What is the MW dataset function in SURBL and why does it matter for email safety?

You get an email that looks like it’s from your bank. It uses the exact logo, the same tone, even a familiar web address. You click. Then your password is gone. This happens because attackers reuse domains from known phishing campaigns — and they’re getting faster at it.

The MW dataset function in SURBL is a real-time filter that flags domains used in such attacks. It doesn’t wait for mass reports — it acts on known malicious sources, stopping threats before they reach your inbox.

SURBL’s MW dataset aggregates threat intelligence from malware command-and-control servers, compromised websites, and active phishing kits. It’s updated continuously and integrated into mail servers and email verification tools to block or flag suspicious domains early.

Key takeaways

  • The MW dataset in SURBL blocks known phishing and malware domains using real-time threat intelligence from active attack infrastructure.
  • It identifies domains used in impersonation attacks by tracking malicious web assets and command-and-control servers.
  • Integrating SURBL’s MW dataset into email systems enables early detection and prevents malicious emails from reaching inboxes.

How does the MW dataset function in SURBL identify phishing domains in practice?

The MW dataset, integrated into SURBL systems, identifies phishing domains by flagging known malicious domains in real time, using automated signals like rapid registration, suspicious TLDs, poor WHOIS data, and anomalies in TLS certificates. When a domain appears in the MW list, email filters cross-check it against known indicators—such as short registration duration, use of high-risk top-level domains (like .xyz or .loan), and missing or fabricated WHOIS records—before blocking or tagging messages. You don’t need to wait for phishing attempts to succeed; SURBL-based filters act preemptively, reducing inbox exposure to threats before they reach users.

Real-world detection: signals that trigger a flag

Let’s walk through how a typical phishing domain gets caught. A domain like secure-login.xyz might be registered with no WHOIS contact, using a new IP with poor reputation and a certificate issued less than 12 hours earlier. These patterns—short registration time, high-risk TLD, no traceable owner—are common in phishing clusters tracked by the MW dataset. The system flags such domains automatically, especially when multiple instances share similar fingerprinting behaviors across content or structure.

These signals are validated through passive monitoring and telemetry from email security providers. The ICANN root zone data and MxToolbox’s domain lookup tools help verify registration patterns at scale. While no single signal is definitive, combinations of anomalies are strong indicators of malicious intent.

How this impacts email delivery and security

Once the MW dataset updates, SURBL-enabled filters—used by major email providers and security gateways—treat flagged domains as high-risk. This means an email from a domain on the MW list may be rejected, quarantined, or marked with a warning. You avoid the cost of a breach—email open rates drop sharply when users are trained to distrust these alerts.

MailTester’s inbox placement testing helps you assess how your verified domains would perform in real inboxes, including whether they’d be caught by such anti-phishing systems. You can audit your outbound list to ensure no valid domains are being mistakenly flagged. For ongoing list hygiene, use our bulk verification tool to clean your email database before sending.

How does MailTester use SURBL and its MW dataset to improve list hygiene?

You can catch phishing domains before they hurt your sender reputation by using MailTester’s real-time verification, which checks each email’s domain against SURBL’s MW dataset. This blacklisted domain list flags domains used in malicious campaigns, so if a domain is on the MW list, MailTester returns a 'risky' verdict, letting you remove it from your list before sending.

Real-time checks with industry-standard blacklists

When you send an email address to MailTester’s verification API or check a list with the bulk tool, we don’t just validate syntax or delivery routes — we dig deeper. We query real-time threat intelligence, including SURBL’s MW dataset, which tracks domains linked to phishing, malware, and spam. The MW dataset is maintained by the Spamhaus Project, a long-standing authority in email threat intelligence.

This isn’t theoretical. SURBL’s blacklists are widely used by email providers and filtering systems. A domain on a SURBL list has a higher chance of being blocked by major inboxes. By integrating MW into our validation process, MailTester adds a layer of proactive security that catches domains with a history of abuse before they ever reach a recipient’s inbox.

Preventing reputation damage before it starts

A single high-risk address in your list can lower deliverability across the board. If your domain starts sending to known phishing domains, email providers may flag your entire sender profile as suspicious. MailTester’s 'risky' verdict helps you avoid this by surfacing these domains early.

Use the real-time verification API or our bulk list checker to test your data. You don’t need to pre-process your list — just send it through our engine, and we’ll return each address with its validity, risk status, and delivery readiness. Check a single address first with our email checker tool, or integrate with your CRM or email platform using our integrations at MailTester integrations.

