Blacklists Compared

30 March 2002

[ Fighting Spam | Blacklists Compared | Current Blacklist Comparison ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
7239(total number of IP addresses tested, including 424 at SDSC)
3319(union of most IP zones)
2321xbl.selwerd.cx
1538blackholes.five-ten-sg.com (union of all results)
1347bl.spamcop.net
998relays.osirusoft.com (union of all results)
937dnsbl.njabl.org (union of all results)
923dnsbl.njabl.org (result 127.0.0.2 = source or relay)
730blocktest.relays.osirusoft.com (not a blacklist!)
687blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
610relays.osirusoft.com (result 127.0.0.2 = relay)
606inputs.relays.osirusoft.com
557relays.ordb.org
516work.drbl.croco.net
507ztl.dorkslayers.com
486block.blars.org
443korea.services.net
440blackholes.intersil.net
365blackholes.wirehub.net
351t1.bl.reynolds.net.au
328relays.visi.com
326orbs.dorkslayers.com
324blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
306blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
244relays.osirusoft.com (result 127.0.0.4 = spam source)
181blacklist.spambag.org
169blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
165flowgoaway.com
162spews.relays.osirusoft.com
145relays.osirusoft.com (result 127.0.0.9 = open socks proxy)
145socks.relays.osirusoft.com
143spamsources.fabel.dk
141proxies.relays.monkeys.com
140blackholes.2mbit.com (union of all results)
1143y.spam.mrs.kithrup.com
108spamsources.relays.osirusoft.com (union of all results)
104spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
94spamguard.leadmon.net (union of all results)
93ipwhois.rfc-ignorant.org
83relays.dorkslayers.com
79spam.wytnij.to
69blackholes.2mbit.com (result 127.0.0.2 = relay)
66blackholes.2mbit.com (result 127.0.0.10 = spam haven)
55dev.null.dk
49blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
46spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
44spamguard.leadmon.net (result 127.0.0.2 = dialup)
40opm.blitzed.org
39spammers.v6net.org
32spamhaus.relays.osirusoft.com
31sbl.spamhaus.org
30http.opm.blitzed.org
30formmail.relays.monkeys.com
29dynablock.wirehub.net (result 127.0.0.2 = dialup)
29dynablock.wirehub.net (union of all results)
21relays.osirusoft.com (result 127.0.0.6 = spamsites)
20dews.qmail.org
14socks.opm.blitzed.org
14dnsbl.njabl.org (result 127.0.0.3 = dialup)
9dialups.relays.osirusoft.com
9relays.osirusoft.com (result 127.0.0.3 = dialup)
5blackholes.2mbit.com (result 127.0.0.4 = spam source)
4spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
4spamguard.leadmon.net (result 127.0.0.3 = spam source)
2spamsites.relays.osirusoft.com (result 127.0.0.6)
2blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
2pm0-no-more.compu.net
2spamsites.relays.osirusoft.com (union of all results)
1blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net" and the pm0-no-more.compu.net zone "blocks all pm0 email."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
7239(total number of IP addresses whose names were tested, including 424 at SDSC)
1013(union of all domain zones)
684abuse.rfc-ignorant.org
390whois.rfc-ignorant.org
7client-domain.sjesl.monkeys.com
5postmaster.rfc-ignorant.org
4dsn.rfc-ignorant.org (zone not intended for this use)
3sender-domain.sjesl.monkeys.com (zone not intended for this use)
1helo-domain.sjesl.monkeys.com (zone not intended for this use)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)
1ex.dnsbl.org (union of all results)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
4822(total number of domains tested, including 180 at SDSC)
651(union of all domain zones)
246whois.rfc-ignorant.org
208abuse.rfc-ignorant.org
140sender-domain.sjesl.monkeys.com
103postmaster.rfc-ignorant.org
74dsn.rfc-ignorant.org
71helo-domain.sjesl.monkeys.com (zone not intended for this use)
49client-domain.sjesl.monkeys.com (zone not intended for this use)
32ex.dnsbl.org (union of all results)
26ex.dnsbl.org (result 127.0.0.2 = spamsites)
6bandwidth-pigs.monkeys.com
6ex.dnsbl.org (result 127.0.0.3 = spam source)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 1 April 2002.