IPv4 Blacklist Due Diligence: Never Buy a Dirty Block
Quick answer: an IPv4 block carrying active abuse listings trades 20-50 percent below a clean equivalent, and in our own deal pipeline that is the single biggest price killer. Listings do not reset when ownership changes - buy the addresses and you inherit the previous holder's reputation with them. Run the check before you make an offer rather than on day three of escrow, and read the result by tier instead of by hit count: a policy-list entry and an active abuse record are not the same problem and should not move the price by the same amount.
This is the buyer's side of reputation risk. For the transaction mechanics around it, see our IPv4 buy and sell guide; for what blocks actually cost by registry and size, the current table is in IPv4 price per IP.
What a listing actually costs you
Reputation is not a yes-or-no property of a block. It is a set of states with very different commercial weight, and conflating them is how buyers either overpay for a problem or walk away from a bargain.
| Listing state | What it means | Effect on price |
|---|---|---|
| Clean across major DNS blacklists | No active entries, no recent listing reasons, announcement history consistent with the registry record. | The reference price. This is what published per-IP ranges assume. |
| Single policy-list entry | One list designates the range as dynamic or residential. A description of expected use, not a finding of abuse. | Minor. A negotiating point and a documentation task, not a repricing event. |
| Active abuse listing on a major reputation list | A live entry with a current reason - spam, malware, or compromised hosts seen recently. | 20-50 percent below a clean block, consistently, in our pipeline. |
| DROP-list entry or hijack history | The range has been published as not-to-be-routed, or was announced by a party with no authority to announce it. | Hard to place at any price. Networks drop the route regardless of who owns it. |
| Unresolvable provenance | WHOIS, IRR objects and BGP history disagree, and no document chain explains why. | Not a discount question. Walk away. |
The 20-50 percent figure is the one we publish and stand behind; it comes from our own closed deals and appears in the July 2026 market report. The other rows are qualitative on purpose, because a single honest number does not exist for them.
A clean-looking block is not a clean block
Blacklist operators do not watch registry transfers. Their data is keyed to addresses, so a listing created against a previous holder's mail server in 2022 is still attached to the same /24 in 2026, under your organization name, the day the transfer completes.
Two consequences follow. First, delisting is usually a remediation process rather than a form: some lists expire entries automatically once the behaviour stops, others require a request with evidence that the cause is gone, and a few will not remove an entry while the range is still announced from the same AS. Second, a block with no reputation at all is a distinct third state. Addresses that were never announced are neither clean nor dirty - they are unknown, and a buyer who intends to send mail should price the warm-up period that follows.
Reading a report without overreacting
This is the part that separates a useful scan from an anxious one. A long report is not automatically a bad block.
- Separate policy from abuse. A dynamic or residential designation describes what a list thinks the range is for. If you are buying for static infrastructure, this is often corrected by documenting the range, and it is not evidence that anyone misbehaved.
- Weigh corroboration, not count. Aggregators republish other operators' data, so one underlying finding can surface on several lists. A single hit traceable to one unverified report is noise. The same addresses on independent lists with separate dated reasons are not.
- Check scope. A /24 with three listed addresses and a /24 listed as a whole are different assets. Establish how much of the range is affected before you argue about how much to discount.
- Check age and activity. An entry whose reason dates to 2021 with nothing since usually clears on request. One refreshed last month will not clear on your timetable.
- One tier moves the price. Active entries with current reasons on major reputation lists are where the 20-50 percent sits. Everything else is negotiation.
Where in the deal to run the check
Three moments, for three different reasons.
- Before you make an offer. This is the only point at which reputation can still change your price rather than your mood.
- Before funds enter escrow. Confirms nothing appeared while terms were being agreed, and produces a dated artefact both sides accept.
- Immediately before the transfer closes. Blocks can be listed during a deal, and a seller's warranty, if you negotiated one, is only enforceable if you can show the state at closing.
A buyer who skips the first and discovers a listing at the second has already lost the leverage they needed. For the registry-side mechanics of what happens after agreement, see our RIPE NCC transfer guide.
Scan the block yourself
The DCXV Blacklist Checker on our IPv4 page scans a network against major DNS blacklists and produces a PDF report. You enter the network in CIDR form, sign in, and pay per scan by card or PayPal before the scan starts. Price follows block size: EUR 3 for a /24 or anything smaller, EUR 13 for a /22, EUR 23 for a /20, EUR 43 for a /16, and a /15 is the largest network accepted. The report stays available for any finished scan, so the check you ran during negotiation is still on file when the transfer closes.
If the block is already with us to take to market, the pre-sale audit is included - we absorb the scan cost on blocks we are representing. The seller's side of the same problem is in how to sell an IPv4 block.
A pre-purchase checklist
- Exact CIDR of every prefix in the deal, not only the parent block
- A blacklist scan covering the whole range, with a dated report
- Listing reasons read individually and sorted into policy and abuse
- RIR WHOIS history and the current holder's organization name
- BGP announcement history - who announced the range, and when
- IRR objects and ROA / RPKI status consistent with the WHOIS holder
- Abuse-contact record, and whether past reports were ever handled
- Any DROP-list or hijack appearance at any point in the block's history
- Whether the seller will warrant reputation state at closing
- A re-scan immediately before funds leave escrow
The bottom line
Scanning a /24 costs EUR 3 and one form. Buying a listed /22 costs five figures and a deliverability problem you did not create. Check before you offer, read the report by tier rather than by hit count, and treat DROP-list entries and hijack history as disqualifying rather than discountable. Run a scan at https://dcxv.com/ipv4, or if you would rather have a block sourced clean in the first place, email ipv4@dcxv.com or start at https://dcxv.com/ipv4/buy.
