How blocklists work
A DNS blocklist (DNSBL) is a zone where listed addresses have a record. Mail servers query it for every connection: if 203.0.113.25 is listed, 25.113.0.203.list.example returns 127.0.0.2, and the server rejects or scores the mail. Each list has its own rules for what gets an address listed and how it comes off.
Threat feeds are similar but track more than spam: command-and-control servers, malware hosting, compromised machines and Tor exit nodes. Frabs collects several every hour, so this check uses the same data Frabs sensors act on.