Blacklists Compared

23 August 2003

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the xbl.selwerd.cx and block.blars.org zones zone because they are too aggressive to be widely useful, and the blocktest.relays.osirusoft.com and query.bondedsender.org zones are also excluded because they are not blacklists.

HitsDNS Zone
14298(total number of IP addresses tested, including 425 at SDSC)
9176(union of most IP zones)
7512xbl.selwerd.cx
4015blackholes.five-ten-sg.com (union of all results)
3934block.blars.org
3862t1.bl.reynolds.net.au
3103dnsbl.sorbs.net (union of all results)
2943blackholes.easynet.nl
2943wpb.bl.reynolds.net.au
2937no-more-funn.moensted.dk (union of all results)
2933blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
2712dnsbl.njabl.org (union of all results)
2633psbl.surriel.com
2425unconfirmed.dsbl.org
2321cbl.abuseat.org
2123dsbl.bl.reynolds.net.au
2123list.dsbl.org
1865proxies.blackholes.easynet.nl
1613cn-kr.blackholes.us (union of all results)
1553dnsbl.njabl.org (result 127.0.0.9 = open proxy)
1527blackhole.compu.net
1519no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
1468dynablock.easynet.nl (result 127.0.0.2 = dialup)
1468dynablock.easynet.nl (union of all results)
1432dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1362bl.spamcop.net
1330dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
1186l2.spews.dnsbl.sorbs.net
1155proxies.relays.monkeys.com (result 127.0.0.2 = open proxy)
1155proxies.relays.monkeys.com (union of all results)
1003ipwhois.rfc-ignorant.org
898no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
886l1.spews.dnsbl.sorbs.net
858cn-kr.blackholes.us (result 127.0.0.2 = China)
858china.blackholes.us
851sbl.spamhaus.org
840unsure.nether.net
773blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
755cn-kr.blackholes.us (result 127.0.0.3 = Korea)
755korea.blackholes.us
751korea.services.net
665opm.blitzed.org
576relays.visi.com
570spews.bl.reynolds.net.au
563dnsbl.njabl.org (result 127.0.0.4 = spam source)
557pdl.bl.reynolds.net.au
536ybl.megacity.org
497blacklist.spambag.org
481blackholes.intersil.net
472cw.blackholes.us
411dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
391dnsbl.delink.net
356dialups.visi.com
331dnsbl.sorbs.net (result 127.0.0.10 = dialup)
318dnsbl.njabl.org (result 127.0.0.3 = dialup)
298spamguard.leadmon.net (union of all results)
293spam.wytnij.to
282dnsbl.njabl.org (result 127.0.0.2 = source or relay)
281spamguard.leadmon.net (result 127.0.0.2 = dialup)
281no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
277relaywatcher.n13mbl.com
267rr.blackholes.us
266multihop.dsbl.org
240level3.blackholes.us
235dnsbl.sorbs.net (result 127.0.0.6 = spam source)
234blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
227lbl.lagengymnastik.dk
214comcast.blackholes.us
213relays.osirusoft.com (union of all results)
205brazil.blackholes.us
185relays.ordb.org
182relays.osirusoft.com (result 127.0.0.4 = spam source)
180sbbl.they.com
171work.drbl.croco.net
167spews.relays.osirusoft.com
164taiwan.blackholes.us
162verio.blackholes.us
155spamsources.fabel.dk
150relays.bl.kundenserver.de
147qwest.blackholes.us
142osrs.bl.reynolds.net.au
142mail-abuse.blacklist.jippg.org
1413y.spam.mrs.kithrup.com
131internap.blackholes.us
128no-more-funn.moensted.dk (result 127.0.0.9 = misc)
120japan.blackholes.us
117query.bondedsender.org (not a blacklist!)
100charter.blackholes.us
95blackholes.brainerd.net
93rmst.bl.reynolds.net.au
91relays.nether.net
90dnsbl.antispam.or.id
86hongkong.blackholes.us
79xo.blackholes.us
78bellsouth.blackholes.us
76argentina.blackholes.us
75mexico.blackholes.us
74blackholes.uceb.org (union of all results)
69osps.bl.reynolds.net.au
69ohps.bl.reynolds.net.au
65russia.blackholes.us
63singapore.blackholes.us
59infolink.blackholes.us
57flowgoaway.com
53tr.countries.nerd.dk
53no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
52turkey.blackholes.us
49vox.schpider.com
48dev.null.dk
46rogers.blackholes.us
42he.blackholes.us
40dun.dnsrbl.net
40satos.rbl.cluecentral.net
37blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