For a hands-on test of how threat intelligence improves your list hygiene, try an inbox placement test with our inbox tester. It shows how real mail clients treat messages sent from cleaned lists — including those with previously flagged domains.

Accuracy matters. MailTester achieves 98.9% verification accuracy by combining multiple data sources, including SURBL’s MW dataset, which contributes to our ability to identify domains with malicious intent, not just technical flaws.

What does a 'risky' verdict mean in MailTester’s verification results?

A 'risky' verdict means the domain behind the email address is flagged for suspected phishing, malware distribution, or other malicious activity. It doesn’t mean the address is invalid—mail may still be delivered—but sending to it can harm your sender reputation or expose you to spam traps. You’re being warned, not blocked.

Why 'risky' isn’t the same as 'catch-all' or 'invalid'

Many tools report only 'valid' or 'invalid', but MailTester goes further. A 'catch-all' domain accepts all incoming mail, which can lead to high bounce rates and poor deliverability if used in campaigns. An 'invalid' address can’t receive mail at all. A 'risky' domain sits in a middle zone: it may accept messages, but it’s associated with known threats.

This signal comes from multiple sources, including real-time threat intelligence like the SURBL (Spam URI Real-time Block List) system. SURBL uses known malicious domains, including those tied to phishing, to help block email spam. The MW dataset function in SURBL specifically tracks domains used in malicious campaigns, helping tools like MailTester flag high-risk domains early.

How this protects your campaigns

Let’s say you're sending a promotional email to a list. A 'risky' domain might still accept your message, but if you send to it, it could count as a ‘delivery to a malicious origin’ in the eyes of inbox providers. That harms your sender reputation over time—especially if you send frequently.

MailTester’s 98.9% accuracy in detection means you’re not just avoiding failed deliveries—you’re reducing risk before it starts. We use signals like those from SURBL, combined with infrastructure checks and historical abuse data, to surface threats you might otherwise miss.

It’s not about stopping delivery. It’s about making sure you only send to domains that are safe, legitimate, and likely to improve your inbox placement. For deeper insight, you can test real inbox placement with our inbox placement tool to validate how your messages land in real user inboxes.

For high-volume senders, it’s standard practice to verify domains at scale. Our bulk verification tool processes thousands of addresses quickly, tagging risky domains so they’re not included in campaigns. You’re not just cleaning lists—you’re protecting your brand’s trust.

How to reduce phishing risk by integrating real-time verification into your workflow

Run every email list through MailTester’s bulk verification API before sending. It flags high-risk domains—including those associated with phishing—before they reach your customers. Combine this with real-time checks for SPF/DKIM alignment, domain age, and blacklisting to catch suspicious patterns early. Automate it across Mailchimp, Klaviyo, or SendGrid to stop bad sends before they leave your inbox.

Prevent phishing exposure with proactive list hygiene

  • Upload your list to the MailTester bulk verification tool before launching any campaign. It processes thousands of addresses in minutes and marks domains with known fraud signals, including those in SURBL or listed in real-time risk feeds.
  • Use the MailTester real-time API within your sending workflow to verify each address on the fly—ideal for onboarding, lead capture, or transactional messages.
  • Let the in-app AI assistant prioritize suspicious entries: it analyzes domain reputation, typo-squatted patterns, and known phishing clusters, helping you decide whether to remove, quarantine, or investigate further.
  • Check for basic domain security alignment: a valid email should have properly configured SPF and DKIM records. Tools like RFC 7208 (SPF) define these standards; missing or mismatched records are common in phishing domains.
  • Assess domain age. Newly created domains are disproportionately used in phishing attacks. Validate domains with less than 90 days of history as high risk—common practice in anti-phishing systems.

Automate defenses at scale

  • Integrate MailTester directly with Mailchimp, Klaviyo, or SendGrid via the native connectors. Every new subscriber or campaign sends are auto-checked before delivery.
  • Set thresholds—e.g., block all addresses from domains with no SPF or from domains under 30 days old. Adjust based on your risk tolerance and industry norms.
  • Monitor your sender reputation. Sending to phishing domains can damage your IP and domain reputation. A single compromised address in a list can trigger blocklists (like Spamhaus) used by major email providers.
  • Review verification reports monthly. Look for spikes in catch-all domains, disposable emails, or patterns of high-risk TLDs to spot system-level vulnerabilities.
  • Test inbox placement with the in-app inbox tester to confirm safe delivery after filtering your list.

