Blacklists Compared

31 January 2004

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
26279(total number of IP addresses tested, including 389 at SDSC)
18571(union of most IP zones)
11677t1.dnsbl.net.au
10922dnsbl.sorbs.net (union of all results)
10240block.blars.org
9186blackholes.five-ten-sg.com (union of all results)
8505sbl-xbl.spamhaus.org (union of all results)
7993unconfirmed.dsbl.org
7905blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
7757list.dsbl.org
7756dsbl.dnsbl.net.au
7134cbl.abuseat.org
7120xbl.spamhaus.org
7120sbl-xbl.spamhaus.org (result 127.0.0.4 = Spamhaus XBL)
7016dnsbl.sorbs.net (result 127.0.0.10 = dialup)
6901dynablock.njabl.org
5395dnsbl.njabl.org (union of all results)
4609no-more-funn.moensted.dk (union of all results)
4284sbl.csma.biz
4061bl.spamcop.net
3319dnsbl.njabl.org (result 127.0.0.9 = open proxy)
2936l2.spews.dnsbl.sorbs.net
2739cn-kr.blackholes.us (union of all results)
2623ipwhois.rfc-ignorant.org
2513l1.spews.dnsbl.sorbs.net
2513spews.dnsbl.net.au
2508dnsbl.ahbl.org (union of all results)
2395spam.wytnij.to
2374dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
2300unsure.nether.net
2116dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
2109no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
2088dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
1948bl.csma.biz
1894no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1725psbl.surriel.com
1590sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1590sbl.spamhaus.org
1372cn-kr.blackholes.us (result 127.0.0.2 = China)
1372china.blackholes.us
1367cn-kr.blackholes.us (result 127.0.0.3 = Korea)
1367korea.blackholes.us
1334korea.services.net
1262dnsbl.njabl.org (result 127.0.0.3 = dialup)
978rmst.dnsbl.net.au
956blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
939comcast.blackholes.us
810spamsources.fabel.dk
746ybl.megacity.org
715dnsbl.sorbs.net (result 127.0.0.6 = spam source)
676wpbl.dnsbl.net.au
662opm.blitzed.org
641spamguard.leadmon.net (union of all results)
624spamguard.leadmon.net (result 127.0.0.2 = dialup)
577probes.dnsbl.net.au
570cw.blackholes.us
551relays.visi.com
546dnsbl.njabl.org (result 127.0.0.4 = spam source)
493hil.habeas.com
467brazil.blackholes.us
467blacklist.spambag.org
464level3.blackholes.us
447rr.blackholes.us
444pss.spambusters.org.ar
419dnsbl.ahbl.org (result 127.0.0.4 = spam source)
412work.drbl.croco.net
379blackholes.intersil.net
324taiwan.blackholes.us
318japan.blackholes.us
309no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
278dnsbl.njabl.org (result 127.0.0.2 = source or relay)
270no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
248wanadoo-fr.blackholes.us
237dnsbl.antispam.or.id
229blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
219charter.blackholes.us
216multihop.dsbl.org
207relays.ordb.org
203bellsouth.blackholes.us
200relaywatcher.n13mbl.com
200ricn.dnsbl.net.au
196qwest.blackholes.us
195dialup.blacklist.jippg.org (union of all results)
192verio.blackholes.us
192dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
189russia.blackholes.us
172mexico.blackholes.us
168infolink.blackholes.us
152mail-abuse.blacklist.jippg.org
148interbusiness.blackholes.us
142xo.blackholes.us
130dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
129internap.blackholes.us
124osrs.dnsbl.net.au
120hongkong.blackholes.us
119singapore.blackholes.us
104relays.nether.net
102dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
98tr.countries.nerd.dk
97turkey.blackholes.us
95osps.dnsbl.net.au
933y.spam.mrs.kithrup.com
91above.blackholes.us
88dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
88dun.dnsrbl.net
85query.bondedsender.org (not a blacklist!)
84sbbl.they.com
83argentina.blackholes.us
78telstra.blackholes.us
78flowgoaway.com
74dnsbl.sorbs.net (result 127.0.0.5 = open relay)
73ohps.dnsbl.net.au
66yipes.blackholes.us
65he.blackholes.us
61rogers.blackholes.us
58relays.bl.kundenserver.de
57inflow.blackholes.us
55rdts.dnsbl.net.au
53ph.rbl.cluecentral.net
50no-more-funn.moensted.dk (result 127.0.0.9 = misc)
49a2000.blackholes.us
41exemptions.ahbl.org (not a blacklist!)
40malaysia.blackholes.us
40spam.exsilia.net (union of all results)
38blackholes.uceb.org (union of all results)
37nigeria.blackholes.us
36blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
36blackholes.brainerd.net
35covad.blackholes.us
33rackspace.blackholes.us
31cybercon.blackholes.us
30swbell.blackholes.us
29eli.blackholes.us
28thailand.blackholes.us
28spam.exsilia.net (result 127.0.0.2 = spam source)
25blackholes.uceb.org (result 127.0.0.2 = open relay)
25blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
23satos.rbl.cluecentral.net
18maxim.blackholes.us
18broadwing.blackholes.us
17spamsources.yamta.org (result 127.0.0.2 = spam source)
17affinity.blackholes.us
15olm.blackholes.us
14blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
13pajo.blackholes.us
13spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
12no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
12blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
12spam.exsilia.net (result 127.0.0.3 = virus source)
11epoch.blackholes.us
10burst.blackholes.us
9no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
9bl.deadbeef.com
8blackholes.uceb.org (result 127.0.0.3 = spam source)
7blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
6omrs.dnsbl.net.au
5navisite.blackholes.us
5ciberlynx.blackholes.us
4owps.dnsbl.net.au
4spamguard.leadmon.net (result 127.0.0.3 = spam source)
3blackholes.uceb.org (result 127.0.0.4 = spam source network)
3owfs.dnsbl.net.au
3dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
2blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
2blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
1valuenet.blackholes.us
1dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)
1no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
1dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
26279(total number of IP addresses whose names were tested, including 389 at SDSC)
11879(union of all domain zones)
8222abuse.rfc-ignorant.org
6420rddn.dnsbl.net.au
2900whois.rfc-ignorant.org (union of all results)
1735whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
1165whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
639bulk.rhs.mailpolice.com
438blackhole.securitysage.com
269rhsbl.ahbl.org
206bl.deadbeef.com
63porn.rhs.mailpolice.com
18postmaster.rfc-ignorant.org
18dsn.rfc-ignorant.org (zone not intended for this use)
18bogusmx.rfc-ignorant.org


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
26306(total number of domains tested, including 241 at SDSC)
7000(union of all domain zones)
2903whois.rfc-ignorant.org (union of all results)
2475whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2110abuse.rfc-ignorant.org
1549bulk.rhs.mailpolice.com
924postmaster.rfc-ignorant.org
763dsn.rfc-ignorant.org
683blackhole.securitysage.com
643rhsbl.ahbl.org
428whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
195bogusmx.rfc-ignorant.org
126porn.rhs.mailpolice.com
125bl.deadbeef.com
41rddn.dnsbl.net.au (zone not intended for this use)
12rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
12rhsbl.sorbs.net (union of all results)
2rhsbl.sorbs.net (result 127.0.0.12 = domain does not send mail)
2cart00ney.surriel.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 15 February 2004.