Blacklist log and tag - how does it work?

We’ve setup blacklist with the filter log and tag. Under the impression that the message was still be delivered but have a tag on it to indicate it was on a blacklist. Because we’ve just activated this the director of IT would like to make sure legit ones are not being stopped right now.

I can see that it’s working on the log side but it doesn’t appear to be tagging and still delivering. Is this not the idea of log and tag?

Subject: Blacklist log and tag - how does it work?

Look at the properties of a document for a field with the name $DNSBLSite (blacklisting) or $DNSWLSite (whitelisting).