Why relying solely on SURBL’s MW dataset isn’t enough for full list hygiene

The MW dataset in SURBL identifies only known malicious domains—it can’t detect new or emerging phishing sites, nor does it verify if an email address is valid, disposable, or a role account. Relying on it alone leaves gaps in your list hygiene, increasing the risk of bounces, deliverability issues, and exposure to fraud. You need more than just a blacklist; you need real-time validation and reputation scoring.

Known threats aren’t the whole picture

Malware Websites (MW) data is reactive. It only flags domains that have already been reported as malicious. That means it won’t catch zero-day phishing campaigns that haven’t yet been reported or detected by security feeds. According to the ICS-CERT, new phishing domains are created at a rate of thousands per day, many of which evade initial detection. Waiting for inclusion in SURBL’s database means you’re already behind.

Beyond blacklists: the missing layers of hygiene

Even a valid domain flagged in MW isn’t necessarily deliverable. You still need to verify if the mailbox exists, if it’s a role account (like admin@ or postmaster@), or if it’s from a disposable email provider like Mailinator. These types of addresses often have poor engagement and inflate bounce rates. SURBL’s MW dataset doesn’t evaluate any of this.

True list hygiene requires layered checks: syntax validation, SMTP verification to confirm inbox existence, domain reputation scoring, and catch-all detection. Each layer addresses a different risk. For example, catch-all mailboxes accept all incoming mail but often mean the address is inactive or low-quality. An address with a good domain reputation can still be invalid, and vice versa.

MailTester integrates SURBL’s MW function but goes further. Our bulk verification tool combines it with real-time SMTP checks, inbox-placement testing, and domain reputation analysis. This gives you a more accurate, actionable result than any single dataset can provide. You’re not just avoiding known bad domains—you’re also filtering out invalid, disposable, or unreliable email addresses before you send.

To test how well your list would perform in real inboxes, use our inbox placement tool: check actual deliverability across major providers. For automated workflows, integrate our API: validate emails at scale with precision. You get 100 free verifications to start—credits never expire.

How MailTester’s 98.9% accuracy supports phishing risk detection

You can trust MailTester’s 98.9% accuracy to identify phishing-related domains by combining real-time behavioral signals with established threat intelligence like the MW dataset from SURBL. This means suspicious domains are flagged without blocking legitimate addresses — a balance critical for marketing and security teams alike. The system continuously learns and adapts, reducing false positives while catching malicious patterns early.

Why precision matters in phishing detection

Phishing domains often mimic real brands or use subtle variations to deceive users. If a tool flags too many legitimate domains as risky, you lose trust in the entire system. That’s why MailTester doesn’t rely on just one signal — instead, it analyzes over 100 behavioral and technical indicators, including historical data from SURBL’s MW dataset, which tracks domains associated with spam and phishing campaigns.

Let’s be clear: detecting a phishing attempt isn’t enough. You need to do it without stopping real customer emails. MailTester’s model achieves this by balancing detection strength with context. A domain might show one red flag — say, a mismatched DNS record — but if other signals confirm it's used for a legitimate campaign, it won’t be blocked. This is why accuracy isn’t just a number; it’s what keeps your send rate high and your inbox placement strong.

How accuracy is maintained in real-world use

MailTester’s 98.9% figure isn’t static. It’s powered by continuous feedback loops from actual sends and bounces. Every verification helps refine the model. When a domain that was once marked "risky" turns out to be valid, that insight updates the system. This real-time learning prevents overreliance on outdated data and ensures the system evolves alongside new phishing tactics.

For example, new phishing sites often appear and disappear quickly. A static blacklist fails here. But a system that cross-checks against active sources like SURBL’s MW dataset — combined with behavioral analysis — can detect these threats before they go live. It’s not magic. It’s math, data, and ongoing refinement. You can test this approach live with our email checker or verify entire lists via our bulk verification tool, both designed to surface risky addresses without overblocking.

Industry standards — such as those from the IETF and spam mitigation frameworks — emphasize the importance of dynamic signal correlation over hardcoded lists. That’s exactly how MailTester works: using well-known threat data, like the MW dataset, not as a final decision but as one input among many. That’s how you get high confidence without high cost.

Common signs of phishing domains that SURBL's MW dataset helps detect

You can catch phishing domains early by spotting red flags like misspelled brands (e.g., 'paypa1.com'), domains registered in under 24 hours with fake or hidden WHOIS data, suspicious use of high-risk TLDs, IPs linked to known abuse, or domains hosting known phishing kits. These traits are common in attacks targeting users through email or social engineering. The MW dataset in SURBL flags these patterns by correlating domain behavior with historical abuse indicators from global threat intelligence networks.

