Blacklists Compared

14 September 2002

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
8464(total number of IP addresses tested, including 648 at SDSC)
4841(union of most IP zones)
3427xbl.selwerd.cx
2314blackholes.five-ten-sg.com (union of all results)
1276no-more-funn.moensted.dk (union of all results)
1209block.blars.org
1157bl.spamcop.net
1073relays.osirusoft.com (union of all results)
906blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
826ztl.dorkslayers.com
798cw.blackholes.us
789blackholes.wirehub.net
774dnsbl.njabl.org (union of all results)
765cn-kr.blackholes.us (union of all results)
753no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
731dnsbl.njabl.org (result 127.0.0.2 = source or relay)
731spam.dnsrbl.net
692unconfirmed.dsbl.org
628blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
546ipwhois.rfc-ignorant.org
523ybl.megacity.org
510cn-kr.blackholes.us (result 127.0.0.3 = Korea)
510korea.blackholes.us
507korea.services.net
495t1.bl.reynolds.net.au
495relays.osirusoft.com (result 127.0.0.4 = spam source)
480blackholes.intersil.net
385spews.relays.osirusoft.com
381list.dsbl.org
379mail-abuse.blacklist.jippg.org
361inputs.relays.osirusoft.com
358relays.osirusoft.com (result 127.0.0.2 = relay)
347assholes.madscience.nl
334blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
319relays.bl.kundenserver.de
316relays.ordb.org
316blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
309proxies.relays.monkeys.com
290relays.visi.com
284multihop.dsbl.org
255cn-kr.blackholes.us (result 127.0.0.2 = China)
255china.blackholes.us
245spam.wytnij.to
238no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
236no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
216flowgoaway.com
206spamsources.relays.osirusoft.com (union of all results)
203relays.osirusoft.com (result 127.0.0.9 = open proxy)
195socks.relays.osirusoft.com
189blacklist.spambag.org
188spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
176sbl.spamhaus.org
157verio.blackholes.us
153spamhaus.relays.osirusoft.com
149relays.osirusoft.com (result 127.0.0.6 = spamsites)
149dev.null.dk
139orbs.dorkslayers.com
137spamsources.fabel.dk
1323y.spam.mrs.kithrup.com
125work.drbl.croco.net
121opm.blitzed.org
114blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
112brazil.blackholes.us
100level3.blackholes.us
100http.opm.blitzed.org
99xo.blackholes.us
99dun.dnsrbl.net
81spamguard.leadmon.net (union of all results)
77blocktest.relays.osirusoft.com (not a blacklist!)
75taiwan.blackholes.us
71dnsbl.delink.net
69rr.blackholes.us
65spamguard.leadmon.net (result 127.0.0.2 = dialup)
57blackhole.compu.net
52japan.blackholes.us
48ciberlynx.blackholes.us
48dialups.relays.osirusoft.com (union of all results)
47argentina.blackholes.us
44rackspace.blackholes.us
43dnsbl.njabl.org (result 127.0.0.3 = dialup)
41formmail.relays.monkeys.com
38dynablock.wirehub.net (result 127.0.0.2 = dialup)
38dynablock.wirehub.net (union of all results)
37inflow.blackholes.us
35dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
33no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
28socks.opm.blitzed.org
28relays.osirusoft.com (result 127.0.0.3 = dialup)
25nigeria.blackholes.us
24relays.dorkslayers.com
20eli.blackholes.us
19russia.blackholes.us
18broadwing.blackholes.us
17thailand.blackholes.us
17spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
14spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
13proxies.relays.osirusoft.com
13dialups.relays.osirusoft.com (result 127.0.0.4 = no reverse DNS)
11blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
9epoch.blackholes.us
9no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
6wanadoo-fr.blackholes.us
4no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
4blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
3no-more-funn.moensted.dk (result 127.0.0.9 = misc)
2valueweb.blackholes.us
2skynetweb.blackholes.us
2spamsources.relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
2spamguard.leadmon.net (result 127.0.0.3 = spam source)
2dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
2dialup.blacklist.jippg.org (union of all results)
1wingate.opm.blitzed.org
1spamsites.relays.osirusoft.com (result 127.0.0.6)
1relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
1blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)
1pm0-no-more.compu.net
1spamsites.relays.osirusoft.com (union of all results)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net" and the pm0-no-more.compu.net zone "blocks all pm0 email."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
8464(total number of IP addresses whose names were tested, including 648 at SDSC)
1514(union of all domain zones)
1209abuse.rfc-ignorant.org
458whois.rfc-ignorant.org (union of all results)
251whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
207whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
6postmaster.rfc-ignorant.org
6dsn.rfc-ignorant.org (zone not intended for this use)
5sender-domain.sjesl.monkeys.com (zone not intended for this use)
5client-domain.sjesl.monkeys.com
2helo-domain.sjesl.monkeys.com (zone not intended for this use)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)
1ex.dnsbl.org (union of all results)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
5508(total number of domains tested, including 214 at SDSC)
892(union of all domain zones)
374abuse.rfc-ignorant.org
321whois.rfc-ignorant.org (union of all results)
208whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
176postmaster.rfc-ignorant.org
145sender-domain.sjesl.monkeys.com
113whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
101dsn.rfc-ignorant.org
99helo-domain.sjesl.monkeys.com (zone not intended for this use)
72client-domain.sjesl.monkeys.com (zone not intended for this use)
35ex.dnsbl.org (union of all results)
24ex.dnsbl.org (result 127.0.0.2 = spamsites)
11ex.dnsbl.org (result 127.0.0.3 = spam source)
7bandwidth-pigs.monkeys.com
1in.dnsbl.org (result 127.0.0.2 = spam source)
1in.dnsbl.org (union of all results)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 16 September 2002.