Blacklists Compared

15 December 2001

[ Fighting Spam | Blacklists Compared | Current Blacklist Comparison ]

Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

There were intermittent difficulties getting results from all of the relays.osirusoft.com zones during the survey this week, so their hit counts are lower than they would otherwise be.

  Hits   DNS Zone
  6745  (total number of IP addresses tested, including 283 at SDSC)
  2439  (union of most IP zones)
  1930  xbl.selwerd.cx
  1201  bl.spamcop.net
   997  blackholes.five-ten-sg.com (union of all results)
   742  outputs.orbz.org
   642  relays.ordb.org
   548  inputs.orbz.org
   400  ztl.dorkslayers.com
   398  blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
   329  blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
   324  orbs.dorkslayers.com
   271  blackholes.intersil.net
   234  block.blars.org
   164  relays.visi.com
   159  dev.null.dk
   153  flowgoaway.com
   146  blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
   127  pm0-no-more.compu.net
   126  blacklist.spambag.org
   120  blocktest.relays.osirusoft.com (not a blacklist!)
   109  blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
   109  relays.dorkslayers.com
   101  relays.osirusoft.com (union of all results)
    71  spammers.v6net.org
    65  ipwhois.rfc-ignorant.org
    55  relays.osirusoft.com (result 127.0.0.2 = relay)
    53  inputs.relays.osirusoft.com
    43  relays.osirusoft.com (result 127.0.0.4 = spam source)
    33  spews.relays.osirusoft.com
    32  blackhole.compu.net
    22  spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
    22  spamsources.relays.osirusoft.com (union of all results)
    14  blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
     2  dialups.relays.osirusoft.com
     2  relays.osirusoft.com (result 127.0.0.3 = dialup)
     1  relays.osirusoft.com (result 127.0.0.6 = spamsites)
     1  spamhaus.relays.osirusoft.com
     1  blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

  Hits   DNS Zone
  6745  (total number of IP addresses whose names were tested, including 283 at SDSC)
   570  (union of all domain zones)
   346  whois.rfc-ignorant.org
   258  abuse.rfc-ignorant.org
     4  postmaster.rfc-ignorant.org
     3  dsn.rfc-ignorant.org (zone not intended for this use)
Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

  Hits   DNS Zone
  4646  (total number of domains tested, including 63 at SDSC)
   393  (union of all domain zones)
   207  whois.rfc-ignorant.org
   123  abuse.rfc-ignorant.org
    75  postmaster.rfc-ignorant.org
    48  dsn.rfc-ignorant.org
    10  bandwidth-pigs.monkeys.com
The web sites listed below provide detailed information about the DNS zones listed above, including their listing policies and suggestions for appropriate use.

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net" and the pm0-no-more.compu.net zone "blocks all pm0 email."


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 15 December 2001.