Red flags in domain creation and structure

  • Domains with subtle typos or leetspeak substitutions (e.g., 'faceb00k.net', 'g00gle-login.com') are common in phishing campaigns to mimic trusted brands. These are consistently flagged by SURBL’s MW dataset due to pattern recognition across past abuse reports.
  • Domains registered in under 24 hours—particularly those with private or spoofed WHOIS data—often lack legitimate business intent. Such rapid registration is a known indicator of short-lived malicious infrastructure.
  • High-risk TLDs (like .top, .info, .tk) used without any prior history of benign use signal potential risk. SURBL's MW dataset tracks TLD adoption trends to identify sudden spikes in abuse patterns tied to these domains.

Indicators from infrastructure and content

  • IP addresses associated with known malicious traffic—such as those listed on Spamhaus or CBL—are automatically cross-referenced by SURBL’s MW dataset. This helps block domains that host phishing content on compromised or abused networks.
  • Domains that serve known phishing kits (e.g., credential harvesters, fake login forms) are flagged based on content signatures and behavioral patterns. These are often detected via reverse DNS lookup and file reputation data.
  • Domain-to-IP relationships that deviate from norm—e.g., a new domain pointing to an IP seen hosting 50+ malicious sites in the last 30 days—are highlighted by the MW dataset as high-risk.

While SURBL’s MW dataset is a key tool for identifying phishing domains, it’s most effective when used alongside other verification methods. For example, real-time email address validation using tools like MailTester’s API can catch suspicious inboxes before they’re used in campaigns. You can verify email addresses at scale with precision, reducing the chance of sending to a fake or abusive account.

For teams handling high-volume email outreach, integrating with MailTester’s real-time verification API ensures your send list remains safe and deliverable. The service checks individual addresses for validity, catch-all status, and risk flags—not just syntax—to provide accurate results backed by real-world data.

How to test inbox placement and identify phishing risks in your campaign flow

You can test inbox placement and detect phishing risks by simulating how your emails land across major providers like Gmail, Outlook, and Yahoo using MailTester’s inbox-placement tester. This reveals whether messages land in the inbox, spam folder, or get blocked—critical for spotting domains flagged by SURBL’s MW dataset, which often correlate with phishing attempts. If a domain is caught in that database, it will consistently fail inbox placement tests.

Simulate real-world inbox delivery with automated testing

Let’s say you’re preparing a campaign. You don’t want to send to a list only to have messages dumped into spam or rejected altogether. MailTester’s inbox placement tool sends test messages to real inboxes across providers and reports back exactly where they land. This isn’t a guess—it’s a live, reproducible check using real infrastructure, not just reputation scores or heuristics.

When a domain appears in SURBL’s MW dataset—commonly used by spam filters to block known malicious domains—it’s more likely to fail these tests. The dataset tracks domains associated with phishing, malware, or abuse. If your campaign includes any such domains, your mail will often end up in spam or blocked entirely, even if the message content is clean.

For a real-world check, test your campaign flow with domains known to be malicious, like those used in common phishing simulations (e.g., fake login pages). This helps you verify that your verification rules are properly catching risky domains before they’re sent.

Use test results to refine your email verification rules

Once you have the inbox placement results, you can see which domains are being blocked or filtered. If a domain is in the MW dataset and fails delivery, that’s a red flag you can use to harden your verification layer. For example, you might add a rule to reject any sender or recipient domain listed in SURBL’s MW dataset.

For high-volume senders, this process becomes part of your automated workflow. You can integrate MailTester’s inbox placement tester into your campaign pipeline to check new domains before sending. This helps catch risks before they harm sender reputation or trigger blocklists.

Tools like SURBL and MXToolbox (which provides real-time DNS diagnostics) are trusted in the ecosystem for identifying threats. The MW dataset is one of several sources used by filtering engines—its inclusion isn’t definitive proof of malicious intent, but it’s a strong signal worth investigating.

Ultimately, the goal is to catch phishing risks early. Real-time inbox placement testing with MailTester gives you a clear picture of deliverability—before you send to a full audience.

The role of automation in real-time phishing risk detection

Automation is the backbone of real-time phishing risk detection. By integrating MailTester’s verification API with platforms like Mailchimp, HubSpot, Klaviyo, and SendGrid, you can block high-risk email addresses before they ever leave your system—eliminating manual review delays and stopping threats at the gate. This isn’t just faster; it’s necessary for maintaining sender reputation and avoiding blacklists.

