If you've checked a domain against SURBL and found it listed, you're not alone. Since mid-2026, there has been an industry-wide wave of domains added to the SURBL Multi blacklist, including domains that were properly warmed up and sending cleanly. This is happening across the cold email industry, not something isolated to one provider or account. Here's what SURBL actually is, why this wave happened, whether it touches your deliverability, and what to do about it.
SURBL (Spam URI Realtime Blocklists) is a domain-based blocklist, not an IP blocklist. It flags domains and URLs found inside message bodies, usually via spam traps and honeypot addresses, rather than tracking the reputation of the server or mailbox that actually sent the message.
It treats unsolicited email as inherently bad: SURBL's operators don't distinguish between spam and legitimate B2B cold outreach. An accusation of cold emailing is often enough to get a domain added, regardless of whether the outreach itself is legal or well-targeted in the sender's market.
It has a well-documented false-positive problem: plenty of legitimate outreach companies end up listed without ever sending anything abusive.
It runs independently of any mailbox provider: SURBL is a third-party organization with its own criteria. A listing is a data point that Gmail and Microsoft may see, not a verdict they hand down themselves.
SURBL relies heavily on honeypots to catch senders. The commonly observed pattern, though SURBL doesn't publish exact mechanics, is that these addresses are built from domains belonging to companies that no longer exist, with the old website or inbox kept technically alive. Since that address never opted into anything, any inbound message can be logged and its sender flagged, whether or not the outreach was ever abusive. The practical result is that a lot of legitimate outreach senders end up listed without ever knowing why.
SURBL's Multi list is actually a collection of several sub-lists, and which one a domain lands on matters:
ABUSE: general spam patterns. This is the list most cold email domains end up on, and the one this article is about.
PH: domains used in phishing.
MW: domains hosting or distributing malware.
CR: domains with compromised security.
CT and DM: tracking domains and disposable or temporary email domains.
If your domain shows up under PH, MW, or CR, that's worth investigating properly, since those point to a real security issue rather than an outreach dispute. An ABUSE listing on a domain used for cold email is a very different situation, and it's the one covered here.
This isn't an issue specific to your account or a sign that something went wrong with your setup. It's a broad, industry-wide sweep. Cold email operators everywhere have reported the same pattern in the same window, on Reddit, in deliverability forums, and elsewhere. Tests across affected domains confirm they were added in bulk rather than individually flagged for real abuse, and affected domains have also been observed coming off the list automatically over time as SURBL's data set cycles.
For years, a SURBL listing really was close to a death sentence. Mail from a listed domain often stopped landing altogether, so the standard advice was to abandon the domain and start over. Most of what you'll find written about SURBL online still reflects that older reality.
Around late 2025, that picture shifted. SURBL-listed domains started landing in inboxes again, provided they were warmed up properly, and this has been observed independently across multiple deliverability providers and cold email operators, not just one source. Gmail and Microsoft still check SURBL and still see the listing. What changed is that the listing stopped acting as a hard, automatic rule and became one weak input among many.
The likely reason: major providers never had a hardcoded rule that said "if SURBL-listed, send to spam." SURBL was always one signal among hundreds. As more legitimate senders got swept into SURBL's listings, treating it as decisive started causing real collateral damage. A flagged company doesn't just lose cold prospects. Its everyday mail to its own clients and partners gets filtered too, which hurts the person on the receiving end who wanted that mail and now isn't getting it. At some point treating SURBL as decisive likely started hurting inbox quality more than it helped, so its weight came down. This reasoning isn't confirmed by any provider, but it fits the pattern seen across affected domains.
Short answer: no, not on its own.
Gmail and Microsoft 365 handle the overwhelming majority of B2B inboxes, and both run their own internal spam filtering systems built on billions of signals: engagement (opens, replies, complaints), sending patterns, authentication, and content quality. Neither ingests SURBL's data set as a boolean rule that automatically routes mail to spam. That's why two domains, one on SURBL and one that has never touched it, can land identically if their sending behavior is the same.
Placement tests confirm it: sending from affected domains continues to show 100% deliverability. Being on SURBL hasn't moved the needle on inbox placement.
It doesn't touch your IP or mailbox reputation: since SURBL lists domains rather than sending infrastructure, a listing has no bearing on your mailbox warm-up progress or your sending IP's standing.
Replacing the domain usually fixes nothing: a new domain starts with zero reputation and needs warm-up from scratch, while the "problem" domain generally wasn't being filtered by SURBL in the first place.
