Why IPs typically get listed
Most listings trace back to a compromised web server, not a sending problem. Common causes include an outdated CMS plugin that let an attacker upload files.
Stolen FTP or hosting panel credentials are another common cause, letting someone drop a fake login page onto your server.
Shared hosting is a frequent factor too. If another site on the same IP gets compromised, your IP can get listed even though your own site is clean.
An open redirect or contact form that got abused to point at an external phishing page can also trigger a listing.
How to check if you're listed
You can query each zone directly with a DNS lookup tool like dig or nslookup, using the reversed IP octets against each zone name.
A result means you're listed there. No result generally means you are clear on that specific zone.
Because two separate zones are involved here, check both individually. A clean result on one does not confirm the other.
A multi-blacklist checker that queries many DNSBLs at once, including phishing-focused ones, saves time over checking each zone by hand.
How to get removed
Removal only works once the actual phishing content is gone and the entry point is closed. Do these in order.
- Locate and delete the phishing page or kit from your server. Check for extra files the attacker may have left behind.
- Identify how the attacker got in. Update the CMS, plugins, and any outdated software, and rotate all hosting and FTP credentials.
- Confirm the page is genuinely down, not just unlinked. A phishing page still reachable by direct URL will keep you listed.
- For phishing.phishtank.com, request delisting through PhishTank's own reporting or review channel, noting the phishing content has been removed.
- For phishing.rbl.msrbl.net, follow up with MSRBL separately, since this zone is maintained on its own schedule and does not always update in step with PhishTank.
If your server was on shared hosting, ask your host to confirm the phishing content was removed platform-wide, not just from your account.
Try our Blacklist Monitoring tool for free today.
How long it typically takes
Processing time varies by operator and by how each request is reviewed. Some phishing databases re-check flagged URLs automatically once they go offline.
Others require a manual review before the listing clears. Expect delisting to take anywhere from a few hours to a couple of weeks.
Because two zones are involved, one may clear before the other. Recheck both zones separately rather than assuming a single fix covers everything.
FAQ
How do I run a phishtank blacklist check?
Query your IP against phishing.phishtank.com and phishing.rbl.msrbl.net separately using a DNS lookup tool. You can also use a multi-blacklist checker that queries both zones at once. A listing on one zone does not always mean you are listed on the other, so check both.
How do I remove IP from PhishTank specifically?
First remove the phishing page from your server and close the security gap that let it get uploaded. Then submit a delisting request through PhishTank's own reporting channel for phishing.phishtank.com. If you are also listed on phishing.rbl.msrbl.net, that requires a separate follow-up with MSRBL.
Can I get listed even if I did not create the phishing page?
Yes. Most listings happen because an attacker compromised an existing server or shared hosting account. The page was placed there without the site owner's knowledge. Removing the malicious content and securing the server is still required before delisting.
Does a phishing listing affect my email deliverability?
It can, indirectly. Spam filters often check URLs found inside email bodies against phishing databases like this one. If your domain or IP is listed and your mail contains a link to it, that message may get blocked or filtered.
Will my listing clear on its own without a request?
Some phishing databases re-scan flagged pages and clear the entry automatically once the content is gone. Others wait for a manual delisting request. Submitting a request after confirming the content is removed is the safer approach either way.