Blacklists Compared

5 June 2004

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
26245(total number of IP addresses tested, including 390 at SDSC)
21291(union of most IP zones)
15235t1.dnsbl.net.au
13714block.blars.org
12904blackholes.five-ten-sg.com (union of all results)
12177blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
11447sbl-xbl.spamhaus.org (union of all results)
11135dnsbl.sorbs.net (union of all results)
9644xbl.spamhaus.org (union of all results)
9619cbl.abuseat.org
9612xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
9612sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
7641dynablock.njabl.org
7256dnsbl.sorbs.net (result 127.0.0.10 = dialup)
7206unconfirmed.dsbl.org
7079dsbl.dnsbl.net.au
7079list.dsbl.org
6494no-more-funn.moensted.dk (union of all results)
4707cn-kr.blackholes.us (union of all results)
4516sbl.csma.biz
4453psbl.surriel.com
4013dnsbl.njabl.org (union of all results)
3536ipwhois.rfc-ignorant.org
3391bl.spamcop.net
3314l2.spews.dnsbl.sorbs.net
3039dnsbl.ahbl.org (union of all results)
3034wpbl.dnsbl.net.au
2940no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
2846spews.dnsbl.net.au
2842l1.spews.dnsbl.sorbs.net
2493rmst.dnsbl.net.au
2378cn-kr.blackholes.us (result 127.0.0.2 = China)
2378china.blackholes.us
2348dnsbl.njabl.org (result 127.0.0.9 = open proxy)
2329cn-kr.blackholes.us (result 127.0.0.3 = Korea)
2329korea.blackholes.us
2169korea.services.net
2141bl.csma.biz
2064blacklist.spambag.org
1961sbl.spamhaus.org
1960sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1826pdl.blackholes.us
1807no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1772dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1742dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
1483dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
1429spam.wytnij.to
1395spamsources.fabel.dk
1280dnsbl.ahbl.org (result 127.0.0.4 = spam source)
1140dnsbl.njabl.org (result 127.0.0.3 = dialup)
1049xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
1049sbl-xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
1048opm.blitzed.org
1046dnsbl.sorbs.net (result 127.0.0.6 = spam source)
986comcast.blackholes.us
964ricn.dnsbl.net.au
831dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
831no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
809sbbl.they.com
722relays.visi.com
712no-more-funn.moensted.dk (result 127.0.0.9 = misc)
648probes.dnsbl.net.au
635dun.dnsrbl.net
619ybl.megacity.org
609unsure.nether.net
578spamguard.leadmon.net (union of all results)
574brazil.blackholes.us
571spamguard.leadmon.net (result 127.0.0.2 = dialup)
536work.drbl.croco.net
516level3.blackholes.us
506cw.blackholes.us
433taiwan.blackholes.us
428blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
424rr.blackholes.us
422japan.blackholes.us
349rbl.rangers.eu.org (union of all results)
335dnsbl.njabl.org (result 127.0.0.4 = spam source)
273blackholes.intersil.net
268charter.blackholes.us
258dnsbl.antispam.or.id
255mexico.blackholes.us
236russia.blackholes.us
232no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
224blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
206dnsbl.njabl.org (result 127.0.0.2 = source or relay)
204turkey.blackholes.us
204tr.countries.nerd.dk
184rbl.rangers.eu.org (result 127.0.0.4 = dialup)
183infolink.blackholes.us
180wanadoo-fr.blackholes.us
172relays.ordb.org
167ohps.dnsbl.net.au
166qwest.blackholes.us
157hongkong.blackholes.us
154osps.dnsbl.net.au
1503y.spam.mrs.kithrup.com
141argentina.blackholes.us
141flowgoaway.com
139verio.blackholes.us
138interbusiness.blackholes.us
137dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
134singapore.blackholes.us
116spamsources.yamta.org (result 127.0.0.2 = spam source)
114multihop.dsbl.org
102yipes.blackholes.us
99malaysia.blackholes.us
97dialup.blacklist.jippg.org (union of all results)
96dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
90xo.blackholes.us
84dnsbl.sorbs.net (result 127.0.0.5 = open relay)
