PhishTank Blacklist Removal: Fix Both Zones Fast

Get help with phishtank blacklist removal. Learn why IPs get listed on phishing.phishtank.com and phishing.rbl.msrbl.net, and how to fix it.
Konetix innovations blacklist monitoring

PhishTank blacklist removal means getting your IP or domain taken off a list of confirmed phishing sites. You do this by removing the phishing content from your server first. Then you request delisting through the relevant channel for each zone. Two separate zones can be involved, so check both.

What this operator checks, and who it affects

PhishTank is a database of web pages confirmed to be phishing sites. Unlike a typical spam blacklist, it does not track your outbound mail volume or spam complaints.

It tracks whether your IP or domain has hosted a page designed to steal logins or payment details.

Two zones are tied to this data. phishing.phishtank.com is the direct list published from PhishTank's own confirmed phishing reports.

phishing.rbl.msrbl.net is a separate zone run by MSRBL (Message Sniffer) that folds PhishTank's phishing data into its own DNSBL feed.

They often reflect the same underlying phishing reports, but they are queried and maintained separately. Clearing one does not automatically clear the other.

This mostly affects web hosting IPs, not sending IPs. But because filters check URLs found inside email, a listing here can still cause your mail to get blocked or flagged.

Monitor Your IP Reputation

Actively monitor up to a /16 subnet (65, 536 IPs) for free. Receive a comprehensive overview of your IPs’ reputation.

Limited time offer.
Try Now for Free

Why IPs typically get listed

Most listings trace back to a compromised web server, not a sending problem. Common causes include an outdated CMS plugin that let an attacker upload files.

Stolen FTP or hosting panel credentials are another common cause, letting someone drop a fake login page onto your server.

Shared hosting is a frequent factor too. If another site on the same IP gets compromised, your IP can get listed even though your own site is clean.

An open redirect or contact form that got abused to point at an external phishing page can also trigger a listing.

How to check if you're listed

You can query each zone directly with a DNS lookup tool like dig or nslookup, using the reversed IP octets against each zone name.

A result means you're listed there. No result generally means you are clear on that specific zone.

Because two separate zones are involved here, check both individually. A clean result on one does not confirm the other.

A multi-blacklist checker that queries many DNSBLs at once, including phishing-focused ones, saves time over checking each zone by hand.

How to get removed

Removal only works once the actual phishing content is gone and the entry point is closed. Do these in order.

  1. Locate and delete the phishing page or kit from your server. Check for extra files the attacker may have left behind.
  2. Identify how the attacker got in. Update the CMS, plugins, and any outdated software, and rotate all hosting and FTP credentials.
  3. Confirm the page is genuinely down, not just unlinked. A phishing page still reachable by direct URL will keep you listed.
  4. For phishing.phishtank.com, request delisting through PhishTank's own reporting or review channel, noting the phishing content has been removed.
  5. For phishing.rbl.msrbl.net, follow up with MSRBL separately, since this zone is maintained on its own schedule and does not always update in step with PhishTank.

If your server was on shared hosting, ask your host to confirm the phishing content was removed platform-wide, not just from your account.

Try our Blacklist Monitoring tool for free today.

How long it typically takes

Processing time varies by operator and by how each request is reviewed. Some phishing databases re-check flagged URLs automatically once they go offline.

Others require a manual review before the listing clears. Expect delisting to take anywhere from a few hours to a couple of weeks.

Because two zones are involved, one may clear before the other. Recheck both zones separately rather than assuming a single fix covers everything.

FAQ

How do I run a phishtank blacklist check?

Query your IP against phishing.phishtank.com and phishing.rbl.msrbl.net separately using a DNS lookup tool. You can also use a multi-blacklist checker that queries both zones at once. A listing on one zone does not always mean you are listed on the other, so check both.

How do I remove IP from PhishTank specifically?

First remove the phishing page from your server and close the security gap that let it get uploaded. Then submit a delisting request through PhishTank's own reporting channel for phishing.phishtank.com. If you are also listed on phishing.rbl.msrbl.net, that requires a separate follow-up with MSRBL.

Can I get listed even if I did not create the phishing page?

Yes. Most listings happen because an attacker compromised an existing server or shared hosting account. The page was placed there without the site owner's knowledge. Removing the malicious content and securing the server is still required before delisting.

Does a phishing listing affect my email deliverability?

It can, indirectly. Spam filters often check URLs found inside email bodies against phishing databases like this one. If your domain or IP is listed and your mail contains a link to it, that message may get blocked or filtered.

Will my listing clear on its own without a request?

Some phishing databases re-scan flagged pages and clear the entry automatically once the content is gone. Others wait for a manual delisting request. Submitting a request after confirming the content is removed is the safer approach either way.