Why IPs typically get listed
This list specializes in open proxies and abuse tied to web forms.
That is different from a typical outbound-spam-only blacklist.
An IP can get listed if it is detected running as an open proxy.
Anonymizing proxies and misconfigured VPN exit points are common triggers here.
Compromised servers sending spam through a hacked mail queue are another cause.
Infected devices on a network, like a hijacked router, can also trigger a listing.
The list consolidates data from other abuse feeds and partner blacklists.
That means an IP can land here because it was already flagged elsewhere.
The project has run continuously since 2006 and draws from many sources.
Because of that history, some listings may reflect a previous user of the IP.
Missing sender authentication, meaning no SPF, DKIM, or DMARC record, is a common cause too.
Poor list hygiene, like mailing old or purchased contact lists, is another standard trigger.
These last two causes apply to most blacklists, not just this one.
How to check if you're listed
You can run a manual DNS lookup against dnsbl.tornevall.org and opm.tornevall.org.
Reverse your IP octets and query it against each zone as a subdomain.
A returned address in the 127.0.0.x range confirms you are listed.
No answer, or an NXDOMAIN response, means your IP is clean on that zone.
Check both zones separately, since a fix on one does not always confirm the other.
Manual lookups work fine for one blacklist at a time.
That gets slow fast if a bounce message doesn't name the exact list.
Many mail admins run into that exact problem during an active incident.
How to get removed
Start by fixing the underlying issue before requesting removal.
Close any open proxy service running on the listed IP.
Patch or rebuild any compromised mail server or device on that IP.
Stop any script or form that is sending unauthorized outbound traffic.
Once the issue is resolved, go to the operator's removal page on tornevall.net.
The current public removal page includes a bot-check challenge before it accepts a request.
This is a standard anti-abuse step, not a sign something is broken.
Enter your IP address and submit the request through that form.
Older support threads mention a separate email contact for delisting requests.
The operator has said in the past that it doesn't mainly handle removals by email anymore.
Some users have still reported staff responding to emailed requests in isolated cases.
The web form on tornevall.net is the more reliable current channel.
Because both zones share the same underlying data, one request should clear both.
If a listing persists on one zone after a confirmed removal, check the other zone directly.
Submit a second request for that specific zone if it is still showing a listing.
Tornevall is a smaller, independently run blacklist, not a large commercial operation.
Its tooling and response times can be less consistent than bigger operators like Spamhaus.
Try our Blacklist Monitoring tool for free today.
How long it typically takes
The operator does not publish a fixed processing time for delisting requests.
Some listings clear soon after a self-service form is submitted and confirmed.
Given the smaller scale of this operator, expect more variation than with major commercial blacklists.
There is no published guaranteed turnaround window to point to here.
If your request sits unanswered for several days, recheck both zones before trying again.
A repeat listing after removal usually means the underlying cause wasn't fully fixed.
Document the fix you made before resubmitting, in case the operator asks for details.
FAQ
How do I do a Tornevall blacklist check?
Run a DNS lookup against dnsbl.tornevall.org and opm.tornevall.org using your IP in reverse order. A returned address in the 127.0.0.x range means you're listed. You can also use a monitoring tool that checks multiple blacklists, including Tornevall's zones, in one pass.
How do I remove an IP from Tornevall?
Fix the cause first, such as an open proxy or a compromised mail server. Then submit a removal request through the operator's page on tornevall.net. The current removal page includes a bot-check step before it accepts your request.
Is opm.tornevall.org the same list as dnsbl.tornevall.org?
Yes, they share the same underlying data. Opm.tornevall.org is the original name for this project, started in 2006. Dnsbl.tornevall.org later became the primary hostname, but the operator has confirmed the older zone still runs alongside it.
Why did I get listed if I don't send spam?
Tornevall's list also targets open proxies and web-form abuse, not only outbound spam. A misconfigured proxy, a hacked contact form, or a compromised device on your network can all trigger a listing. The list also pulls in data from other abuse feeds.
Can I email Tornevall to request removal?
The operator has stated in the past that it doesn't mainly handle removals by email anymore. The self-service removal page on tornevall.net is the more reliable current channel. Email may still work in some isolated cases, but it isn't guaranteed.