Blacklists Compared

19 June 2004

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
26393(total number of IP addresses tested, including 394 at SDSC)
20808(union of most IP zones)
15115t1.dnsbl.net.au
14156block.blars.org
12610blackholes.five-ten-sg.com (union of all results)
11873blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
11284sbl-xbl.spamhaus.org (union of all results)
10532dnsbl.sorbs.net (union of all results)
9886xbl.spamhaus.org (union of all results)
9877cbl.abuseat.org
9871sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
9870xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
7570dynablock.njabl.org
7168dnsbl.sorbs.net (result 127.0.0.10 = dialup)
6849unconfirmed.dsbl.org
6726list.dsbl.org
6725dsbl.dnsbl.net.au
6438no-more-funn.moensted.dk (union of all results)
4789cn-kr.blackholes.us (union of all results)
4051sbl.csma.biz
3575ipwhois.rfc-ignorant.org
3528dnsbl.njabl.org (union of all results)
3067no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
2891l2.spews.dnsbl.sorbs.net
2846bl.spamcop.net
2643dnsbl.ahbl.org (union of all results)
2520cn-kr.blackholes.us (result 127.0.0.3 = Korea)
2520korea.blackholes.us
2509l1.spews.dnsbl.sorbs.net
2508wpbl.dnsbl.net.au
2493spews.dnsbl.net.au
2471rmst.dnsbl.net.au
2426psbl.surriel.com
2351korea.services.net
2269cn-kr.blackholes.us (result 127.0.0.2 = China)
2269china.blackholes.us
1978blacklist.spambag.org
1874dnsbl.njabl.org (result 127.0.0.9 = open proxy)
1799pdl.blackholes.us
1755no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1578bl.csma.biz
1535sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1535sbl.spamhaus.org
1440dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
1418dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1377spamsources.fabel.dk
1187dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
1168spam.wytnij.to
1156dnsbl.njabl.org (result 127.0.0.3 = dialup)
1086dnsbl.ahbl.org (result 127.0.0.4 = spam source)
948dnsbl.sorbs.net (result 127.0.0.6 = spam source)
941ricn.dnsbl.net.au
817comcast.blackholes.us
733no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
728opm.blitzed.org
726xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
726sbl-xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
692dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
675work.drbl.croco.net
661brazil.blackholes.us
644no-more-funn.moensted.dk (result 127.0.0.9 = misc)
607spamguard.leadmon.net (union of all results)
602sbbl.they.com
593dun.dnsrbl.net
587probes.dnsbl.net.au
563spamguard.leadmon.net (result 127.0.0.2 = dialup)
558unsure.nether.net
538level3.blackholes.us
519cw.blackholes.us
512japan.blackholes.us
456taiwan.blackholes.us
441relays.visi.com
414blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
361rr.blackholes.us
320dnsbl.njabl.org (result 127.0.0.2 = source or relay)
299blackholes.intersil.net
292ybl.megacity.org
280relays.ordb.org
271no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
259dnsbl.antispam.or.id
235blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
221charter.blackholes.us
221rbl.rangers.eu.org (union of all results)
210russia.blackholes.us
206qwest.blackholes.us
201mexico.blackholes.us
196turkey.blackholes.us
196tr.countries.nerd.dk
186dnsbl.njabl.org (result 127.0.0.4 = spam source)
177wanadoo-fr.blackholes.us
168infolink.blackholes.us
163hongkong.blackholes.us
146verio.blackholes.us
144rbl.rangers.eu.org (result 127.0.0.4 = dialup)
1433y.spam.mrs.kithrup.com
141interbusiness.blackholes.us
133flowgoaway.com
132argentina.blackholes.us
128spamsources.yamta.org (result 127.0.0.2 = spam source)
126dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
120osps.dnsbl.net.au
116singapore.blackholes.us
116ohps.dnsbl.net.au
111dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
109multihop.dsbl.org
100osrs.dnsbl.net.au
98dnsbl.sorbs.net (result 127.0.0.5 = open relay)
96dialup.blacklist.jippg.org (union of all results)
95xo.blackholes.us
94dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
