# RBL Tools > Free network tools for IP address and subnet owners: DNS blocklists (RBL), PTR and FCrDNS, BGP visibility, RPKI, IRR, ASPA, route and WHOIS history, RIPE object, ROA, prefix-list and geofeed generators, rDNS delegation, lookup (network, WHOIS, DNS, geolocation), abuse contacts, traceroute, subnet calculator and a subnet pre-purchase report. No account, no API key. 40 languages. ## MCP server - URL: https://rbl.tools/mcp (Streamable HTTP, stateless JSON, no authentication) - Claude Code: `claude mcp add --transport http rbl-tools https://rbl.tools/mcp` - Any client with remote MCP: `{"mcpServers":{"rbl-tools":{"type":"http","url":"https://rbl.tools/mcp"}}}` - Clients that only run local servers: `{"mcpServers":{"rbl-tools":{"command":"npx","args":["-y","mcp-remote","https://rbl.tools/mcp"]}}}` - Skill for agents: https://rbl.tools/skill.md - Limits: 30 tool calls a minute per client. Every tool accepts whole subnets or lists in one call. ## Tools - **check_blocklists** (Check IPs against DNS blocklists): Checks IP addresses against 13 free DNS blocklists (SpamCop, Barracuda, UCEPROTECT, PSBL, Mailspike, SpamRATS, DroneBL, Blocklist.de, Backscatterer, JustSpam and others) plus 2 whitelists, through our own recursive resolver, so lists that refuse public resolvers still answer. Accepts one IPv4 or IPv6 address, an IPv4 subnet from /22 to /32, a range a - b, a mail server domain (its A records are checked) or a list of up to 1024 IPv4 addresses. A single address also gets PTR and the AbuseIPDB report count for 90 days. Use when mail lands in spam, before using or buying an address, or when asked whether an IP is blacklisted. A list that did not answer is reported under unavailable sources: never present it as clean. Whitelist rows (DNSWL, Mailspike WL) are good news when listed. Spamhaus is not queried (commercial use needs a license): for it, point the user to https://check.spamhaus.org. Input: IPv4 or IPv6 address, IPv4 subnet /22-/32, range like 192.0.2.10 - 192.0.2.40, mail server domain, or several IPv4 values one per line. - **check_ptr** (Check PTR and FCrDNS): Reverse DNS for every address of an IPv4 subnet (up to /22) or a list: the PTR name, whether it resolves back to the same IP (FCrDNS), and template or generic names such as ip-1-2-3-4 or dynamic pool names that mail servers distrust. Use when setting up a mail server or when mail is rejected for missing or generic reverse DNS. Input: IPv4 address, IPv4 subnet up to /22, or several values one per line. - **blocklist_catalog** (Blocklist catalog and delisting): Static reference for every DNS blocklist this server checks: type (blocking, informational, whitelist), zone, what it lists, how to get delisted and the removal page, and whether it answers IPv6. Use after check_blocklists found a listing, to tell the user exactly how to get off that list. Optional query filters by list name or zone. - **bgp_visibility** (BGP visibility of a prefix): Which RIPE RIS route collectors see a prefix, from which origin ASN and through which upstreams, with the visibility percentage and MOAS (several origins) detection. Use when part of the internet cannot reach a network, after a new announcement, or to confirm who announces a prefix. Input: IPv4 or IPv6 prefix or address, e.g. 195.133.84.0/24 or 2a13:7dc0:1000::/36. - **rpki_validate** (RPKI route origin validation): RPKI status of announced prefixes: valid, invalid or not found, with the ROAs that match and the reason an announcement is invalid (wrong origin ASN or max-length too short). Accepts up to 100 prefixes. Use when a route is rejected or flagged as RPKI invalid, or before changing announcements. Input: IPv4 or IPv6 prefix, or up to 100 prefixes one per line. - **compare_bgp_irr_rpki** (Compare BGP, IRR and RPKI): Puts the three sources of truth side by side for a prefix, an ASN or an as-set: what is announced in BGP, which route objects exist in 8 IRR databases (RIPE, RADB, ARIN, APNIC and others) and what RPKI allows, and lists where they disagree. Use when an upstream or IX filters routes, or to audit IRR hygiene. Input: IPv4 or IPv6 prefix, ASN like AS198037, or as-set like AS-HETZNER. - **check_aspa** (ASPA check): Whether an ASN has published an ASPA object (its authorised upstream providers, signed in RPKI) and, for an AS path, whether the path is valid against ASPA. Use for route leak protection questions or to verify a new ASPA. Input: ASN like AS198037, or an AS path like 198037 174 3356. - **route_history** (Route announcement history): Who announced a prefix and when over two years and more: origin ASNs with first and last seen dates, including short suspicious announcements. Use to check a subnet's past before buying it, or to investigate a possible hijack. Input: IPv4 or IPv6 prefix. - **generate_ripe_objects** (Generate RIPE objects): Builds RIPE database objects (route or route6, inetnum or inet6num, domain for reverse DNS) for a prefix with correct syntax, prefilled from what is already announced and registered. Returns the objects as