Blacklists Compared

22 June 2002

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
8017(total number of IP addresses tested, including 402 at SDSC)
4042(union of most IP zones)
3144xbl.selwerd.cx
1893blackholes.five-ten-sg.com (union of all results)
1276no-more-funn.moensted.dk (union of all results)
1174bl.spamcop.net
1148relays.osirusoft.com (union of all results)
907blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
779dnsbl.njabl.org (union of all results)
767ztl.dorkslayers.com
765dnsbl.njabl.org (result 127.0.0.2 = source or relay)
737blocktest.relays.osirusoft.com (not a blacklist!)
730no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
707block.blars.org
655unconfirmed.dsbl.org
556korea.services.net
537work.drbl.croco.net
521relays.osirusoft.com (result 127.0.0.4 = spam source)
510blackholes.intersil.net
454blackholes.wirehub.net
433spews.relays.osirusoft.com
414ipwhois.rfc-ignorant.org
380ybl.megacity.org
378list.dsbl.org
357blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
356inputs.relays.osirusoft.com
353relays.osirusoft.com (result 127.0.0.2 = relay)
336blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
329t1.bl.reynolds.net.au
310no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
270proxies.relays.monkeys.com
255relays.ordb.org
247relays.osirusoft.com (result 127.0.0.9 = open proxy)
246socks.relays.osirusoft.com
237blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
227multihop.dsbl.org
226relays.visi.com
210orbs.dorkslayers.com
192blacklist.spambag.org
176flowgoaway.com
170no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
168spamsources.fabel.dk
156spam.wytnij.to
149sbl.spamhaus.org
1483y.spam.mrs.kithrup.com
147spamhaus.relays.osirusoft.com
139relays.osirusoft.com (result 127.0.0.6 = spamsites)
128spamsources.relays.osirusoft.com (union of all results)
127opm.blitzed.org
127spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
82spamguard.leadmon.net (union of all results)
80http.opm.blitzed.org
52spamguard.leadmon.net (result 127.0.0.2 = dialup)
51socks.opm.blitzed.org
48blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
43formmail.relays.monkeys.com
40no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
37relays.dorkslayers.com
34spammers.v6net.org
33dynablock.wirehub.net (result 127.0.0.2 = dialup)
33dynablock.wirehub.net (union of all results)
26no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
25spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
19dialups.relays.osirusoft.com
19relays.osirusoft.com (result 127.0.0.3 = dialup)
14dnsbl.njabl.org (result 127.0.0.3 = dialup)
13proxies.relays.osirusoft.com
8blackhole.compu.net
7blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
5spamguard.leadmon.net (result 127.0.0.3 = spam source)
2wingate.opm.blitzed.org
2pm0-no-more.compu.net
1spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net" and the pm0-no-more.compu.net zone "blocks all pm0 email."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
8017(total number of IP addresses whose names were tested, including 402 at SDSC)
1233(union of all domain zones)
893abuse.rfc-ignorant.org
822whois.rfc-ignorant.org (union of all results)
640whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
182whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
7postmaster.rfc-ignorant.org
6client-domain.sjesl.monkeys.com
4dsn.rfc-ignorant.org (zone not intended for this use)
4sender-domain.sjesl.monkeys.com (zone not intended for this use)
2helo-domain.sjesl.monkeys.com (zone not intended for this use)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)
1ex.dnsbl.org (union of all results)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
5339(total number of domains tested, including 190 at SDSC)
744(union of all domain zones)
284abuse.rfc-ignorant.org
265whois.rfc-ignorant.org (union of all results)
183whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
160sender-domain.sjesl.monkeys.com
138postmaster.rfc-ignorant.org
104helo-domain.sjesl.monkeys.com (zone not intended for this use)
82whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
74dsn.rfc-ignorant.org
72client-domain.sjesl.monkeys.com (zone not intended for this use)
25ex.dnsbl.org (union of all results)
20ex.dnsbl.org (result 127.0.0.2 = spamsites)
6bandwidth-pigs.monkeys.com
5ex.dnsbl.org (result 127.0.0.3 = spam source)
1in.dnsbl.org (result 127.0.0.2 = spam source)
1in.dnsbl.org (union of all results)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 23 June 2002.