Blacklists Compared

6 April 2002

[ Fighting Spam | Blacklists Compared | Current Blacklist Comparison ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
7627(total number of IP addresses tested, including 417 at SDSC)
3406(union of most IP zones)
2560xbl.selwerd.cx
1707blackholes.five-ten-sg.com (union of all results)
1135bl.spamcop.net
1047relays.osirusoft.com (union of all results)
972dnsbl.njabl.org (union of all results)
963dnsbl.njabl.org (result 127.0.0.2 = source or relay)
859blocktest.relays.osirusoft.com (not a blacklist!)
770blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
631inputs.relays.osirusoft.com
630relays.osirusoft.com (result 127.0.0.2 = relay)
553relays.ordb.org
521ztl.dorkslayers.com
491block.blars.org
487korea.services.net
459blackholes.intersil.net
454relays.visi.com
452work.drbl.croco.net
434blackholes.wirehub.net
381t1.bl.reynolds.net.au
366orbs.dorkslayers.com
324blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
315blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
243relays.osirusoft.com (result 127.0.0.4 = spam source)
210blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
198blacklist.spambag.org
194blackholes.2mbit.com (union of all results)
162spews.relays.osirusoft.com
162flowgoaway.com
161proxies.relays.monkeys.com
159spamsources.fabel.dk
149socks.relays.osirusoft.com
148relays.osirusoft.com (result 127.0.0.9 = open proxy)
1253y.spam.mrs.kithrup.com
108ipwhois.rfc-ignorant.org
102spam.wytnij.to
102relays.dorkslayers.com
99spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
99spamsources.relays.osirusoft.com (union of all results)
87blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
87spamguard.leadmon.net (union of all results)
86blackholes.2mbit.com (result 127.0.0.2 = relay)
76blackholes.2mbit.com (result 127.0.0.10 = spam haven)
74unconfirmed.dsbl.org
62list.dsbl.org
47spamguard.leadmon.net (result 127.0.0.2 = dialup)
41sbl.spamhaus.org
40spammers.v6net.org
39spamhaus.relays.osirusoft.com
36opm.blitzed.org
34relays.osirusoft.com (result 127.0.0.6 = spamsites)
33spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
28http.opm.blitzed.org
26blackholes.2mbit.com (result 127.0.0.4 = spam source)
24dews.qmail.org
23dynablock.wirehub.net (result 127.0.0.2 = dialup)
23formmail.relays.monkeys.com
23dynablock.wirehub.net (union of all results)
14dialups.relays.osirusoft.com
13relays.osirusoft.com (result 127.0.0.3 = dialup)
10socks.opm.blitzed.org
9dnsbl.njabl.org (result 127.0.0.3 = dialup)
7spamguard.leadmon.net (result 127.0.0.3 = spam source)
6blackholes.2mbit.com (result 127.0.0.9 = open proxy)
5spamsites.relays.osirusoft.com (result 127.0.0.6)
5spamsites.relays.osirusoft.com (union of all results)
1wingate.opm.blitzed.org
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1pm0-no-more.compu.net

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net" and the pm0-no-more.compu.net zone "blocks all pm0 email."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
7627(total number of IP addresses whose names were tested, including 417 at SDSC)
1108(union of all domain zones)
756abuse.rfc-ignorant.org
424whois.rfc-ignorant.org
9postmaster.rfc-ignorant.org
5client-domain.sjesl.monkeys.com
4dsn.rfc-ignorant.org (zone not intended for this use)
2sender-domain.sjesl.monkeys.com (zone not intended for this use)
1bandwidth-pigs.monkeys.com
1helo-domain.sjesl.monkeys.com (zone not intended for this use)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
4994(total number of domains tested, including 172 at SDSC)
648(union of all domain zones)
248whois.rfc-ignorant.org
212abuse.rfc-ignorant.org
132sender-domain.sjesl.monkeys.com
117postmaster.rfc-ignorant.org
69helo-domain.sjesl.monkeys.com (zone not intended for this use)
56dsn.rfc-ignorant.org
52client-domain.sjesl.monkeys.com (zone not intended for this use)
25ex.dnsbl.org (union of all results)
22ex.dnsbl.org (result 127.0.0.2 = spamsites)
7bandwidth-pigs.monkeys.com
3ex.dnsbl.org (result 127.0.0.3 = spam source)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 8 April 2002.