text to paste into the RIPE database. Use when registering or moving a subnet. Input: IPv4 or IPv6 prefix. - **generate_roa** (Generate ROAs): Proposes ROAs for the prefixes an ASN currently announces, or for given prefixes, with a safe max-length, and returns them as CSV for the RIPE NCC portal bulk import. Use when creating RPKI for a network or fixing RPKI invalid routes. Input: ASN like AS198037, or prefixes one per line. - **build_prefix_list** (Prefix-list from an as-set): Expands an as-set or ASN through IRR databases (like bgpq4) into the list of announced prefixes and a ready Cisco IOS prefix-list for IPv4 and IPv6. Use when building a customer or peer BGP filter. Input: as-set like AS-HETZNER, or an ASN. - **geofeed** (Build or validate a geofeed): Builds an RFC 8805 geofeed CSV for a prefix, or validates an existing geofeed file by URL: syntax, prefixes outside the network, country codes. Use when geolocation services show the wrong country for a network. Input: IPv4 or IPv6 prefix, or the https URL of a geofeed CSV. - **check_rdns_delegation** (Reverse DNS delegation check): Checks reverse DNS delegation of a prefix: the domain object in the RIPE database and whether every listed nserver answers for the in-addr.arpa or ip6.arpa zone. Use when PTR records do not resolve although they were set. Input: IPv4 or IPv6 prefix. - **network_lookup** (Network overview): Overview of an IP address, prefix or ASN: covering route, origin ASN and holder, country, RIR, RPKI status and related prefixes. Use as the first look at an unknown address or network. Input: IPv4 or IPv6 address or prefix, ASN, or range. - **whois** (WHOIS / RDAP lookup): Registry record (RDAP, with WHOIS details) for an IP address, prefix, ASN or domain: holder organisation, network name, country, abuse contact, registration dates, nameservers for domains. Input: IP address, prefix, ASN or domain. - **dns_lookup** (DNS records): DNS records of a domain: A, AAAA, MX, NS, TXT (SPF, DMARC), CAA, SOA and CNAME, resolved by our server. Use for mail setup (MX, SPF, DMARC) or to see where a domain points. Input: domain name, e.g. example.com. - **geolocation** (IP geolocation comparison): Where different geolocation databases place an IP or a prefix (IPinfo, DB-IP, GeoLite2, IP2Location, the RIR record and the network's own geofeed) and whether they agree. A prefix is checked at its first host. Use when services show the wrong country. Input: IPv4 or IPv6 address or prefix. - **whois_history** (WHOIS history): Versions of the RIPE database objects of a prefix or ASN with what changed between them: holder, maintainers, transfers. Use to check ownership history before buying or after a transfer. Input: IPv4 or IPv6 prefix, or ASN. - **abuse_contacts** (Abuse contacts): Where to send an abuse complaint for IP addresses, prefixes or ASNs (from RDAP of all five RIRs), up to 500 lines at once, grouped by contact. Use for any question like where do I report spam, an attack or scanning from this IP, including well-known addresses (8.8.8.8, 1.1.1.1): contacts change, look them up instead of answering from memory. Pair it with check_blocklists to show whether the address is really known for abuse. Input: IP addresses, prefixes or ASNs, one per line (up to 500). - **traceroute** (Traceroute from our server): Traceroute from our server in Frankfurt to an IP or domain, with ASN and country for every hop and the round-trip times. Takes up to half a minute. Use to see where packets are lost or delayed on the way to a host. Input: IPv4 or IPv6 address, or domain. - **subnet_calculator** (Subnet calculator): Subnet math: network, broadcast, mask, host count and ranges for an IPv4 or IPv6 prefix, split a prefix into smaller ones, merge (aggregate) a list of prefixes, convert a range a - b into CIDRs, and reverse DNS zone names. Exact, computed locally. Input: prefix like 195.133.84.0/22, range a - b, or several prefixes one per line to merge. - **subnet_report** (Subnet pre-purchase report): One report on whether an IPv4 subnet (/22 to /32) is safe to buy or lease, graded A to F: blocklist listings of every address, PTR coverage, BGP visibility and origin, RPKI and IRR status, announcement history, ownership history, geolocation agreement and leftovers from the previous owner. Takes up to a minute for a /22. Use before buying, leasing or accepting an IP range. Input: IPv4 subnet from /22 to /32. ## Prompts - **mail_deliverability**: Checks a mail server address or domain against blocklists and reverse DNS and explains what to fix. - **subnet_due_diligence**: Runs the pre-purchase report on an IPv4 subnet and explains the grade. - **route_troubleshooting**: Checks visibility, RPKI and IRR for a prefix and finds why networks filter it. ## Pages Every tool has a page: https://rbl.tools/en/?q=, for example https://rbl.tools/en/rbl?q=195.133.84.0/24. Replace en with any of: en, es, ru, uk, zh, ar, fr, bn, pt, id, de, tr, it, pl, nl, ro, el, hu, sv, cs, sr, ca, bg, sq, da, fi, no, hr, sk, be, lt, bs, sl, ga, lv, mk, et, lb, mt, is.