Email blocklist · invaluement (Robert K. McEwen)

What is Invaluement, and how do you get off ivmSIP, ivmSIP/24, or ivmURI?

Samuel Chenard

By Samuel Chenard · CEO & Co-Founder, Palisade · Reviewed July 19, 2026

Invaluement is a commercial anti-spam service that runs three DNS blocklists: ivmSIP and ivmSIP/24 list spam-sending IP addresses and subnets, and ivmURI lists spammy domains found in email links. Mail filters subscribe to it as a Spamhaus supplement, so a listing blocks your delivery at the receivers that use it.

Invaluement at a glance
Operatorinvaluement (Robert K. McEwen)
TypeIP and domain blocklist
IP lookup zoneSubscriber-assigned hostname (no open public DNS zone)
Query methodA-record DNSBL that resolves a hit to 127.0.0.2 (or a variation) and returns NXDOMAIN when clean. There is no open public zone: invaluement distributes the lists to subscribers only, by an assigned direct-query hostname or an rsync feed, behind a free 7-day trial and paid plans.
Who uses itinvaluement is consumed as an add-on inside other people's spam filters and mail servers. It bills itself as a supplement to Spamhaus that catches spam Spamhaus misses, so a listing costs you delivery specifically at receivers that run invaluement alongside their primary blocklist.
ReachModerate to high, but only at receivers that subscribe to it. The reach is narrower than Spamhaus, yet invaluement has many hundreds of subscribers and is often used for strict accept-or-reject decisions, so where it is deployed a listing can block your mail outright rather than just add spam score.
Removal costFree on every list (paid delisting offers are scams)

Check if you're on Invaluement

Two facts decide what you do next: which invaluement list flagged you, and whether the flagged identifier is an IP or a domain. ivmSIP and ivmSIP/24 list the IP your mail leaves from; ivmURI lists domains that appear in your message links. One catch specific to invaluement: it distributes its lists to subscribers, so there is no open public zone to dig. Check your sending IP and your domains below, then confirm an invaluement-specific listing on their own lookup.

Is your IP or domain on Invaluement?

Enter your sending IP or domain and the check runs instantly on the next page. Free, no signup.

Related free tools: URL reputation (for ivmURI) · Full blocklist checker · Domain reputation · Email security score

What is Invaluement?

Invaluement is a commercial anti-spam operation that publishes three DNS blocklists (DNSBLs). It does not filter your mail itself. It sells reputation data that other people's spam filters query: when a receiver runs invaluement, its mail server checks your sending IP, or the domains inside your message, against invaluement's lists in real time and blocks you if you are listed. invaluement describes itself as an add-on that runs alongside a primary blocklist such as Spamhaus and catches the spam Spamhaus misses.

Three separate lists sit under the invaluement brand, and the one that flagged you decides what you have to fix. ivmSIP and ivmSIP/24 are IP lists: ivmSIP lists individual spam-sending addresses, and ivmSIP/24 lists whole /24 subnets where a pattern of spam shows up. ivmURI is different in kind: it lists the domains (and a few IPs) found inside the clickable links in spam, not the sending IP. So an ivmSIP hit is about where your mail comes from, while an ivmURI hit is about a domain you are putting in front of recipients.

invaluement is a subscription service, not a free public utility, which changes how you deal with a listing. It has published its lists since 2007, to many hundreds of subscribers, and is operated as invaluement by Robert K. McEwen. Access comes as an assigned direct-query hostname or an rsync feed, behind a free seven-day trial and paid plans. Because of that model there is no open zone you can query the way you can with Spamhaus, so a definitive check runs on invaluement's own lookup page.

The Invaluement lists, and what each one covers

Invaluement is not one list. Identify the exact zone that flagged you: it decides what you fix and how you get removed.

