421 Connection Refused: Blocklisted Host (DNSBL)

SMTP error code 421: causes, retry logic, and the sender-side fix. Connection Refused: Blocklisted Host (DNSBL).
SMTPedia editorial team
Email infrastructure & deliverability editor
3 min read Jun 26, 2026 24 views
Code421
Bounce typeSoft bounce
RetryableNo until delisted
Action neededIdentify DNSBL, delist
Typical error message
421 Service not available, connection from x.x.x.x refused: DNSBL listed

What does 421 Connection refused, blocklisted host mean?

The receiving server queried a DNSBL (Spamhaus, Barracuda, Abusix, SORBS, or similar), matched your sending IP, and returned a soft 421 rejection rather than a hard 550. Some MTAs intentionally use 421 for DNSBL matches as a defensive measure: the soft response makes the message queue, giving the sender an opportunity to delist and have retries succeed automatically. The cause is identical to hard DNSBL rejections (your IP is on a public reputation list); the only difference is the recovery path is a bit more graceful. Identify which DNSBL matched, fix the underlying issue, then delist.

Is this a soft or hard bounce?

⚠️
Soft bounce, but retries will fail until delisted

Despite the soft 421, retries from the queue will keep failing until you address the DNSBL listing. The soft response is just a buffer, not a self-recovery mechanism.

Common causes

🔬
Spamhaus zone match

XBL, PBL, CSS, or SBL listing on your sending IP. Check check.spamhaus.org.

Barracuda Reputation listing

BRBL match. See 554 5.7.1 Barracuda.

⚠️
Abusix Mail Intelligence match

Abusix combined zone listing. Multiple sub-lists possible.

🔥
Recipient-specific local DNSBL

Some receivers query private local DNSBLs not publicly identified.

How to fix it

1
Read bounce text for cited DNSBL name

Most 421 DNSBL rejections explicitly name the matching list. If not, look up at multirbl.valli.org to scan major DNSBLs.

2
Address root cause for the listing

XBL: clean compromised systems. PBL: use authenticated relay. Reputation lists: improve bounce rate and complaints.

3
Submit delisting request

Follow the specific DNSBL’s removal procedure. Self-service (PBL) typically resolves in hours; manual review (SBL) takes 24 to 72 hours.

4
Verify retry success

Once delisted, your queue retries will start succeeding automatically without manual intervention.

Provider-specific notes

DNSBLRemoval speed
Spamhaus PBLSelf-service, minutes to hours.
Spamhaus XBL/SBL/CSSManual review, 24 to 72 hours.
Barracuda BRBLSelf-service form, usually under 24 hours.
Abusix combined zoneSelf-service or manual depending on sub-list.
Pre-bounce verification

Prevent the bounces that hurt your sender IP

DNSBL listings are heavily driven by bounce rate from poor list hygiene. SMTPing catches invalid addresses before you send, keeping your IP off blocklists. 25 free checks daily, no card required.

Try SMTPing free →

About the Author

Alaa - SMTPedia author

Alaa · LinkedIn

Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.


About SMTPedia

SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.

We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.