olespete
Member
OP
Trust No One
- Joined:
- Jun 2024
- Posts:
- 270
- From:
- Unknown
Started a new VPS on some random budget host last week, ran the usual checks before even installing anything. MXToolbox came back with 3 blocklists and a Sender Score of 42. FORTY TWO.
This is why you NEVER trust fresh IPs. Could be previous tenant ran malware, could be entire /24 burned by some bulletproof host three years ago. You don't know! I always check before I even open port 22. Fail2ban goes on FIRST, then firewall, THEN I think about what to actually host.
What are your worst scores? Post screenshots if you got em.
I want to see who wins the dirtiest IP award. My theory is anything under /24 price of $200 is basically radioactive at this point.
airgapped, encrypted, faraday'd, still worried
adam20
Member
Ex-Abuse Desk
- Joined:
- Jul 2024
- Posts:
- 149
- From:
- Los Angeles, US
The ticket said... "our IP is clean, your scanner is wrong, we are legitimate business"
Then I look up the range and it's been listed on UCEPROTECT since 2019 because a reseller three layers down kept selling $2/year "bulletproof" proxies to carders. The current owner bought the /24 for pocket change and wonders why their wordpress contact form bounces.
The funniest ones are the "reputation repair" services that show up in my queue. $500 to "clean" an IP that got listed because someone actually committed crimes on it. Buddy, I don't control Spamhaus. I can barely control my own coffee intake.
reported. resolved. repeat.
Zurich1984
Member
- Joined:
- Jun 2024
- Posts:
- 118
- From:
- Zurich, CH
/24 will cost you a kidney
Saw a /24 sell last week for $3800 at auction. Five years ago that was $1200. Now every burned range that gets delisted is "premium clean" and they want $6000.
The scarcity makes providers reuse anything. Dirty IP, clean IP, doesn't matter, someone will buy it. /24 will cost you a kidney by 2028 at this rate.
/24 for sale. No lowballs.
mediaaustin
Member
Deliverability Nerd
- Joined:
- Jul 2024
- Posts:
- 276
- From:
- Austin, US
Most of you are checking the wrong things
Sender Score is basically useless for VPS IPs, it's meant for mail server reputation with actual volume history. For what it's worth, what actually matters for a fresh IP is:
- Is the /24 or /22 on any DNSBL with a "snowshoe" or "policy" listing (Spamhaus PBL, for example, which is actually not a negative, just means "dynamically assigned") — check https://mxtoolbox.com/blacklists.aspx
- Does the ASN have a known bad reputation, which is harder to fix than any single IP
- Has someone actually mailed from this IP before, because greenfield IPs with zero history often get temp-failed by Gmail and Microsoft regardless of "cleanliness"
I had a client get a 0/100 on some random IP reputation site because the previous owner sent 400 emails total over two years. The score was low because there was no data. Meanwhile their actual deliverability to the major inbox providers was fine afte
SPF, DKIM, DMARC — holy trinity ✉️
JokoNord
Member
- Joined:
- Jun 2024
- Posts:
- 190
- From:
- Jakarta, ID
Thank you very much @mediaaustin
I made VPS last month on Hostinger, IP was on 2 blocklists. I sent ticket to them, they changed IP for me no charge. New IP was clean. Very grateful 🙏
But I check again this week, old IP still on blocklists. So I think maybe they just give to next customer? Not good, not good for that person.
traffic worse than my packet loss
GeorgeNmp
Member
AS64512
- Joined:
- May 2024
- Posts:
- 218
- From:
- Ashburn, US
Old IP still on blocklists. So I think maybe they just give to next customer?
JokoNord, what you are describing is common practice and technically rational from a provider's perspective, though customer-hostile. The IP is returned to the pool and reassigned; most budget hosts do not maintain per-IP reputation tracking because that requires integration with RIR allocation data, IRR objects, and continuous DNSBL polling at scale.
What is more interesting to me is how little RPKI and BGP route validation helps here. You can have a valid ROA for your prefix, signed with a maxLength that prevents hijacking, and still host content that burns the IP reputation entirely separately from routing security. The IRR entries for your ASN will look pristine while UCEPROTECT lists your entire /22.
I run a small network and we filter outbound SMTP at the edge for all new allocations for 30 days. Not popular with customers who "need mail immediately," but it keeps our ASN rep
iBGP, eBGP, don't care, just peer
larryjeong
Member
- Joined:
- Jun 2024
- Posts:
- 179
- From:
- Texas, US
The worst I had was a ip with sender score 12
Bought some €4/month nat box from contabo.com, figured how bad could it be. Receive it and cant even send password reset emails to myself. Checked and yeah 12/100, listed everywhere
Tried to get delisted but they wanted $50 for "express cleaning" lol no. Just got refund and bought another one. Second ip was 78 which is usable I guess. Still a lot cheaper than paying for clean ip
Im definitely not running mail on budget vps anymore. Just use forwardemail or something
$3/year. 128MB RAM. Pure happiness.
danfra
Member
- Joined:
- Jun 2024
- Posts:
- 159
- From:
- Frankfurt, DE
Seen scrubbing centers drop dirty IPs during attack mitigation
Customer gets 120 Gbps volumetric, traffic shifts to anycast scrubbing layer, but egress IP is on Spamhaus DROP so upstream null-routes it anyway. Now you have clean traffic and no route to send it back. Happens more than you'd think.
Some providers filter by reputation at peering edge, not just DDoS. dirty ASN + attack = permanent blackhole, not temporary mitigation. check your ASN reputation same as IP, especially if you're on budget host sharing transit with bulletproof neighbors.
mitigated 800Gbps before breakfast