IP Delisting
IP delisting is the process of removing an IP address from the ReportedIP blacklist, either automatically through time decay (most IPs drop off within 60–90 days of the last report) or manually with the delisting form on this page. Requests are decided within 48 hours, every step is logged, and removal is always free of charge.
Why IPs Get Listed
IP addresses are added to the ReportedIP database when they are reported for malicious activity by community members, WordPress security plugins, or honeypot servers. Common reasons include:
- Brute-force login attempts against WordPress sites
- Comment spam or form spam
- XMLRPC attacks
- Port scanning or vulnerability probing
- DDoS participation
A listing does not necessarily mean the IP owner is malicious. Shared hosting, compromised servers, VPN exit nodes, and open proxies can all result in legitimate users having a listed IP.
Automatic Removal
ReportedIP uses a time dampening system with exponential decay. Reports automatically lose weight over time:
| Report Age | Remaining Weight |
|---|---|
| Fresh (0 days) | 100% |
| 30 days | 50% |
| 60 days | 25% |
| 90 days | 12.5% |
If no new reports are filed against an IP, its Confidence Score will gradually decrease until it falls below the blocking threshold. Most IPs are effectively delisted within 60–90 days of the last report.
How to Request Delisting
If you believe your IP has been listed in error, or you have resolved the security issue that caused the listing, you can request manual delisting.
1. Check Your IP
Third-party lists matter too: if the address also answers on independent blacklists, the cause is on the machine rather than in our data. The DNSBL Blacklist Check shows all of them at once, and Reverse DNS tells you whether the PTR record of the address resolves back, which makes a request easier to verify. First, check your IP's current status on the ReportedIP homepage. This will show you the Confidence Score, number of reports, and the attack categories associated with your IP. How the score is computed and when an IP enters the exported blacklist (confidence ≥ 75 %, 48-hour cool-down, whitelist exclusion) is documented on the Blacklist page.
2. Fix the Cause
Find out why the address sent the traffic that was reported, and stop it: a compromised CMS, an infected client, an open proxy or a misconfigured scanner. A request for an address that is still attacking will be declined, and even if it were not, new reports would list it again within hours.
3. Submit the Form
Use the form below. You need the IP address, your connection to it and one or two sentences about the cause and the fix. Every IP detail page and every lookup result for a reported address links here with the address already filled in.
- Without an account: enter your email address. We send you a confirmation link, valid for 48 hours. The request is only reviewed after you click it, so nobody can file requests in your name.
- With an account: sign in first. The request is confirmed right away and appears in your dashboard under IP Delisting, where you can follow its status.
Request Delisting
One address per request. For provider-level range issues, write to abuse@reportedip.com with WHOIS proof of ownership.
Common Causes of False Listings
A listing does not always mean the current user of an address did something wrong. Typical cases:
- Shared hosting: Another site on the same server was compromised
- VPN / Proxy: A previous user of the IP was malicious
- Dynamic IP: Your ISP reassigned a previously abused IP to you
- Security testing: Legitimate penetration testing was mistakenly reported
Review Process
After submitting a delisting request, here is what to expect:
Confirmation
Without an account you confirm the request with the link in our email. With an account it is confirmed as soon as you submit it. Unconfirmed requests are deleted after seven days.
Automatic removal or review
If you are signed in and every report against the address came from your own account, you are simply withdrawing your own reports, so the address is removed immediately. In every other case our team reviews the reports, checks the source data and your description, usually within 48 hours.
Outcome
You get a short email with the decision. There are two outcomes:
- Removed: the address and all reports against it are deleted, the Confidence Score starts again at 0
- Declined: the reports stay, the email says why. You can submit a new request 14 days after the decision
Records and Privacy
Every request is documented so that it can be traced later when and why an address was removed or kept: submission, confirmation, the decision, who made it, how many reports were deleted and which emails were sent. Removed reports themselves are not kept, only their number.
- What we store: the IP address, your email address, your account if you were signed in, your connection to the address, the organization if given, your description and the log of the request.
- Why: to process your request and to be able to prove how it was handled (Art. 6(1)(c) and (f) GDPR).
- How long: unconfirmed requests are deleted after seven days. Decided requests and their log are kept for three years and then deleted.
- Who reported the address is never disclosed to the requester, and your request is never shown to the reporters.
Your rights to access, rectification and erasure are described in our privacy policy.
Prevention
To avoid future listings, consider the following best practices:
- Secure your server: Keep software up to date, use strong passwords, and disable unused services
- Enable rate limiting: Use tools like fail2ban or Cloudflare to limit brute-force attempts from your IP range
- Monitor for compromise: Regularly check your server for unauthorized access, malware, or misconfigured services
- Check regularly: Use the ReportedIP API or website to monitor your IP's reputation proactively
Why Delisting Requests Are Denied
Most denied requests fall into a small number of patterns. Avoiding them speeds up your review considerably:
- The abuse is still ongoing. Our honeypots or community sensors recorded reports within the last 24–48 hours. Fix the root cause first, a delisting while attacks continue would be reverted within hours anyway.
- No remediation described. "Please delist my IP" without explaining what was fixed gives the reviewer nothing to verify. One sentence about the cause (compromised CMS, open relay, infected client) and the fix is enough.
- The request cannot be linked to the IP. Requests from the owning organization, the hosting provider, or an address in the IP's rDNS domain carry far more weight than an anonymous free-mail address.
- Bulk requests for entire ranges. We delist individual addresses after review. For provider-level range issues, contact us with WHOIS proof of ownership.
Delisting FAQ
How long does delisting take?
Requests are usually decided within 48 hours after you confirm them, and immediately if all reports against the address came from your own account. Once removed, the IP disappears from API responses immediately and from the exported blacklist files with the next daily export. Automatic delisting through time decay takes longer: without new reports, an IP's confidence score halves every 30 days, so most addresses fall below the 75 % blacklist threshold within 60–90 days of the last report.
Does delisting cost anything?
No. Delisting from ReportedIP is always free. We never charge for removal, paid "express delisting" is a practice we consider incompatible with a trustworthy blocklist. Any third party charging money to remove an IP from ReportedIP is not affiliated with us.
Will my IP be relisted after delisting?
Only if new attacks are reported. Delisting removes existing reports and resets the confidence score to zero, but it does not immunize the address. If the underlying issue, a compromised site, an open proxy, malware on a client, is not fixed, community sensors will report the IP again and the score will rebuild. Repeated relistings are a strong signal to audit the machine behind the address.
Where can I see the status of my request?
Signed-in users find all their requests with status and decision in the dashboard under IP Delisting. Requests sent without an account show up there as well once you register with the same email address. Without an account, the decision reaches you by email.
Can I monitor my IP so I notice a listing early?
Yes. Query GET /reportedip/v2/check?ip=<your-ip> from a cron job, a free
account includes 1,000 checks per day, which is more than enough to watch an entire address pool.
See the API Reference for details.
Last updated: · Maintained by the ReportedIP team