ListWhat it coversWhere it's queriedGetting off
ivmSIP
invaluementSIP (ivmSIP)
IP
IP addresses that, in invaluement's words, either only send spam or emit an extremely high percentage of spam. It says most listings are botnets, elusive snowshoe spammers, or irresponsible ESPs, with rarer short-term listings of normally legitimate senders whose systems have been compromised into sending mass spam.Subscriber-assigned direct-query hostname or rsync feed; a hit resolves to 127.0.0.2. No open public zone.
Removal web form
invaluement publishes no fixed removal time on its public pages. You request removal by entering the listed IP on its delist page at invaluement.com/removal/; a listing driven by a live spam source will not clear until that source stops.
ivmSIP/24
invaluementSIP/24 (ivmSIP/24)
IP
IP ranges and /24 subnets where invaluement has detected a pattern of spam sending. It says it preemptively lists spammers' subnets while working to avoid nearby ranges owned by innocent bystanders, and that it was possibly the first anti-spam list to primarily target snowshoe spammers, even before Spamhaus released its CSS list.Subscriber-assigned direct-query hostname or rsync feed; a hit resolves to 127.0.0.2. No open public zone.
Removal web form
No fixed timeframe is published. Because ivmSIP/24 lists a whole subnet, the trigger may be a neighbor on shared space rather than you; removal is requested on invaluement's delist page once spam from the range stops.
ivmURI
invaluementURI (ivmURI)
URI
Domain names (and a few IPs) found inside the clickable links in the body of spam, in the same family as SURBL and URIBL. invaluement says these domains are generally not seen in legitimate email and are mostly owned by spammers, though a normally-innocent domain can be listed after criminals hijack it.Subscriber-assigned direct-query hostname or rsync feed; a hit resolves to 127.0.0.2. No open public zone.
Removal web form
No fixed timeframe is published. If a clean domain of yours was hijacked or its links abused in spam, fix the compromise first, then request removal on invaluement's delist page.

Why your IP or domain got listed

A listing is a reputation verdict. These are the situations Invaluement lists senders for:

Most common reasons senders land here, ranked

Likely causeWhat's happening
A compromised mailbox, app, or host started sending spamThe most common ivmSIP trigger. A phished account, a vulnerable web form, or a hijacked device sends spam from your IP. invaluement lists the address, and its own copy notes that even a normally legitimate sender gets a short-term listing while a compromised system is emitting mass spam.
Anyone can send as your domain because it isn't enforcedIf your domain has no DMARC policy at enforcement, anyone can forge it in the From: header. That mostly costs you deliverability and fuels brand-impersonation phishing; where that phishing also embeds your domain in its own links, it can feed an ivmURI listing indirectly. Enforcement shuts that spoofing seam, but the direct ivmURI fix is cleaning up wherever your domain is used in spam links. This is the spoofing seam Palisade helps you close.
SPF, DKIM, or DMARC is missing or misalignedUnauthenticated mail reads as spam to receivers and to the detection that feeds these lists. Gaps in SPF and DKIM, or a DMARC record stuck at p=none, make a listing easy to earn and easy for abuse to hide behind.
You share IP space with a snowshoe spammerivmSIP/24 lists subnets, and invaluement built it specifically to catch snowshoe operations that spray low volumes across many addresses. On shared or cloud IP space, a neighbor's spam can list the /24 that your sending IP also lives in.
A domain in your links was hijacked or abusedivmURI targets domains found in spam links. A legitimate site that gets hacked, or a link-shortener and tracking domain that spammers exploit, can be listed even when your mail server is clean. Fix the abuse before you ask for removal.
Triage flowchart for an Invaluement listing: ivmSIP flags your individual sending IP, ivmSIP/24 flags your whole /24 subnet (often a neighbor on shared space), and ivmURI flags a domain in your message links; for any of the three, confirm on invaluement's own lookup and request removal at invaluement.com/removal.

How to delist from Invaluement

Removal only holds if the spam stops first: invaluement is a curated, subscriber-fed list, so a fresh request will not survive an active spam source. Work these in order. Two things are specific to invaluement. There is no open public zone to query, so you confirm a listing on their own lookup, and the delist request itself is made on invaluement's delist page rather than through a one-click self-service portal.