36inflow.blackholes.us
35no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
34blackholes.uceb.org (result 127.0.0.3 = spam source)
34blackholes.uceb.org (result 127.0.0.2 = open relay)
34spam.shri.net
31rackspace.blackholes.us
30dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
30dialup.blacklist.jippg.org (union of all results)
29probes.bl.reynolds.net.au
28nigeria.blackholes.us
27malaysia.blackholes.us
26above.blackholes.us
24interbusiness.blackholes.us
24covad.blackholes.us
24spam.exsilia.net (union of all results)
23cybercon.blackholes.us
21eli.blackholes.us
21socks.relays.osirusoft.com
21relays.osirusoft.com (result 127.0.0.9 = open proxy)
21ph.rbl.cluecentral.net
20spam.exsilia.net (result 127.0.0.2 = spam source)
20bl.deadbeef.com
19broadwing.blackholes.us
17thailand.blackholes.us
17telstra.blackholes.us
17dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
17spamsources.relays.osirusoft.com (union of all results)
15yipes.blackholes.us
15spamsources.relays.osirusoft.com (result 127.0.0.4 = spam source)
15spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
15no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
15blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
12pajo.blackholes.us
12blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
11wanadoo-fr.blackholes.us
11maxim.blackholes.us
8affinity.blackholes.us
8a2000.blackholes.us
8owps.bl.reynolds.net.au
8no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
7burst.blackholes.us
7spamsites.bl.reynolds.net.au
6lauderdale.blackholes.us
6relays.osirusoft.com (result 127.0.0.2 = open relay)
6inputs.relays.osirusoft.com
5olm.blackholes.us
5navisite.blackholes.us
5blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
5blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
4epoch.blackholes.us
4blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
4spam.exsilia.net (result 127.0.0.3 = virus source)
3t3direct.bl.reynolds.net.au
3dialups.relays.osirusoft.com (result 127.0.0.3 = dialup)
3relays.osirusoft.com (result 127.0.0.3 = dialup)
3dialups.relays.osirusoft.com (union of all results)
2spamsources.relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
2relays.osirusoft.com (result 127.0.0.7 = unconfirmed opt-in)
2spamguard.leadmon.net (result 127.0.0.3 = spam source)
2blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
1ciberlynx.blackholes.us
1blackholes.uceb.org (result 127.0.0.4 = spam source network)
1dnsbl.sorbs.net (result 127.0.0.5 = open relay)
1dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
1omrs.bl.reynolds.net.au
1blocktest.relays.osirusoft.com (not a blacklist!)
1dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems. The blackhole.compu.net zone "is primarily for hosts which were not blocked by other blackhole sites and spammed compu.net."


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
14298(total number of IP addresses whose names were tested, including 425 at SDSC)
4924(union of all domain zones)
2628abuse.rfc-ignorant.org
1842rddn.bl.reynolds.net.au
873whois.rfc-ignorant.org (union of all results)
607endn.bl.reynolds.net.au
606spamdomains.blackholes.easynet.nl
553bulk.rhs.mailpolice.com
501whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
372whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
109bl.deadbeef.com
89porn.rhs.mailpolice.com
33dsn.rfc-ignorant.org (zone not intended for this use)
19postmaster.rfc-ignorant.org


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
15273(total number of domains tested, including 231 at SDSC)
3864(union of all domain zones)
1269whois.rfc-ignorant.org (union of all results)
1139abuse.rfc-ignorant.org
1063whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
926bulk.rhs.mailpolice.com
880endn.bl.reynolds.net.au
828spamdomains.blackholes.easynet.nl
498postmaster.rfc-ignorant.org
434dsn.rfc-ignorant.org
206whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
108bl.deadbeef.com
105porn.rhs.mailpolice.com
25rddn.bl.reynolds.net.au (zone not intended for this use)
10bandwidth-pigs.monkeys.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 31 August 2003.