Stop threats before they reach the inbox

Let’s say you’re sending a campaign. Without automation, you’d have to manually vet every address, which is impossible at scale. With MailTester’s real-time API, every email is checked against a live dataset—including SURBL’s MW dataset, which flags domains associated with phishing and malicious activity—before delivery. This means risky addresses, like those from disposable domains or known phishing sources, are blocked instantly.

Integrations with marketing tools mean you don’t need to rework your workflow. The validation happens automatically, seamlessly, and in real time. You’re not slowing down your send volume—you’re protecting it. According to research from the Anti-Phishing Working Group (APWG), over 80% of reported phishing attacks used domains that were either newly registered or had prior malicious history, a pattern that SURBL’s MW dataset helps catch.

Protect your sender reputation with consistency

Every time a high-risk address receives a message, especially if it’s a role-based or disposable inbox, your deliverability score drops. Even a single bounce from a known bad domain can trigger automated filtering systems to flag your IP or domain. Automation prevents that by stopping unsafe sends before they happen.

By combining real-time verification with industry-standard checks—like SPF, DKIM, and DMARC validation—MailTester gives you confidence your mail reaches real inboxes, not spam traps. You’re not just avoiding bounces; you’re maintaining a clean sender reputation. Tools like MxToolbox and Spamhaus track sender behavior, and consistent, low-risk sending patterns are favored in their algorithms. Automating checks helps you stay on the right side of those rules.

Whether you’re running a campaign, sending transactional emails, or validating leads, automated verification isn’t a luxury. It’s a requirement. With MailTester’s real-time verification API and integrations, you get precise, reliable checks without disrupting your workflow.

Conclusion: Proactive list hygiene with SURBL and MailTester reduces phishing exposure

The MW dataset in SURBL provides a critical layer of threat intelligence, flagging domains associated with known phishing campaigns. But relying solely on blacklists is insufficient — threat landscapes evolve, and false positives can disrupt legitimate communication.

MailTester goes beyond SURBL by combining the MW dataset with real-time SMTP validation, domain reputation analysis, and a 98.9% accuracy rate. This multi-layered approach identifies not just known threats, but also invalid, disposable, and risky addresses before they’re sent.

Regularly verifying your email lists prevents accidental exposure to phishing detection systems and protects your sender reputation. You’re not just filtering spam — you’re reducing your attack surface.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

What is the MW dataset function in SURBL?

The MW dataset in SURBL is a real-time threat feed that identifies domains associated with phishing, malware, or other malicious activity based on known indicators.

How does SURBL detect phishing domains?

SURBL uses reputation signals like domain registration patterns, IP history, TLD usage, and content fingerprinting to flag domains used in phishing attacks.

Does MailTester use SURBL’s MW dataset?

Yes, MailTester incorporates the MW dataset function from SURBL as one of many signals to identify domains that are known for phishing or abuse.

What happens when a domain is flagged by SURBL’s MW dataset?

The domain is considered high-risk. MailTester returns a 'risky' verdict, suggesting the domain may be used for phishing and should be removed from email lists.

Can a 'risky' domain still accept emails?

Yes—some phishing domains are set up to receive mail while harvesting credentials. This makes them dangerous even if they appear active.

Is the MW dataset alone sufficient for email security?

No. The MW dataset only covers known malicious domains. A full security strategy requires multiple layers, including SPF, DKIM, DMARC, and real-time verification.

MailTester achieves 98.9% accuracy in verifying email addresses, including identifying domains linked to phishing or abuse through SURBL and other signals.

Can I test inbox placement for domains flagged by SURBL?

Yes—MailTester’s inbox-placement tests evaluate deliverability, including whether domains flagged by SURBL are blocked or delivered to spam folders.

Do purchased credits in MailTester expire?

No, purchased credits never expire, giving you flexibility to verify lists at your own pace, especially when auditing for phishing risks.

How can I integrate MailTester with my email platform?

MailTester integrates directly with Mailchimp, HubSpot, Klaviyo, and SendGrid, allowing automatic verification before sending campaigns.

What is the difference between 'risky' and 'catch-all' in MailTester?

'Risky' indicates a domain is linked to abuse (like phishing), while 'catch-all' means the domain accepts all email addresses—both signals are useful for list hygiene but for different reasons.

Do phishing domains use real sender reputations?

Some do—attackers often use compromised accounts or spoofed domains. Email verification tools like MailTester help catch these before they damage sender reputation.