Blacklists Compared

12 October 2002

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
8678(total number of IP addresses tested, including 595 at SDSC)
5189(union of most IP zones)
3564xbl.selwerd.cx
2483blackholes.five-ten-sg.com (union of all results)
1398bl.spamcop.net
1298relays.osirusoft.com (union of all results)
1272no-more-funn.moensted.dk (union of all results)
1239block.blars.org
1218blackholes.wirehub.net
1175ztl.dorkslayers.com
931blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
775cw.blackholes.us
764dnsbl.njabl.org (union of all results)
749cn-kr.blackholes.us (union of all results)
737no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
720dnsbl.njabl.org (result 127.0.0.2 = source or relay)
714unconfirmed.dsbl.org
707spam.dnsrbl.net
706blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
639blackholes.intersil.net
569relays.osirusoft.com (result 127.0.0.4 = spam source)
536ipwhois.rfc-ignorant.org
515ybl.megacity.org
514proxies.relays.monkeys.com
505cn-kr.blackholes.us (result 127.0.0.3 = Korea)
505korea.blackholes.us
500korea.services.net
444work.drbl.croco.net
398t1.bl.reynolds.net.au
395list.dsbl.org
390blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
388spews.relays.osirusoft.com
373inputs.relays.osirusoft.com
370relays.osirusoft.com (result 127.0.0.2 = relay)
366assholes.madscience.nl
353blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
318mail-abuse.blacklist.jippg.org
303socks.relays.osirusoft.com
301relays.osirusoft.com (result 127.0.0.9 = open proxy)
284multihop.dsbl.org
266relays.bl.kundenserver.de
261spamsources.relays.osirusoft.com (union of all results)
251no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
244cn-kr.blackholes.us (result 127.0.0.2 = China)
244china.blackholes.us
241spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
240spam.wytnij.to
233relays.ordb.org
232no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
219flowgoaway.com
205blacklist.spambag.org
200relays.visi.com
195opm.blitzed.org
1823y.spam.mrs.kithrup.com
177sbl.spamhaus.org
175relays.osirusoft.com (result 127.0.0.6 = spamsites)
175spamhaus.relays.osirusoft.com
163http.opm.blitzed.org
158blocktest.relays.osirusoft.com (not a blacklist!)
151verio.blackholes.us
138dev.null.dk
122spamsources.fabel.dk
119orbs.dorkslayers.com
116level3.blackholes.us
105brazil.blackholes.us
94rackspace.blackholes.us
93xo.blackholes.us
91dun.dnsrbl.net
88spamguard.leadmon.net (union of all results)
83blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
73taiwan.blackholes.us
69spamguard.leadmon.net (result 127.0.0.2 = dialup)
67blackhole.compu.net
64formmail.relays.monkeys.com
63dialups.visi.com
62internap.blackholes.us
61ciberlynx.blackholes.us
60rr.blackholes.us
49argentina.blackholes.us
49socks.opm.blitzed.org
44dnsbl.njabl.org (result 127.0.0.3 = dialup)
43dnsbl.delink.net
42dialups.relays.osirusoft.com (union of all results)
36dynablock.wirehub.net (result 127.0.0.2 = dialup)
36japan.blackholes.us
36inflow.blackholes.us
36dynablock.wirehub.net (union of all results)
34no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
31singapore.blackholes.us
30dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
29russia.blackholes.us
28relays.osirusoft.com (result 127.0.0.3 = dialup)
27eli.blackholes.us
20nigeria.blackholes.us
18spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
17broadwing.blackholes.us
16relays.dorkslayers.com
15spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
13epoch.blackholes.us
12dialups.relays.osirusoft.com (result 127.0.0.4 = no reverse DNS)
12blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
11thailand.blackholes.us
9he.blackholes.us
8wanadoo-fr.blackholes.us
8no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
7no-more-funn.moensted.dk (result 127.0.0.9 = misc)
7blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
5dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
5dialup.blacklist.jippg.org (union of all results)
4valueweb.blackholes.us
4wingate.opm.blitzed.org
4proxies.relays.osirusoft.com
4spamguard.leadmon.net (result 127.0.0.3 = spam source)
3spamsources.relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
3relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
3no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
1skynetweb.blackholes.us
1spamsources.relays.osirusoft.com (result 127.0.0.9 = unconfirmed opt-in)
1spamsites.relays.osirusoft.com (result 127.0.0.6)
1blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)
1spamsites.relays.osirusoft.com (union of all results)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
8678(total number of IP addresses whose names were tested, including 595 at SDSC)
1700(union of all domain zones)
1298abuse.rfc-ignorant.org
552whois.rfc-ignorant.org (union of all results)
298whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
254whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
12postmaster.rfc-ignorant.org
11dsn.rfc-ignorant.org (zone not intended for this use)
8client-domain.sjesl.monkeys.com
4sender-domain.sjesl.monkeys.com (zone not intended for this use)
3helo-domain.sjesl.monkeys.com (zone not intended for this use)
1ex.dnsbl.org (result 127.0.0.2 = spamsites)
1ex.dnsbl.org (union of all results)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
5857(total number of domains tested, including 236 at SDSC)
1034(union of all domain zones)
418whois.rfc-ignorant.org (union of all results)
416abuse.rfc-ignorant.org
297whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
195postmaster.rfc-ignorant.org
144sender-domain.sjesl.monkeys.com
121whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
119dsn.rfc-ignorant.org
94helo-domain.sjesl.monkeys.com (zone not intended for this use)
65client-domain.sjesl.monkeys.com (zone not intended for this use)
31ex.dnsbl.org (union of all results)
24ex.dnsbl.org (result 127.0.0.2 = spamsites)
7bandwidth-pigs.monkeys.com
7ex.dnsbl.org (result 127.0.0.3 = spam source)
1in.dnsbl.org (result 127.0.0.2 = spam source)
1in.dnsbl.org (union of all results)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 15 October 2002.