74rbl.rangers.eu.org (result 127.0.0.3 = spam haven)
69ph.rbl.cluecentral.net
67mail-abuse.blacklist.jippg.org
62bellsouth.blackholes.us
62above.blackholes.us
62relays.nether.net
60osrs.dnsbl.net.au
59internap.blackholes.us
59he.blackholes.us
56rbl.rangers.eu.org (result 127.0.0.2 = spam source)
55hil.habeas.com
52telstra.blackholes.us
45dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
41thailand.blackholes.us
41inflow.blackholes.us
41rdts.dnsbl.net.au
37swbell.blackholes.us
35cybercon.blackholes.us
35blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
33covad.blackholes.us
31nigeria.blackholes.us
30rogers.blackholes.us
26blackholes.uceb.org (union of all results)
21exemptions.ahbl.org (not a blacklist!)
19rackspace.blackholes.us
18eli.blackholes.us
18dnsbl.ahbl.org (result 127.0.0.15 = open relay)
17blackholes.uceb.org (result 127.0.0.2 = open relay)
16rbl.rangers.eu.org (result 127.0.0.10 = virus notices)
16blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
16blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
16query.bondedsender.org (not a blacklist!)
15rbl.rangers.eu.org (result 127.0.0.1 = misc)
14affinity.blackholes.us
12olm.blackholes.us
12broadwing.blackholes.us
12satos.rbl.cluecentral.net
10a2000.blackholes.us
10bl.deadbeef.com
10dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
9blackholes.brainerd.net
9dnsbl.ahbl.org (result 127.0.0.11 = no postmaster or abuse e-mail)
8blackholes.uceb.org (result 127.0.0.3 = spam source)
7blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
6spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
5burst.blackholes.us
5relays.bl.kundenserver.de
4pajo.blackholes.us
4navisite.blackholes.us
4epoch.blackholes.us
4owps.dnsbl.net.au
4no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
3maxim.blackholes.us
3rbl.rangers.eu.org (result 127.0.0.5 = relay output)
3omrs.dnsbl.net.au
2ciberlynx.blackholes.us
2dev.null.dk
2no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
2spam.dnsrbl.net
2dnsbl.ahbl.org (result 127.0.0.14 = denial-of-service attacker)
1blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
1rbl.rangers.eu.org (result 127.0.0.9 = worm source)
1spamsites.dnsbl.net.au
1dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)
1spamguard.leadmon.net (result 127.0.0.3 = spam source)
1dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
1no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
1blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
26245(total number of IP addresses whose names were tested, including 390 at SDSC)
11816(union of all domain zones)
8537abuse.rfc-ignorant.org
6604rddn.dnsbl.net.au
3759whois.rfc-ignorant.org (union of all results)
2540whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
1219whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
973bulk.rhs.mailpolice.com
569rhsbl.ahbl.org
269blackhole.securitysage.com
204bl.deadbeef.com
39porn.rhs.mailpolice.com
21postmaster.rfc-ignorant.org
21dsn.rfc-ignorant.org (zone not intended for this use)
1bogusmx.rfc-ignorant.org


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
22104(total number of domains tested, including 263 at SDSC)
7096(union of all domain zones)
3166whois.rfc-ignorant.org (union of all results)
2729whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2273abuse.rfc-ignorant.org
1361bulk.rhs.mailpolice.com
968postmaster.rfc-ignorant.org
940rhsbl.ahbl.org
611dsn.rfc-ignorant.org
527blackhole.securitysage.com
437whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
281bogusmx.rfc-ignorant.org
173bl.deadbeef.com
60porn.rhs.mailpolice.com
55ex.dnsbl.org (union of all results)
54rddn.dnsbl.net.au (zone not intended for this use)
52ex.dnsbl.org (result 127.0.0.2 = spamsites)
38rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
38rhsbl.sorbs.net (union of all results)
3ex.dnsbl.org (result 127.0.0.3 = spam source)
2rhsbl.sorbs.net (result 127.0.0.12 = domain does not send mail)
2cart00ney.surriel.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 20 June 2004.