85malaysia.blackholes.us
75relays.nether.net
72internap.blackholes.us
67he.blackholes.us
64thailand.blackholes.us
61mail-abuse.blacklist.jippg.org
59bellsouth.blackholes.us
49hil.habeas.com
48inflow.blackholes.us
46above.blackholes.us
45ph.rbl.cluecentral.net
44telstra.blackholes.us
44spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
38rbl.rangers.eu.org (result 127.0.0.2 = spam source)
37cybercon.blackholes.us
37covad.blackholes.us
36dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
36blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
36blackholes.brainerd.net
31broadwing.blackholes.us
30swbell.blackholes.us
30rogers.blackholes.us
29blackholes.uceb.org (union of all results)
28yipes.blackholes.us
28rdts.dnsbl.net.au
23rackspace.blackholes.us
23nigeria.blackholes.us
23eli.blackholes.us
23blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
22a2000.blackholes.us
20blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
19query.bondedsender.org (not a blacklist!)
18rbl.rangers.eu.org (result 127.0.0.1 = misc)
16rbl.rangers.eu.org (result 127.0.0.10 = virus notices)
16exemptions.ahbl.org (not a blacklist!)
14blackholes.uceb.org (result 127.0.0.2 = open relay)
14satos.rbl.cluecentral.net
13blackholes.uceb.org (result 127.0.0.3 = spam source)
12affinity.blackholes.us
12dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
10olm.blackholes.us
8pajo.blackholes.us
8bl.deadbeef.com
7navisite.blackholes.us
7epoch.blackholes.us
7blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
6dnsbl.ahbl.org (result 127.0.0.11 = no postmaster or abuse e-mail)
5maxim.blackholes.us
5spam.dnsrbl.net
5dnsbl.ahbl.org (result 127.0.0.15 = open relay)
4burst.blackholes.us
4no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
3owps.dnsbl.net.au
3dnsbl.ahbl.org (result 127.0.0.14 = denial-of-service attacker)
2ciberlynx.blackholes.us
2rbl.rangers.eu.org (result 127.0.0.5 = relay output)
2rbl.rangers.eu.org (result 127.0.0.3 = spam haven)
2omrs.dnsbl.net.au
2relays.bl.kundenserver.de
2dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
1blackholes.uceb.org (result 127.0.0.4 = spam source network)
1blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
1rbl.rangers.eu.org (result 127.0.0.9 = worm source)
1spamsites.dnsbl.net.au
1dev.null.dk
1no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
1dnsbl.ahbl.org (result 127.0.0.18 = virus source)
1dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
26393(total number of IP addresses whose names were tested, including 394 at SDSC)
11945(union of all domain zones)
8694abuse.rfc-ignorant.org
6686rddn.dnsbl.net.au
3620whois.rfc-ignorant.org (union of all results)
2426whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
1194whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
881bulk.rhs.mailpolice.com
519rhsbl.ahbl.org
244bl.deadbeef.com
207blackhole.securitysage.com
29porn.rhs.mailpolice.com
19postmaster.rfc-ignorant.org
16dsn.rfc-ignorant.org (zone not intended for this use)
3bogusmx.rfc-ignorant.org


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
21592(total number of domains tested, including 279 at SDSC)
6587(union of all domain zones)
2813whois.rfc-ignorant.org (union of all results)
2373whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2276abuse.rfc-ignorant.org
1218bulk.rhs.mailpolice.com
931postmaster.rfc-ignorant.org
820rhsbl.ahbl.org
643dsn.rfc-ignorant.org
440whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
406blackhole.securitysage.com
289bogusmx.rfc-ignorant.org
158bl.deadbeef.com
64porn.rhs.mailpolice.com
52ex.dnsbl.org (union of all results)
45ex.dnsbl.org (result 127.0.0.2 = spamsites)
44rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
44rhsbl.sorbs.net (union of all results)
32rddn.dnsbl.net.au (zone not intended for this use)
7ex.dnsbl.org (result 127.0.0.3 = spam source)
1rhsbl.sorbs.net (result 127.0.0.12 = domain does not send mail)
1cart00ney.surriel.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 5 July 2004.