Blacklists Compared

19 April 2003

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx zone because it is too aggressive to be widely useful, and excludes the blocktest.relays.osirusoft.com zone because it is not a blacklist.

HitsDNS Zone
11472(total number of IP addresses tested, including 469 at SDSC)
7978(union of most IP zones)
5626xbl.selwerd.cx
4846blackholes.five-ten-sg.com (union of all results)
3315t1.bl.reynolds.net.au
2886block.blars.org
2684blackholes.wirehub.net
2449no-more-funn.moensted.dk (union of all results)
2003unconfirmed.dsbl.org
1807dnsbl.njabl.org (union of all results)
1773blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
1753relays.osirusoft.com (union of all results)
1671list.dsbl.org
1601blackholes.five-ten-sg.com (result 127.0.0.3 = dialup)
1530bl.spamcop.net
1492dnsbl.sorbs.net (union of all results)
1422proxies.blackholes.wirehub.net
1320proxies.relays.monkeys.com (result 127.0.0.2 = open proxy)
1320proxies.relays.monkeys.com (union of all results)
1306no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
1250cn-kr.blackholes.us (union of all results)
1032ztl.dorkslayers.com
987spews.bl.reynolds.net.au
984blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
973ipwhois.rfc-ignorant.org
962dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
932opm.blitzed.org
926relays.osirusoft.com (result 127.0.0.4 = spam source)
914spews.relays.osirusoft.com
912dnsbl.njabl.org (result 127.0.0.9 = open proxy)
894dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
784blocktest.relays.osirusoft.com (not a blacklist!)
772blackholes.intersil.net
759sbl.spamhaus.org
718cn-kr.blackholes.us (result 127.0.0.2 = China)
718china.blackholes.us
697spamhaus.relays.osirusoft.com
691work.drbl.croco.net
676spam.dnsrbl.net
651cw.blackholes.us
638relays.osirusoft.com (result 127.0.0.6 = spamsites)
620ybl.megacity.org
619no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
538korea.services.net
538dnsbl.delink.net
532cn-kr.blackholes.us (result 127.0.0.3 = Korea)
532korea.blackholes.us
527spamsources.fabel.dk
482dnsbl.njabl.org (result 127.0.0.4 = spam source)
345blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
343blacklist.spambag.org
292spam.wytnij.to
289no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
282dnsbl.njabl.org (result 127.0.0.2 = source or relay)
264multihop.dsbl.org
260blackholes.uceb.org (union of all results)
245relays.osirusoft.com (result 127.0.0.2 = relay)
244inputs.relays.osirusoft.com
235level3.blackholes.us
226flowgoaway.com
209spamguard.leadmon.net (union of all results)
195brazil.blackholes.us
190spamguard.leadmon.net (result 127.0.0.2 = dialup)
185relays.osirusoft.com (result 127.0.0.9 = open proxy)
172verio.blackholes.us
172socks.relays.osirusoft.com
171mail-abuse.blacklist.jippg.org
169taiwan.blackholes.us
163dun.dnsrbl.net
157spamsources.relays.osirusoft.com (union of all results)
150relays.bl.kundenserver.de
146rr.blackholes.us
146spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
130dynablock.wirehub.net (result 127.0.0.2 = dialup)
130dynablock.wirehub.net (union of all results)
129blackholes.uceb.org (result 127.0.0.3 = spam source)
129dnsbl.njabl.org (result 127.0.0.3 = dialup)
129bl.deadbeef.com
1213y.spam.mrs.kithrup.com
112dialups.visi.com
103internap.blackholes.us
103dialups.relays.osirusoft.com (union of all results)
102dnsbl.sorbs.net (result 127.0.0.6 = spam source)
98no-more-funn.moensted.dk (result 127.0.0.9 = misc)
98orbs.dorkslayers.com
97dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
90japan.blackholes.us
88blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
87xo.blackholes.us
85argentina.blackholes.us
82relays.osirusoft.com (result 127.0.0.3 = dialup)
82no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
80blackhole.compu.net
75dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
72rackspace.blackholes.us
66blackholes.uceb.org (result 127.0.0.2 = relay)
63bl.deadbeef.com
61hongkong.blackholes.us
59blackholes.brainerd.net
58tr.countries.nerd.dk
50blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
48russia.blackholes.us
48interbusiness.blackholes.us
44inflow.blackholes.us
42vox.schpider.com
39relays.ordb.org
33blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
33spam.exsilia.net (union of all results)
29he.blackholes.us
29cybercon.blackholes.us
28eli.blackholes.us
28no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
27spam.exsilia.net (result 127.0.0.2 = spam source)
26wanadoo-fr.blackholes.us
26above.blackholes.us
25singapore.blackholes.us
24no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
18spammers.v6net.org
18nigeria.blackholes.us
18blackholes.uceb.org (result 127.0.0.4 = spam source network)
16proxies.relays.osirusoft.com
15spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
14telstra.blackholes.us
14relays.dorkslayers.com
14ph.rbl.cluecentral.net
13yipes.blackholes.us
13blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
12malaysia.blackholes.us
11valuenet.blackholes.us
11epoch.blackholes.us
11dialup.blacklist.jippg.org (union of all results)
10covad.blackholes.us
10dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
9spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
7thailand.blackholes.us
7pajo.blackholes.us
7broadwing.blackholes.us
7dev.null.dk
6affinity.blackholes.us
6dialups.relays.osirusoft.com (result 127.0.0.4 = no reverse DNS)
6blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
6spam.exsilia.net (result 127.0.0.3 = virus source)
4spamguard.leadmon.net (result 127.0.0.3 = spam source)
3valueweb.blackholes.us
3dnsbl.sorbs.net (result 127.0.0.5 = open relay)
3spamsources.relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
3spamsites.relays.osirusoft.com (result 127.0.0.6)
3blackholes.five-ten-sg.com (result 127.0.0.6 = relay)
3spamsites.relays.osirusoft.com (union of all results)
2skynetweb.blackholes.us
2relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
2dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)
2no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
1dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
1dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
1no-more-funn.moensted.dk (result 127.0.0.11 = repeated probes)
1proxies.exsilia.net

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
11472(total number of IP addresses whose names were tested, including 469 at SDSC)
2700(union of all domain zones)
2357abuse.rfc-ignorant.org
607whois.rfc-ignorant.org (union of all results)
352whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
255whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
11dsn.rfc-ignorant.org (zone not intended for this use)
7postmaster.rfc-ignorant.org


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
7250(total number of domains tested, including 240 at SDSC)
1246(union of all domain zones)
637abuse.rfc-ignorant.org
420whois.rfc-ignorant.org (union of all results)
332postmaster.rfc-ignorant.org
310whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
247dsn.rfc-ignorant.org
110whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
30ex.dnsbl.org (union of all results)
28ex.dnsbl.org (result 127.0.0.2 = spamsites)
23bl.deadbeef.com
8bandwidth-pigs.monkeys.com
4in.dnsbl.org (union of all results)
3in.dnsbl.org (result 127.0.0.6 = unconfirmed opt-in)
2ex.dnsbl.org (result 127.0.0.3 = spam source)
1in.dnsbl.org (result 127.0.0.2 = spam source)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 22 April 2003.