554 5.7.1 Service unavailable; Client host [IP address] blocked using zen.spamhaus.org
Sample bounce line
554 5.7.1 Service unavailable; Client host [203.0.113.10] blocked using zen.spamhaus.org
What it means
The receiving Postfix server looked up the connecting IP in ZEN and rejected the connection because it is listed. ZEN is the combination of Spamhaus' free IP-based DNSBLs (SBL, CSS, XBL and PBL). The wording is Postfix's, not Spamhaus's, and X.7.1 is RFC 3463 Delivery not authorized, a permanent error.
Why it happens
- The sending IP is listed in one of ZEN's datasets. Return codes: 127.0.0.2 SBL, 127.0.0.3 SBL (CSS data), 127.0.0.4 XBL, 127.0.0.9 SBL (DROP), 127.0.0.10 PBL (ISP-maintained), 127.0.0.11 PBL (Spamhaus-maintained)
- False rejection: if the recipient's server queries through a public or open resolver, Spamhaus returns the error code 127.255.255.254, and a misconfigured MTA can treat it as a listing; the Spamhaus page says the problem is then with the recipient's server configuration
How to fix it
- Look up the IP at https://check.spamhaus.org (Spamhaus IP and Domain Reputation Checker) to see which list and why, then follow its remediation steps; Spamhaus directs listed parties to its removal process there
- If you are on a PBL or ISP-maintained range, send through your provider's authenticated mail relay instead of directly
- If the listing is a public-resolver error, resend later or tell the recipient's admin to query from their own resolver or use Spamhaus DQS (check.spamhaus.org/returnc/pub)
- Receiving admin: the documented Postfix usage is reject_rbl_client zen.spamhaus.org in the restrictions (SMTPD_ACCESS_README)
Check your domain now
Many of these errors come from missing or broken SPF, DKIM, DMARC or reverse DNS records. Enter your domain to run the free check.
Related errors
No related errors listed yet.