch or segment that was sending at that moment
1 to 3Compare the segment before and after the timestamp: source, age, last engagementA list source or age band that stands out
3 to 4Suppress that segment across every list, export it as a fileTypically 5 to 20% of the list
4 to 5Check Postmaster Tools domain reputation and complaint rate for yesterdayWhether the domain took damage too
5 to 6Decide: hold, second IP, or relayBased on the cause and the deadline
6 to 8Submit delisting requests, one per list, cause fixed and statedA ticket or removal confirmation
8 to 24Do not send from the listed IP. Send transactional from another IP or relayRemoval confirmation email
24Re-check every list. If clear, resume at 30% of normal rate on that IPDeferral rate under 2% in the first hour

Most operators want to pull the hour 6 delisting into hour 1. Resist it. CSS removals clear in about an hour, which is exactly why people relist themselves the same afternoon.

Why you should not delist and resume immediately

Because the second listing is longer, and the cause is still in the queue. A CSS entry that returns inside 48 hours of removal gets flagged as a persistent source and the expiry stretches from hours into days. Barracuda stops accepting removal requests from IPs that keep coming back. UCEPROTECT's Level 1 timer resets to a fresh 7 days on every hit.

A 100,000 recipient campaign stalled at 48,000:

PathDay 1Day 2Day 3Result
Delist at hour 1, resume at hour 2Relisted by hour 6Second removal refused or delayedStill listed52,000 unsent, IP damaged for weeks
Hold, find cause, delist at hour 6, resume at hour 24Listed, investigatingClean, 30% rateClean, 60% rate52,000 sent over days 2 to 4

Losing a day hurts. Losing the IP for three weeks hurts more.

Finding the cause in the sent half

The cause is nearly always visible in the 48,000 that went out, and the first rejection timestamp points at it. Three causes cover almost every case:

Spam trap hits. Spamhaus SBL and CSS are trap-driven. If the first rejection lands 20 minutes into a send that runs in list order, the addresses in that window are the suspects. Recycled traps are old addresses the ISP converted after 6 to 12 months of inactivity, so a "reactivation" segment is the classic culprit.

A complaint spike. Check the feedback loop and Postmaster Tools. Google's sender guidelines set 0.3% as the hard line and 0.1% as the target. A segment pulling 0.5% complaints will not show as a Spamhaus listing but will trigger Microsoft S3140 and Gmail throttling. Same fix: find the segment, suppress it.

A bad import. A partner CSV, a trade show scan, a form with no confirmation. These arrive as one block and get you listed as one block. Sort the sent log by list source; anything over 5% hard bounces is it.

Suppress it everywhere, then run it through a list cleaning pass to catch the traps you cannot see by eye.

The multi-IP advantage

With 3 dedicated IPs, a listing on one is a 33% capacity cut. Pull the listed IP out of rotation, keep the other 2 sending to clean segments, and investigate calmly. With a single IP, listed means every campaign and every password reset is stuck until it clears.

SetupListing on one IPSending continues atTransactional mail
1 dedicated IPFull stop0%Stopped, or moved to a relay in a hurry
3 dedicated IPsPull 166%Continues on a separate IP
5 dedicated IPs, transactional isolatedPull 180%Unaffected
Shared pool (SendGrid, Mailgun)You did not cause it, it still stops you0% until the provider rotates the poolAlso stuck

On a shared pool you inherit the listing and cannot pull the IP at all, which is the case for dedicated over shared above 20,000 a day. For sizing, see do I need a dedicated IP or shared.

What the incident costs

For a 100,000 recipient campaign stalled at half, single IP, Spamhaus CSS listing handled correctly.

Line itemTypical cost
Delisting fees$0, no reputable list charges
Sending downtime1 to 3 days
Staff time, investigation and cleanup10 to 20 hours
Unsent half, revenue delayed 2 to 4 daysyour normal per-campaign revenue, held
Second IP or relay to keep transactional moving$10 to $90 for the month
If mishandled: relisted, re-warm needed2 to 4 weeks at 30 to 60% volume
If the domain took damage too2 to 6 weeks of Postmaster Low reputation

The last two rows are where the real money goes, and both are avoidable.

The 7-day recovery plan

Day 1. The hour-by-hour table above. Queue held, cause found, segment suppressed, delisting submitted, transactional moved.

Day 2. Confirm removal at every list, not only the one you noticed. Resume at 30% of normal rate, engaged recipients only (opened or clicked in 90 days). Above 2% deferred means stop again.