  1. Confirm the listing and which list it is

    Run your sending IP through the free IP reputation check below, and your domains through the URL reputation checker if a bounce or report points at ivmURI. Note whether it is ivmSIP, ivmSIP/24, or ivmURI, then confirm the invaluement-specific listing on their own lookup, since the lists are subscriber-only.

  2. Stop the spam at the source

    Before you ask for removal, end whatever caused it: reset the compromised mailbox, patch or close the vulnerable app or open relay, clean the infected host, and stop any non-compliant sending. invaluement will not keep a removal in place while spam is still leaving your IP or your domain.

  3. Authenticate every sender so it cannot recur

    Publish correct SPF, turn on DKIM for each service that sends as you, and set DMARC. Verify with the free SPF, DKIM, and DMARC checkers. Moving DMARC to p=reject shuts down spoofing of your domain in the From: header; for an ivmURI listing, pair it with locking down the domain and its hosting so it can't be hijacked back into spam links.

  4. Request removal on invaluement's delist page

    Go to invaluement.com/removal/, enter the listed IP or domain, and follow the instructions it returns. Send any follow-up from a real business mailbox rather than a free webmail account, and include why the listing should be cleared; requests from a legitimate address are taken more seriously.

  5. Confirm you are clear and keep monitoring

    Re-check the IP and domain reputation, and re-run invaluement's own lookup, to confirm the listing is gone. Keep watching reputation and keep DMARC reports flowing so the next compromise surfaces as an alert instead of a fresh listing and a wave of bounces.

Removal is free

Checking is free on invaluement's own lookup page, which handles up to ten IPs or domains at a time. invaluement does not publish a delisting fee or a fixed removal timeframe on its public pages; you request removal directly on its delist page. Treat any third party that offers paid "invaluement removal" with suspicion: you deal with invaluement directly, and the durable fix is stopping the spam and authenticating your mail.

Open www.invaluement.com

When a Invaluement listing isn't your fault

An invaluement listing usually reflects real spam, but not always your own. ivmSIP/24 lists whole /24 subnets, so on shared or cloud IP space the spammer may be a neighbor rather than you. ivmURI can list a legitimate domain after criminals hijack it, which invaluement acknowledges directly. And because the lists are subscriber-only, a public blocklist tool that shows "not listed" may simply lack access, not prove you are clear.

How to stay off Invaluement

The real fix: enforce authentication, don't just monitor

Almost every invaluement listing traces back to spam actually leaving your infrastructure, or your domain being embedded in the links of spam sent from elsewhere. A blocklist lookup only tells you that you are listed; it does nothing to stop a compromised sender, secure an abused domain, or clear the listing. Host correct SPF, DKIM, and DMARC, move every domain to p=reject to shut down spoofing of the From: header and brand impersonation, and watch the DMARC reports for senders you did not know about, so a compromise surfaces as an alert before it becomes spam leaving your IP. Enforcement closes the spoofing seam; cleaning up your senders and locking down your domains is what keeps you off ivmSIP and ivmURI.

DMARC software that does the work

Palisade's AI agent takes domains all the way to enforcement: hosted SPF, DKIM, DMARC, and MTA-STS records, DMARC reports monitored continuously, and policies advanced to p=reject automatically. Your first domain is free, and the full product is open for 15 days, no card.

Get startedBook a demo

1 domain free up to 1,000 emails/month

Watching Invaluement across every client domain

One client on ivmSIP is an afternoon; a book of clients, each one compromise away from an invaluement listing, is the job. The subnet list makes it worse: one snowshoe tenant on shared space can pull neighbors down with it. Palisade hosts and manages SPF, DKIM, and DMARC for every client domain, surfaces unauthenticated senders in the DMARC reports before they turn into spam, and walks each domain to p=reject automatically. It watches every client IP and domain from one console and opens tickets in ConnectWise, HaloPSA, and Autotask, and your own MSP domain is a free NFR domain to prove it on.

Questions readers ask

Frequently asked questions

Sources and last verified

Every Invaluement fact on this page is drawn from the operator's own documentation, last checked 2026-07-19. Blocklist policies change; if a detail looks off, the linked source is authoritative.

Related blocklists and guides

Check any IP or domain against every major blocklist