Blacklists Compared

12 July 2003

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx and block.blars.org zones zone because they are too aggressive to be widely useful, and the blocktest.relays.osirusoft.com and query.bondedsender.org zones are also excluded because they are not blacklists.

HitsDNS Zone
13119(total number of IP addresses tested, including 397 at SDSC)
9395(union of most IP zones)
7495xbl.selwerd.cx
5384t1.bl.reynolds.net.au
4184blackholes.easynet.nl
4147block.blars.org
4092blackholes.five-ten-sg.com (union of all results)
3997wpb.bl.reynolds.net.au
3632dnsbl.njabl.org (union of all results)
3598no-more-funn.moensted.dk (union of all results)
3594unconfirmed.dsbl.org
3470psbl.surriel.com
3341list.dsbl.org
3339dsbl.bl.reynolds.net.au
3114dnsbl.sorbs.net (union of all results)
3065blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
3057proxies.blackholes.easynet.nl
2618dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
2572dnsbl.njabl.org (result 127.0.0.9 = open proxy)
2450dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
2227proxies.relays.monkeys.com (union of all results)
2226proxies.relays.monkeys.com (result 127.0.0.2 = open proxy)
2115cn-kr.blackholes.us (union of all results)
2068no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
2059bl.spamcop.net
1811relays.osirusoft.com (union of all results)
1590blackhole.compu.net
1405ipwhois.rfc-ignorant.org
1079cn-kr.blackholes.us (result 127.0.0.2 = China)
1079china.blackholes.us
1071relays.osirusoft.com (result 127.0.0.9 = open proxy)
1069socks.relays.osirusoft.com
1036cn-kr.blackholes.us (result 127.0.0.3 = Korea)
1036korea.blackholes.us
1025korea.services.net
1024no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
953spews.bl.reynolds.net.au
933unsure.nether.net
815spamsources.fabel.dk
743blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
735sbl.spamhaus.org
723dynablock.easynet.nl (result 127.0.0.2 = dialup)
723wdl.bl.reynolds.net.au
723dynablock.easynet.nl (union of all results)
714opm.blitzed.org
587pdl.bl.reynolds.net.au
548blocktest.relays.osirusoft.com (not a blacklist!)
541ybl.megacity.org
530cw.blackholes.us
501dnsbl.njabl.org (result 127.0.0.4 = spam source)
480blacklist.spambag.org
472blackholes.intersil.net
423spews.relays.osirusoft.com
422dnsbl.delink.net
405work.drbl.croco.net
391dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
388relays.osirusoft.com (result 127.0.0.4 = spam source)
377spam.wytnij.to
369relaywatcher.n13mbl.com
317spamhaus.relays.osirusoft.com
314dnsbl.njabl.org (result 127.0.0.2 = source or relay)
298spamguard.leadmon.net (union of all results)
283spamguard.leadmon.net (result 127.0.0.2 = dialup)
268brazil.blackholes.us
249dnsbl.njabl.org (result 127.0.0.3 = dialup)
247level3.blackholes.us
240relays.osirusoft.com (result 127.0.0.6 = spamsites)
229no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
227dialups.visi.com
215dnsbl.antispam.or.id
214multihop.dsbl.org
213blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
209taiwan.blackholes.us
199mail-abuse.blacklist.jippg.org
194comcast.blackholes.us
188lbl.lagengymnastik.dk
180inputs.relays.osirusoft.com
177relays.osirusoft.com (result 127.0.0.2 = open relay)
173dnsbl.sorbs.net (result 127.0.0.6 = spam source)
173relays.ordb.org
168rr.blackholes.us
168osrs.bl.reynolds.net.au
157sbbl.they.com
143japan.blackholes.us
142ohps.bl.reynolds.net.au
141verio.blackholes.us
140no-more-funn.moensted.dk (result 127.0.0.9 = misc)
1383y.spam.mrs.kithrup.com
134qwest.blackholes.us
122dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
122dialups.relays.osirusoft.com (union of all results)
121relays.bl.kundenserver.de
115query.bondedsender.org (not a blacklist!)
108blackholes.uceb.org (union of all results)
104osps.bl.reynolds.net.au
98relays.osirusoft.com (result 127.0.0.3 = dialup)
97no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
94russia.blackholes.us
94spamsources.relays.osirusoft.com (union of all results)
90relays.nether.net
86hongkong.blackholes.us
86charter.blackholes.us
85spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
84argentina.blackholes.us
78mexico.blackholes.us
76rmst.bl.reynolds.net.au
66xo.blackholes.us
63flowgoaway.com
62internap.blackholes.us
62blackholes.brainerd.net
61vox.schpider.com
54turkey.blackholes.us
51tr.countries.nerd.dk
50dun.dnsrbl.net
49rogers.blackholes.us
49blackholes.uceb.org (result 127.0.0.3 = spam source)
47dnsbl.sorbs.net (result 127.0.0.10 = dialup)
44bellsouth.blackholes.us
42infolink.blackholes.us
39inflow.blackholes.us
37blackholes.uceb.org (result 127.0.0.2 = open relay)
36interbusiness.blackholes.us
35he.blackholes.us
35bl.deadbeef.com
34proxy.relays.osirusoft.com
34blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
30wanadoo-fr.blackholes.us
30eli.blackholes.us
27singapore.blackholes.us
27malaysia.blackholes.us
26above.blackholes.us
26dialup.blacklist.jippg.org (union of all results)
25cybercon.blackholes.us
24dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
22nigeria.blackholes.us
22spam.exsilia.net (union of all results)
21rackspace.blackholes.us
21a2000.blackholes.us
21probes.bl.reynolds.net.au
20no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
20spam.exsilia.net (result 127.0.0.2 = spam source)
18covad.blackholes.us
17blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
16thailand.blackholes.us
16broadwing.blackholes.us
16spam.shri.net
15blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
15ph.rbl.cluecentral.net
14spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
14blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
12maxim.blackholes.us
10yipes.blackholes.us
10no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
9telstra.blackholes.us
9spamsources.relays.osirusoft.com (result 127.0.0.6 = spamhaus)
8owps.bl.reynolds.net.au
8no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
7pajo.blackholes.us
6dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
5olm.blackholes.us
5burst.blackholes.us
5affinity.blackholes.us
5blackholes.uceb.org (result 127.0.0.4 = spam source network)
5dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
5dev.null.dk
5blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
4omrs.bl.reynolds.net.au
3navisite.blackholes.us
3epoch.blackholes.us
3dnsbl.sorbs.net (result 127.0.0.5 = open relay)
2t3direct.bl.reynolds.net.au
2dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
2no-more-funn.moensted.dk (result 127.0.0.11 = repeated probes)
2blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
2spam.exsilia.net (result 127.0.0.3 = virus source)
1ciberlynx.blackholes.us
1spamsites.bl.reynolds.net.au
1owfs.bl.reynolds.net.au
1dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)
1proxies.relays.monkeys.com (result 127.0.0.3 = proxy output)
1spamguard.leadmon.net (result 127.0.0.3 = spam source)
1blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
1proxies.exsilia.net

