Blacklists Compared

19 October 2002

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
9026(total number of IP addresses tested, including 463 at SDSC)
5630(union of most IP zones)
3927xbl.selwerd.cx
2784blackholes.five-ten-sg.com (union of all results)
2120bl.spamcop.net
1534relays.osirusoft.com (union of all results)
1412blackholes.wirehub.net
1384block.blars.org
1354no-more-funn.moensted.dk (union of all results)
1211ztl.dorkslayers.com
1081blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
865cn-kr.blackholes.us (union of all results)
863dnsbl.njabl.org (union of all results)
824dnsbl.njabl.org (result 127.0.0.2 = source or relay)
818no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
816unconfirmed.dsbl.org
801blocktest.relays.osirusoft.com (not a blacklist!)
784cw.blackholes.us
756blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
750relays.osirusoft.com (result 127.0.0.4 = spam source)
673spam.dnsrbl.net
650blackholes.intersil.net
594proxies.relays.monkeys.com
586ipwhois.rfc-ignorant.org
527ybl.megacity.org
511cn-kr.blackholes.us (result 127.0.0.3 = Korea)
511korea.blackholes.us
507korea.services.net
503list.dsbl.org
449blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
445spews.relays.osirusoft.com
440spamsources.relays.osirusoft.com (union of all results)
439work.drbl.croco.net
423t1.bl.reynolds.net.au
414spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
396relays.osirusoft.com (result 127.0.0.2 = relay)
396blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
393inputs.relays.osirusoft.com
354cn-kr.blackholes.us (result 127.0.0.2 = China)
354china.blackholes.us
353assholes.madscience.nl
318relays.osirusoft.com (result 127.0.0.9 = open proxy)
314mail-abuse.blacklist.jippg.org
309socks.relays.osirusoft.com
308relays.ordb.org
305relays.bl.kundenserver.de
276relays.visi.com
276multihop.dsbl.org
260no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
249spam.wytnij.to
247flowgoaway.com
230opm.blitzed.org
221no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
215sbl.spamhaus.org
214dnsbl.delink.net
211spamhaus.relays.osirusoft.com
208blacklist.spambag.org
196relays.osirusoft.com (result 127.0.0.6 = spamsites)
1843y.spam.mrs.kithrup.com
167http.opm.blitzed.org
159orbs.dorkslayers.com
150verio.blackholes.us
131brazil.blackholes.us
130dev.null.dk
128spamsources.fabel.dk
107level3.blackholes.us
97internap.blackholes.us
92dun.dnsrbl.net
91spamguard.leadmon.net (union of all results)
88ciberlynx.blackholes.us
84taiwan.blackholes.us
82xo.blackholes.us
80blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
79rr.blackholes.us
78rackspace.blackholes.us
75socks.opm.blitzed.org
74blackhole.compu.net
73spamguard.leadmon.net (result 127.0.0.2 = dialup)
69dialups.visi.com
67formmail.relays.monkeys.com
55argentina.blackholes.us
46japan.blackholes.us
44dialups.relays.osirusoft.com (union of all results)
39dnsbl.njabl.org (result 127.0.0.3 = dialup)
37inflow.blackholes.us
35dynablock.wirehub.net (result 127.0.0.2 = dialup)
35hongkong.blackholes.us
35dynablock.wirehub.net (union of all results)
34no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
33dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
29relays.osirusoft.com (result 127.0.0.3 = dialup)
28russia.blackholes.us
25relays.dorkslayers.com
24singapore.blackholes.us
23nigeria.blackholes.us
21spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
16broadwing.blackholes.us
15spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
14eli.blackholes.us
14blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
12he.blackholes.us
11epoch.blackholes.us
11dialups.relays.osirusoft.com (result 127.0.0.4 = no reverse DNS)
9wanadoo-fr.blackholes.us
9no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
8thailand.blackholes.us
8malaysia.blackholes.us
7no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
7blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
7dialup.blacklist.jippg.org (union of all results)
6proxies.relays.osirusoft.com
6dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
5no-more-funn.moensted.dk (result 127.0.0.9 = misc)
4wingate.opm.blitzed.org
4spamsources.relays.osirusoft.com (result 127.0.0.9 = unconfirmed opt-in)
4relays.osirusoft.com (result 127.0.0.5 = relay output)
3valueweb.blackholes.us
3spamguard.leadmon.net (result 127.0.0.3 = spam source)
2spamsources.relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
2relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
1skynetweb.blackholes.us
1spamsites.relays.osirusoft.com (result 127.0.0.6)
1dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
1blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
1spamsites.relays.osirusoft.com (union of all results)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
9026(total number of IP addresses whose names were tested, including 463 at SDSC)
1741(union of all domain zones)
1375abuse.rfc-ignorant.org
507whois.rfc-ignorant.org (union of all results)
281whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
226whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
11postmaster.rfc-ignorant.org
9dsn.rfc-ignorant.org (zone not intended for this use)
8client-domain.sjesl.monkeys.com
4sender-domain.sjesl.monkeys.com (zone not intended for this use)
4helo-domain.sjesl.monkeys.com (zone not intended for this use)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
6391(total number of domains tested, including 219 at SDSC)
1048(union of all domain zones)
426whois.rfc-ignorant.org (union of all results)
395abuse.rfc-ignorant.org
304whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
198postmaster.rfc-ignorant.org
166sender-domain.sjesl.monkeys.com
129dsn.rfc-ignorant.org
122whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
104helo-domain.sjesl.monkeys.com (zone not intended for this use)
73client-domain.sjesl.monkeys.com (zone not intended for this use)
30ex.dnsbl.org (union of all results)
23ex.dnsbl.org (result 127.0.0.2 = spamsites)
9bandwidth-pigs.monkeys.com
7ex.dnsbl.org (result 127.0.0.3 = spam source)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 22 October 2002.