Blacklists Compared

13 April 2002

[ Fighting Spam | Blacklists Compared | Current Blacklist Comparison ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
7442(total number of IP addresses tested, including 419 at SDSC)
3341(union of most IP zones)
2612xbl.selwerd.cx
1662blackholes.five-ten-sg.com (union of all results)
1098bl.spamcop.net
1065relays.osirusoft.com (union of all results)
965dnsbl.njabl.org (union of all results)
955dnsbl.njabl.org (result 127.0.0.2 = source or relay)
793blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
629relays.osirusoft.com (result 127.0.0.2 = relay)
629inputs.relays.osirusoft.com
563relays.ordb.org
529ztl.dorkslayers.com
502block.blars.org
493korea.services.net
469blackholes.intersil.net
422relays.visi.com
384work.drbl.croco.net
348blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
336t1.bl.reynolds.net.au
312blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
305blackholes.wirehub.net
302orbs.dorkslayers.com
286relays.osirusoft.com (result 127.0.0.4 = spam source)
257unconfirmed.dsbl.org
217blackholes.2mbit.com (union of all results)
195blacklist.spambag.org
181spews.relays.osirusoft.com
173flowgoaway.com
172blocktest.relays.osirusoft.com (not a blacklist!)
165blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
145proxies.relays.monkeys.com
143spamsources.fabel.dk
135relays.osirusoft.com (result 127.0.0.9 = open proxy)
134socks.relays.osirusoft.com
124ipwhois.rfc-ignorant.org
123spamsources.relays.osirusoft.com (union of all results)
120spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
113spam.wytnij.to
1123y.spam.mrs.kithrup.com
89blackholes.2mbit.com (result 127.0.0.2 = relay)
89relays.dorkslayers.com
80spamguard.leadmon.net (union of all results)
73blackholes.2mbit.com (result 127.0.0.10 = spam haven)
59sbl.spamhaus.org
48blackholes.2mbit.com (result 127.0.0.4 = spam source)
45opm.blitzed.org
44spamguard.leadmon.net (result 127.0.0.2 = dialup)
41blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
39relays.osirusoft.com (result 127.0.0.6 = spamsites)
38http.opm.blitzed.org
37formmail.relays.monkeys.com
35spamhaus.relays.osirusoft.com
35dews.qmail.org
34spammers.v6net.org
25spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
21dynablock.wirehub.net (result 127.0.0.2 = dialup)
21dynablock.wirehub.net (union of all results)
12list.dsbl.org
11socks.opm.blitzed.org
10dnsbl.njabl.org (result 127.0.0.3 = dialup)
10spamguard.leadmon.net (result 127.0.0.3 = spam source)
9dialups.relays.osirusoft.com
9relays.osirusoft.com (result 127.0.0.3 = dialup)
7blackholes.2mbit.com (result 127.0.0.9 = open proxy)
7blackhole.compu.net
3spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
3spamsites.relays.osirusoft.com (result 127.0.0.6)
3spamsites.relays.osirusoft.com (union of all results)
2blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
2pm0-no-more.compu.net
1spamguard.leadmon.net (result 127.0.0.5 = relay)
1blackholes.five-ten-sg.com (result 127.0.0.6 = relay)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net" and the pm0-no-more.compu.net zone "blocks all pm0 email."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
7442(total number of IP addresses whose names were tested, including 419 at SDSC)
937(union of all domain zones)
768abuse.rfc-ignorant.org
219whois.rfc-ignorant.org
6client-domain.sjesl.monkeys.com
5dsn.rfc-ignorant.org (zone not intended for this use)
3postmaster.rfc-ignorant.org
2sender-domain.sjesl.monkeys.com (zone not intended for this use)
1helo-domain.sjesl.monkeys.com (zone not intended for this use)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
4912(total number of domains tested, including 166 at SDSC)
500(union of all domain zones)
247abuse.rfc-ignorant.org
129sender-domain.sjesl.monkeys.com
110postmaster.rfc-ignorant.org
74helo-domain.sjesl.monkeys.com (zone not intended for this use)
62whois.rfc-ignorant.org
57dsn.rfc-ignorant.org
54client-domain.sjesl.monkeys.com (zone not intended for this use)
27ex.dnsbl.org (union of all results)
24ex.dnsbl.org (result 127.0.0.2 = spamsites)
6bandwidth-pigs.monkeys.com
3ex.dnsbl.org (result 127.0.0.3 = spam source)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 15 April 2002.