If your deliverability genuinely is suffering, the fix has nothing to do with SURBL. B2B inbox placement comes down to three fundamentals:
Sender reputation: a running score based on how people engage with your mail over time. It builds through proper warm-up and consistent, genuine engagement, and it's one of the most influential factors in whether your mail lands.
Sending setup: correct SPF, DKIM, and DMARC configuration is the technical foundation that proves you are who you say you are. SPF authorizes which servers can send on your domain's behalf, DKIM cryptographically signs outgoing mail so receivers know it wasn't tampered with in transit, and DMARC tells receiving servers what to do when a message fails those checks. Missing or misconfigured authentication is one of the most common causes of spam placement, independent of any blacklist.
Email content: spam-trigger language, broken or suspicious links, poorly structured HTML, and missing unsubscribe options are all judged independently for each message, even from a domain with a strong reputation.
A practical way to work through it:
Run a placement or spam test. This isolates whether you're actually landing in the inbox and points to which of the three fundamentals needs attention, rather than guessing.
Warm up properly, and warm up against the right network. For B2B outreach, your warm-up network should mirror where you're actually sending: mostly Google Workspace and Microsoft 365 inboxes, sending gradually with genuine engagement rather than volume alone.
Fix content and setup issues as they show up. Validate SPF, DKIM, and DMARC, clean up spam-trigger language, check that links resolve where they say they do, include an unsubscribe option, and keep messages simple. Using a dedicated domain for outreach, separate from your primary business domain, also keeps any sending issues from touching the mail that matters most.
As a matter of good hygiene, delisting requests are being actively submitted for affected domains. This isn't because deliverability is at risk. It's simply good practice to keep a clean record. You don't need to do anything on your end for this to happen.
Keep sending and keep warming up as normal. There's no need to pause outreach while a SURBL listing clears up.
Don't rush to replace the domain. A SURBL listing alone isn't a reason to abandon a domain. Rotating to a new domain still means paying for that new domain and starting warm-up over from zero. That's a real cost for a listing that isn't hurting your placement.
Watch your reply rate and inbox placement, not the lookup tool. If replies are coming in and seed tests show you landing in the inbox, the listing isn't affecting you, whatever a SURBL check says.
Request a delisting yourself if it gives you peace of mind. You're welcome to submit a removal request directly through SURBL's lookup tool at any time. Approval isn't guaranteed, and it isn't required for your mail to keep landing.
This guidance is specific to SURBL. It does not mean blacklists never matter. A listing on Spamhaus or other major, widely-adopted blocklists is a genuine issue and should be treated seriously. If you're ever unsure which list you're dealing with, or whether a listing you've found is something to worry about, reach out to our support team and we'll help you check.
SURBL's own lookup tool: available free on SURBL's website. Enter your domain and it will show "not listed" or "is listed" along with which sub-list it falls under (ABUSE, PH, MW, CR, CT, or DM).
Multi-blacklist checkers: tools that check a domain against many blocklists at once, useful for getting the full picture in one pass.
A placement or spam test: the most useful check of all, since it tells you where your mail is actually landing rather than what a lookup tool predicts.
Is a SURBL listing still bad for cold email? Much less than it used to be. On its own, a SURBL listing no longer routes mail to spam with Gmail or Microsoft 365. It's one weak signal, not a hard rule, and a properly warmed-up domain still lands.
Should I replace a domain that's on SURBL? Not just because it's listed. Check your reply rate and inbox placement first. If they're healthy, keep using the domain.
Can I get delisted? You can request removal through SURBL's own site. There's no guarantee it will be granted, and for a dedicated outreach domain it usually isn't necessary anyway.
Will this affect my mailboxes too? No. SURBL lists domains, not mailboxes or sending IPs, so it has no direct bearing on mailbox warm-up or reputation.
What does the specific list type mean (ABUSE, PH, MW, CR)? ABUSE points to general spam patterns, the one most cold email domains land on. PH, MW, and CR point to phishing, malware, or a compromised domain, which are genuinely worth investigating rather than ignoring.
Does this mean I can ignore all blacklists? No, this is specific to SURBL. Major blocklists like Spamhaus still matter and should be fixed if you're ever listed there.
A SURBL listing on a domain is part of a known, industry-wide event, not a reflection of anything wrong with your account or your sending practices. Tests continue to show 100% deliverability on affected domains, delisting requests are being handled as routine hygiene, and neither Gmail nor Microsoft 365 treat SURBL as a hard rule. Keep sending, keep warming up, and focus on the metrics that actually reflect your inbox placement: replies and seed test results. If you're genuinely seeing placement problems, look at sender reputation, authentication, and content first, since those are what actually decide where your mail lands.