On 3 September 2026, the email-intelligence vendor Validity launched Heatwave, a blocklist built for a single purpose: catching domains that fake their way to a good sender reputation through artificial (synthetic) warmup. It launched already listing more than a million domains, and because it feeds real filtering infrastructure, a listing is not just cosmetic.
What "artificial warming" actually is
Legitimate warmup means gradually increasing real sending to real recipients so mailbox providers learn to trust a new domain or IP. Artificial warmup automates a fake version of that. A warmup service connects to networks of controlled mailboxes that send each other short messages and then open, click and reply to them, generating the engagement signals Gmail and Outlook use to gauge trust. The domain looks established and engaged; none of it is real. It is most commonly bolted onto cold-email tooling so a fresh domain can start blasting outreach without the usual reputation ramp.
Validity's framing is blunt. "When reputation is manufactured instead of earned, it's just plain cheating, and the whole ecosystem suffers," said Tom Bartel, Validity's SVP of Data.
This is not a new concern for us. Back in 2025 we tested nearly all the major warmup tools and found they delivered no meaningful lift in domain reputation - Gmail and Microsoft were already detecting the automated interactions and discounting them - and we warned that leaning on artificial engagement could do more harm than good. Heatwave is the mailbox-provider ecosystem now putting an enforcement edge on that same conclusion.
Why Heatwave matters (it feeds real filtering)
Heatwave is not a standalone list you can ignore. Per Validity, it is mirrored into the company's existing DNS reputation zones, so the signal reaches partners without any new integration on their side. Validity says it is used or being evaluated by mailbox and security partners including Comcast, Proofpoint, Spamhaus and SURBL, plus ESPs. Spamhaus CEO Carel Bitter described it as "an additional signal we can use to correlate domains." In short: a Heatwave listing can translate into worse inbox placement at real providers.
It is worth being clear-eyed about the source, too. Validity is a commercial vendor and Heatwave is a proprietary, paid-ecosystem list - not a community blocklist. That does not make it wrong, but its reach comes from Validity's partner relationships rather than open governance.
How to check if you are listed - and the delisting catch
You can look up a domain at lookup.validity.tools. A listed domain is shown with a classification (warming, or warming plus active outreach), an observation age, a relative listing score, and the raw DNS answer from Validity's bl.validity.tools reputation zone - the same signal its partners consume.
bl.validity.tools zone.How to read a Heatwave DNS answer
Heatwave is a DNS blocklist, so its partners do not need the dashboard - they resolve a single DNS name and read a coded reply. If a domain such as examplemail.com is listed, a lookup of examplemail.com.bl.validity.tools returns a 127.x.x.x address whose octets encode the verdict, in the shape 127.{age}.{score}.{stage}. Taking the real answer 127.1.76.2 from the screenshot above:
| Octet (field) | Values | What it means (Validity's own decode) |
|---|---|---|
| 1st (prefix) | 127 | Fixed. Any 127/8 answer means the domain is listed (the reply is a code, not a real IP address) |
| 2nd (age) | 0-4 | Observation age since first synthetic-warming observation: 0 = under 7 days, 1 = 7-30, 2 = 30-90, 3 = 90-180, 4 = 180+ days |
| 3rd (score) | 0-100 | Relative severity band versus other recent listings; recomputed hourly, not comparable over time, and does not drive the listing decision. 0 = manually listed |
| 4th (stage) | 2, 3 or 4 | 2 = synthetic warming only; 3 = graduated to real cold outreach (active); 4 = pre-warming (a registered sibling of a warming family, published pre-emptively, not yet observed sending) |
| NXDOMAIN | - | Domain is not currently listed |
So 127.1.76.2 reads as "listed, first observed 7 to 30 days ago (age 1), severity band 76, stage 2 = synthetic warming only" - the same verdict the human dashboard shows, in a form a mailbox provider or filter can act on with one query. That is why Heatwave "feeds real filtering" with no integration work: a partner just adds a DNS lookup. (One wrinkle worth noting: for a stage-4 "pre-warming" answer, Validity says the 2nd octet is the domain's registration age, not an observation age.) This decode is Validity's own, published in the "How to read this DNS answer" reference on the lookup tool:
Delisting is hard, by design. Validity is explicit that "ending synthetic warming or cold outreach does not, by itself, invalidate a previously accurate observation" - switching off a warmup service does not clear a listing. Removal comes only through a manual listing-review request, which Validity says it evaluates by hand, typically within two to five business days, and only if it decides the original determination was erroneous or the activity was incorrectly attributed to the domain.
It builds name-similarity "families" of look-alike domains. Heatwave groups domains that share a brand stem across different extensions and variants - for example examplemail.com, examplemail.us and examplemail-group.com - and will surface members of that family even when the domain you actually looked up is not listed. Validity goes further: its DNS decode shows a "pre-warming" stage (stage 4) that publishes a registered sibling of a warming family pre-emptively, before it has been observed sending at all - name-family membership alone is enough to be listed. This is clustering by name, not by confirmed ownership: Validity is explicit that "name similarity is an investigative lead, not proof," and a related listing is not the same as your domain being blocklisted. It is still worth watching: a warmed look-alike you do not control could create noise around your brand, and how much weight any given mailbox provider or filter places on such an association is not something Validity publishes. Treat a related-domain flag as a prompt to investigate, not automatically a sign that you did something wrong.
If a related-domain listing genuinely is not yours - a lookalike someone else registered, or a domain you do not control - the remedy is a listing review request, since misattribution and impersonation are among the few grounds Validity will act on.
What senders should do
- Stop artificial warmup now. If your cold-email stack includes an automated warmup pool that exchanges mail between mailboxes, that is exactly what Heatwave targets. Warm gradually with real sends to engaged recipients instead.
- Check your domains - and your lookalikes. Look yourself up at lookup.validity.tools, and watch for warmed lookalike domains that could drag your primary domain down.
- Monitor your blocklist and reputation status continuously, so a new listing does not surprise you weeks into a drop in inbox placement.
- Build reputation you actually own: correct SPF, DKIM and DMARC, clean lists, and real engagement. That is the only "warmup" no blocklist can penalise.
Heatwave is part of a broader shift: mailbox providers and their data partners are getting better at telling manufactured signals from earned ones. For anyone doing email properly it changes nothing. For anyone renting reputation from a warmup farm, the ground just moved.