Day 3. Rate to 60% if day 2 was clean. Finish the unsent half from the cleaned queue, engaged-first. Postmaster Tools domain and IP reputation should both be Medium or better.

Day 4 to 5. Back to 100%. Run a blocklist check every morning; a returning CSS listing here means a trap address survived the cleanup.

Day 6 to 7. Post-mortem. Write down the source of the bad segment, who imported it, and the rule that stops a repeat. Add per-IP monitoring using how to monitor deliverability.

If domain reputation dropped to Low as well, stretch this to 3 weeks.

Prevention checklist

Each item is a few hours of setup.

  • Per-IP blocklist monitoring, hourly. A cron job running dig against zen.spamhaus.org, b.barracudacentral.org and dnsbl-1.uceprotect.net per IP, alerting on any answer. Catches a listing in 60 minutes rather than at 48% sent.
  • List check before every send. Same lookup as a pre-flight step. Listed means the send does not start.
  • Segment-first sends. Most engaged 20% first, wait 30 minutes, read bounces and complaints, then release the rest.
  • New imports go out alone. Any list under 30 days old is its own campaign, on its own IP if you have three.
  • Retry policy set to hold on 5.7.x. A blocklist rejection parks the queue, never retries.
  • Transactional on its own IP. Receipts never share an IP with marketing.
  • Complaint rate per segment. A 0.05% campaign average can hide a 0.6% segment.

How BulkEmailSetup helps

We build dedicated SMTP infrastructure you own, with 3 dedicated IPs from the entry plan so that one listing is a 33% capacity cut and not a stopped business. Every setup ships with per-IP blocklist monitoring, a retry policy that parks the queue on a blocklist rejection, and transactional mail isolated from marketing. If a listing happens, we handle the delisting and the resume schedule.

Basic is $549 one-time, covering 1 SMTP server, 3 dedicated IPs, 25,000 emails/day and unlimited contacts. Higher tiers scale to 15 IPs and 200,000 emails/day. See pricing, or read dedicated IP vs shared IP for why the shared pool version of this incident has no playbook at all.

Frequently asked questions

What should I do first when my IP gets blacklisted during a campaign?

Pause the queue and turn off retries within the first 5 minutes. Every retry against a listed IP is a fresh rejection logged by the receiver, and Spamhaus CSS listings in particular extend when the IP keeps pushing mail. Then read the bounce text, because the wording names the list, and the list tells you how bad it is.

Which blacklist is the worst to be on mid-campaign?

Spamhaus SBL and CSS, because Gmail, Microsoft and most corporate gateways query Spamhaus and reject outright with a 550. A Barracuda listing costs you mostly corporate mail. UCEPROTECT Level 1 is used by a small share of receivers and expires on its own 7 days after the last hit. Microsoft S3140 only affects Outlook and Hotmail addresses.

Should I delist and finish the campaign right away?

No. Delisting takes 1 to 24 hours, but if the same segment that caused the listing is still in your queue, you get relisted within hours. Spamhaus treats a repeat listing inside 48 hours as a persistent source and the second term runs days rather than hours. Find the bad segment first, suppress it, then delist.

Can I finish the unsent half on a different IP?

Only after you have removed the cause. Moving the same queue to a clean IP with the spam trap addresses still in it burns the second IP too, and now you have two listings. Once the bad segment is suppressed, finishing on a second warmed IP at 60 to 70% of its normal rate is reasonable.

How much does a mid-campaign blacklisting cost?

For a 100,000 recipient send that stalls at 50% you typically lose 2 to 3 days of sending, 10 to 20 hours of staff time, and the revenue from the unsent half. A worse listing that needs a re-warm adds 2 to 4 weeks at reduced volume. The direct delisting cost is zero, since no reputable list charges.

How do multiple dedicated IPs help when one gets listed?

With 3 dedicated IPs you pull the listed one out of rotation and keep sending on the other 2 at about 66% capacity while you investigate. With a single IP, listed means stopped. This is the main practical reason we set up 3 IPs on our entry plan rather than 1.

Tags

ip blacklisted during campaignip blacklist emergencyspamhaus listing mid sendcampaign paused blocklistdedicated ip blacklistemail blacklist recoverymultiple dedicated ips
BulkEmailSetup

Written by BulkEmailSetup Team

We help businesses set up their own bulk email infrastructure, dedicated SMTP servers, IP rotation, and full deliverability control. One-time setup, no monthly platform fees.

Ready to set up your email infrastructure?

Get dedicated SMTP servers, IP rotation, and expert support to scale your email sending.

View Pricing