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
13119(total number of IP addresses whose names were tested, including 397 at SDSC)
3912(union of all domain zones)
2662abuse.rfc-ignorant.org
1207rddn.bl.reynolds.net.au
828whois.rfc-ignorant.org (union of all results)
433whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
395whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
250bulk.rhs.mailpolice.com
105porn.rhs.mailpolice.com
98bl.deadbeef.com
31dsn.rfc-ignorant.org (zone not intended for this use)
14postmaster.rfc-ignorant.org


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
8123(total number of domains tested, including 197 at SDSC)
1658(union of all domain zones)
720abuse.rfc-ignorant.org
611whois.rfc-ignorant.org (union of all results)
502whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
410postmaster.rfc-ignorant.org
374dsn.rfc-ignorant.org
109whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
37ex.dnsbl.org (union of all results)
35ex.dnsbl.org (result 127.0.0.2 = spamsites)
34bl.deadbeef.com
24rddn.bl.reynolds.net.au (zone not intended for this use)
9bandwidth-pigs.monkeys.com
5in.dnsbl.org (union of all results)
4in.dnsbl.org (result 127.0.0.6 = unconfirmed opt-in)
2ex.dnsbl.org (result 127.0.0.3 = spam source)
1in.dnsbl.org (result 127.0.0.2 = spam source)


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 19 July 2003.