Blacklists Compared

26 October 2002

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
8822(total number of IP addresses tested, including 456 at SDSC)
5500(union of most IP zones)
3845xbl.selwerd.cx
2764blackholes.five-ten-sg.com (union of all results)
1608relays.osirusoft.com (union of all results)
1502bl.spamcop.net
1450block.blars.org
1416blackholes.wirehub.net
1307no-more-funn.moensted.dk (union of all results)
1150ztl.dorkslayers.com
1124blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
888dnsbl.njabl.org (union of all results)
838dnsbl.njabl.org (result 127.0.0.2 = source or relay)
832blocktest.relays.osirusoft.com (not a blacklist!)
832cn-kr.blackholes.us (union of all results)
799no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
781cw.blackholes.us
761relays.osirusoft.com (result 127.0.0.4 = spam source)
749ipwhois.rfc-ignorant.org
747unconfirmed.dsbl.org
714blackholes.intersil.net
713blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
631spam.dnsrbl.net
564proxies.relays.monkeys.com
505spews.relays.osirusoft.com
500ybl.megacity.org
484cn-kr.blackholes.us (result 127.0.0.3 = Korea)
484korea.blackholes.us
478korea.services.net
458blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
456list.dsbl.org
439t1.bl.reynolds.net.au
436work.drbl.croco.net
430spamsources.relays.osirusoft.com (union of all results)
406spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
390relays.osirusoft.com (result 127.0.0.2 = relay)
390inputs.relays.osirusoft.com
376relays.osirusoft.com (result 127.0.0.9 = open proxy)
371socks.relays.osirusoft.com
364blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
348cn-kr.blackholes.us (result 127.0.0.2 = China)
348china.blackholes.us
340assholes.madscience.nl
317mail-abuse.blacklist.jippg.org
315relays.bl.kundenserver.de
293relays.ordb.org
278sbl.spamhaus.org
275spamhaus.relays.osirusoft.com
268relays.osirusoft.com (result 127.0.0.6 = spamsites)
254multihop.dsbl.org
245no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
237opm.blitzed.org
236spam.wytnij.to
230dnsbl.delink.net
217blacklist.spambag.org
216relays.visi.com
216flowgoaway.com
214no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
178http.opm.blitzed.org
1623y.spam.mrs.kithrup.com
156orbs.dorkslayers.com
149brazil.blackholes.us
148verio.blackholes.us
133spamsources.fabel.dk
119dev.null.dk
108internap.blackholes.us
104level3.blackholes.us
102spamguard.leadmon.net (union of all results)
101xo.blackholes.us
100ciberlynx.blackholes.us
96blackhole.compu.net
89taiwan.blackholes.us
86spamguard.leadmon.net (result 127.0.0.2 = dialup)
85blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
79rackspace.blackholes.us
72dialups.visi.com
71socks.opm.blitzed.org
67argentina.blackholes.us
66dun.dnsrbl.net
59japan.blackholes.us
58rr.blackholes.us
50dnsbl.njabl.org (result 127.0.0.3 = dialup)
47formmail.relays.monkeys.com
44russia.blackholes.us
42dialups.relays.osirusoft.com (union of all results)
34he.blackholes.us
33dynablock.wirehub.net (result 127.0.0.2 = dialup)
33inflow.blackholes.us
33dynablock.wirehub.net (union of all results)
32hongkong.blackholes.us
30no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
29dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
24relays.osirusoft.com (result 127.0.0.3 = dialup)
23singapore.blackholes.us
23nigeria.blackholes.us
22spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
20malaysia.blackholes.us
20relays.dorkslayers.com
15broadwing.blackholes.us
13dialups.relays.osirusoft.com (result 127.0.0.4 = no reverse DNS)
12eli.blackholes.us
12spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
12blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
11epoch.blackholes.us
10no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
8wanadoo-fr.blackholes.us
7blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
6thailand.blackholes.us
6proxies.relays.osirusoft.com
6no-more-funn.moensted.dk (result 127.0.0.9 = misc)
4relays.osirusoft.com (result 127.0.0.5 = relay output)
4spamguard.leadmon.net (result 127.0.0.3 = spam source)
3no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
2valueweb.blackholes.us
2spamsources.relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
1skynetweb.blackholes.us
1wingate.opm.blitzed.org
1spamsources.relays.osirusoft.com (result 127.0.0.9 = unconfirmed opt-in)
1spamsites.relays.osirusoft.com (result 127.0.0.6)
1relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
1dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
1blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
1spamsites.relays.osirusoft.com (union of all results)
1dialup.blacklist.jippg.org (union of all results)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
8822(total number of IP addresses whose names were tested, including 456 at SDSC)
1708(union of all domain zones)
1367abuse.rfc-ignorant.org
467whois.rfc-ignorant.org (union of all results)
280whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
187whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
10client-domain.sjesl.monkeys.com
6postmaster.rfc-ignorant.org
6dsn.rfc-ignorant.org (zone not intended for this use)
5sender-domain.sjesl.monkeys.com (zone not intended for this use)
4helo-domain.sjesl.monkeys.com (zone not intended for this use)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
6164(total number of domains tested, including 231 at SDSC)
1028(union of all domain zones)
416whois.rfc-ignorant.org (union of all results)
404abuse.rfc-ignorant.org
295whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
190postmaster.rfc-ignorant.org
167sender-domain.sjesl.monkeys.com
121whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
118dsn.rfc-ignorant.org
103helo-domain.sjesl.monkeys.com (zone not intended for this use)
77client-domain.sjesl.monkeys.com (zone not intended for this use)
28ex.dnsbl.org (union of all results)
21ex.dnsbl.org (result 127.0.0.2 = spamsites)
7bandwidth-pigs.monkeys.com
7ex.dnsbl.org (result 127.0.0.3 = spam source)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 29 October 2002.