Blacklists Compared

29 March 2003

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
11467(total number of IP addresses tested, including 429 at SDSC)
7999(union of most IP zones)
5765xbl.selwerd.cx
4872blackholes.five-ten-sg.com (union of all results)
3352t1.bl.reynolds.net.au
2905blackholes.wirehub.net
2624block.blars.org
2362relays.osirusoft.com (union of all results)
2349no-more-funn.moensted.dk (union of all results)
2084dnsbl.njabl.org (union of all results)
1858unconfirmed.dsbl.org
1792blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
1518list.dsbl.org
1341blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
1334bl.spamcop.net
1280dnsbl.sorbs.net (union of all results)
1262blackholes.intersil.net
1254ztl.dorkslayers.com
1233spamhaus.relays.osirusoft.com
1228blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
1211no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
1210sbl.spamhaus.org
1209proxies.blackholes.wirehub.net
1200relays.osirusoft.com (result 127.0.0.6 = spamsites)
1155cn-kr.blackholes.us (union of all results)
1135proxies.relays.monkeys.com (result 127.0.0.2 = open proxy)
1135proxies.relays.monkeys.com (union of all results)
985relays.osirusoft.com (result 127.0.0.4 = spam source)
981spews.relays.osirusoft.com
933spews.bl.reynolds.net.au
918ipwhois.rfc-ignorant.org
870dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
832dnsbl.njabl.org (result 127.0.0.9 = open proxy)
774dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
773blocktest.relays.osirusoft.com (not a blacklist!)
723dnsbl.njabl.org (result 127.0.0.4 = spam source)
705opm.blitzed.org
641spam.dnsrbl.net
581no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
580korea.services.net
579ybl.megacity.org
579cn-kr.blackholes.us (result 127.0.0.2 = China)
579china.blackholes.us
577work.drbl.croco.net
576cn-kr.blackholes.us (result 127.0.0.3 = Korea)
576korea.blackholes.us
566cw.blackholes.us
524rackspace.blackholes.us
498dnsbl.delink.net
442spamsources.fabel.dk
431blacklist.spambag.org
419spam.wytnij.to
404blackholes.uceb.org (union of all results)
389dnsbl.njabl.org (result 127.0.0.2 = source or relay)
378relays.osirusoft.com (result 127.0.0.2 = relay)
378inputs.relays.osirusoft.com
375blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
319no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
287multihop.dsbl.org
238brazil.blackholes.us
238blackholes.uceb.org (result 127.0.0.4 = spam source network)
233flowgoaway.com
230relays.bl.kundenserver.de
220mail-abuse.blacklist.jippg.org
180verio.blackholes.us
176spamguard.leadmon.net (union of all results)
175dun.dnsrbl.net
175spamsources.relays.osirusoft.com (union of all results)
161spamguard.leadmon.net (result 127.0.0.2 = dialup)
160spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
154taiwan.blackholes.us
146relays.ordb.org
134dnsbl.njabl.org (result 127.0.0.3 = dialup)
1303y.spam.mrs.kithrup.com
122internap.blackholes.us
118dynablock.wirehub.net (result 127.0.0.2 = dialup)
118dynablock.wirehub.net (union of all results)
114rr.blackholes.us
111vox.schpider.com
108level3.blackholes.us
107orbs.dorkslayers.com
104blackholes.uceb.org (result 127.0.0.3 = spam source)
97relays.osirusoft.com (result 127.0.0.9 = open proxy)
97no-more-funn.moensted.dk (result 127.0.0.9 = misc)
97blackhole.compu.net
95xo.blackholes.us
94dialups.relays.osirusoft.com (union of all results)
91bl.deadbeef.com
90japan.blackholes.us
89blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
86dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
86no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
85dnsbl.sorbs.net (result 127.0.0.6 = spam source)
78socks.relays.osirusoft.com
75argentina.blackholes.us
70dialups.visi.com
67relays.osirusoft.com (result 127.0.0.3 = dialup)
66blackholes.brainerd.net
63blackholes.uceb.org (result 127.0.0.2 = relay)
59hongkong.blackholes.us
57bl.deadbeef.com
46spam.exsilia.net (union of all results)
44interbusiness.blackholes.us
44inflow.blackholes.us
44inflow.noflow.org
43tr.countries.nerd.dk
43spam.exsilia.net (result 127.0.0.2 = spam source)
41russia.blackholes.us
39dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
33above.blackholes.us
30singapore.blackholes.us
30no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
27he.blackholes.us
27cybercon.blackholes.us
26wanadoo-fr.blackholes.us
26relays.osirusoft.com (result 127.0.0.5 = relay output)
25eli.blackholes.us
21proxies.relays.osirusoft.com
19ph.rbl.cluecentral.net
18malaysia.blackholes.us
18dev.null.dk
18no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
18blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
17nigeria.blackholes.us
16covad.blackholes.us
16blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
15relays.dorkslayers.com
14thailand.blackholes.us
14epoch.blackholes.us
13spammers.v6net.org
13yipes.blackholes.us
12valuenet.blackholes.us
12blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
12spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
12spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
11blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
10telstra.blackholes.us
9dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
9dialup.blacklist.jippg.org (union of all results)
8dialups.relays.osirusoft.com (result 127.0.0.4 = no reverse DNS)
7broadwing.blackholes.us
7affinity.blackholes.us
6pajo.blackholes.us
6dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)
6no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
5valueweb.blackholes.us
4dnsbl.sorbs.net (result 127.0.0.5 = open relay)
3spamsources.relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
3relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
3spamguard.leadmon.net (result 127.0.0.3 = spam source)
3spam.exsilia.net (result 127.0.0.3 = virus source)
2dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
2blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
2proxies.exsilia.net
1ciberlynx.blackholes.us
1no-more-funn.moensted.dk (result 127.0.0.11 = repeated probes)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
11467(total number of IP addresses whose names were tested, including 429 at SDSC)
2864(union of all domain zones)
1943abuse.rfc-ignorant.org
1214whois.rfc-ignorant.org (union of all results)
867whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
348whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
14postmaster.rfc-ignorant.org
12dsn.rfc-ignorant.org (zone not intended for this use)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
8033(total number of domains tested, including 226 at SDSC)
1262(union of all domain zones)
612abuse.rfc-ignorant.org
517whois.rfc-ignorant.org (union of all results)
346whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
292postmaster.rfc-ignorant.org
209dsn.rfc-ignorant.org
171whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
78bl.deadbeef.com
31ex.dnsbl.org (union of all results)
28ex.dnsbl.org (result 127.0.0.2 = spamsites)
7bandwidth-pigs.monkeys.com
5in.dnsbl.org (union of all results)
3ex.dnsbl.org (result 127.0.0.3 = spam source)
3in.dnsbl.org (result 127.0.0.6 = unconfirmed opt-in)
1in.dnsbl.org (result 127.0.0.2 = spam source)
1in.dnsbl.org (result 127.0.0.3 = fraudulent sign-up)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 2 April 2003.