Blacklists Compared

20 November 2004

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists.

HitsDNS Zone
33560(total number of IP addresses tested, including 469 at SDSC)
28038(union of most IP zones)
22256t1.dnsbl.net.au
19133blackholes.five-ten-sg.com (union of all results)
18282blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
15872dnsbl.sorbs.net (union of all results)
14161sbl-xbl.spamhaus.org (union of all results)
12796xbl.spamhaus.org (union of all results)
12739cbl.abuseat.org
12716sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
12715xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
10514dnsbl.sorbs.net (result 127.0.0.10 = dialup)
9545no-more-funn.moensted.dk (union of all results)
9541unconfirmed.dsbl.org
9430list.dsbl.org
9339dynablock.njabl.org
9312dsbl.dnsbl.net.au
9112cn-kr.blackholes.us (union of all results)
6674cn-kr.blackholes.us (result 127.0.0.3 = Korea)
6674korea.blackholes.us
6668korea.services.net
6425sbl.csma.biz
6150no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
5996rmst.dnsbl.net.au
5697combined-hib.dnsiplists.completewhois.com (union of all results)
5684combined-hib.dnsiplists.completewhois.com (result 127.0.0.4 = bad whois data)
4906psbl.surriel.com
4071dnsbl.njabl.org (union of all results)
3942bl.csma.biz
3905blacklist.spambag.org
3488bl.spamcop.net
3377dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
3016wpbl.dnsbl.net.au
2905l2.spews.dnsbl.sorbs.net
2730dnsbl.njabl.org (result 127.0.0.9 = open proxy)
2478spews.dnsbl.net.au
2438cn-kr.blackholes.us (result 127.0.0.2 = China)
2438china.blackholes.us
2424l1.spews.dnsbl.sorbs.net
2252ricn.dnsbl.net.au
2252spamsources.fabel.dk
2201dnsbl.ahbl.org (union of all results)
1952dnsbl.sorbs.net (result 127.0.0.6 = spam source)
1875no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1730pdl.blackholes.us
1612sbl.spamhaus.org
1596sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1429unsure.nether.net
1372dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
1151dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1135spam.wytnij.to
1098bl.spamcannibal.org
1052dnsbl.rangers.eu.org (union of all results)
1042work.drbl.croco.net
1039dnsbl.njabl.org (result 127.0.0.3 = dialup)
1029dnsbl.antispam.or.id
945brazil.blackholes.us
877dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
809dnsbl.rangers.eu.org (result 127.0.0.2 = dialup)
771dnsbl.ahbl.org (result 127.0.0.4 = spam source)
744no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
730sbl-xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
729xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
725opm.blitzed.org
703probes.dnsbl.net.au
652level3.blackholes.us
617japan.blackholes.us
561no-more-funn.moensted.dk (result 127.0.0.9 = misc)
536taiwan.blackholes.us
522blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
493comcast.blackholes.us
486ybl.megacity.org
346mexico.blackholes.us
334charter.blackholes.us
330rr.blackholes.us
305cw.blackholes.us
236no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
231blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
230russia.blackholes.us
227blackholes.intersil.net
221qwest.blackholes.us
217hongkong.blackholes.us
198argentina.blackholes.us
187interbusiness.blackholes.us
167wanadoo-fr.blackholes.us
166dnsbl.njabl.org (result 127.0.0.2 = source or relay)
151dnsbl.njabl.org (result 127.0.0.4 = spam source)
145dnsbl.rangers.eu.org (result 127.0.0.16 = spam haven)
143query.bondedsender.org (not a blacklist!)
126flowgoaway.com
125verio.blackholes.us
115xo.blackholes.us
113above.blackholes.us
113tr.countries.nerd.dk
112dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
111singapore.blackholes.us
100turkey.blackholes.us
100osps.dnsbl.net.au
97ohps.dnsbl.net.au
92multihop.dsbl.org
86relays.ordb.org
85internap.blackholes.us
80spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
80spamguard.leadmon.net (union of all results)
76dnsbl.rangers.eu.org (result 127.0.0.8 = spam source)
75relaywatcher.n13mbl.com
73yipes.blackholes.us
73dialup.blacklist.jippg.org (union of all results)
71malaysia.blackholes.us
71dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
69cybercon.blackholes.us
55dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
53thailand.blackholes.us
51dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
49bellsouth.blackholes.us
48osrs.dnsbl.net.au
47he.blackholes.us
47ph.rbl.cluecentral.net
46blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
42inflow.blackholes.us
41relays.nether.net
40mail-abuse.blacklist.jippg.org
38nigeria.blackholes.us
33telstra.blackholes.us
33blackholes.brainerd.net
32covad.blackholes.us
31rdts.dnsbl.net.au
30blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
27eli.blackholes.us
27blackholes.uceb.org (union of all results)
23rogers.blackholes.us
21infolink.blackholes.us
21dnsbl.rangers.eu.org (result 127.0.0.4 = virus notices)
20swbell.blackholes.us
19a2000.blackholes.us
18dnsbl.sorbs.net (result 127.0.0.5 = open relay)
18blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
17rackspace.blackholes.us
17blackholes.uceb.org (result 127.0.0.3 = spam source)
17exemptions.ahbl.org (not a blacklist!)
16epoch.blackholes.us
16broadwing.blackholes.us
14dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
13combined-hib.dnsiplists.completewhois.com (result 127.0.0.2 = unallocated IP address)
11navisite.blackholes.us
11maxim.blackholes.us
10hil.habeas.com
10satos.rbl.cluecentral.net
10dnsbl.ahbl.org (result 127.0.0.15 = open relay)
9affinity.blackholes.us
8burst.blackholes.us
5olm.blackholes.us
5blackholes.uceb.org (result 127.0.0.2 = open relay)
4pajo.blackholes.us
4blackholes.uceb.org (result 127.0.0.6 = spam haven)
4owps.dnsbl.net.au
4bl.deadbeef.com
3dnsbl.ahbl.org (result 127.0.0.14 = denial-of-service attacker)
2ciberlynx.blackholes.us
2dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)
2relays.bl.kundenserver.de
2dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
2blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1valuenet.blackholes.us
1blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
1dnsbl.rangers.eu.org (result 127.0.0.32 = worm source)
1omrs.dnsbl.net.au
1dev.null.dk
1no-more-funn.moensted.dk (result 127.0.0.8 = open web form)
1no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
1no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
1blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
1blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
1dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
33560(total number of IP addresses whose names were tested, including 469 at SDSC)
14191(union of all domain zones)
10272abuse.rfc-ignorant.org
7339rddn.dnsbl.net.au
5333dynamic.rhs.mailpolice.com
4259whois.rfc-ignorant.org (union of all results)
3295whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
1541webmail.rhs.mailpolice.com
964whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
562rhsbl.ahbl.org
539bulk.rhs.mailpolice.com
443adv.rhs.mailpolice.com
316bl.deadbeef.com
16postmaster.rfc-ignorant.org
14dsn.rfc-ignorant.org (zone not intended for this use)
7porn.rhs.mailpolice.com
2blackhole.securitysage.com
1bogusmx.rfc-ignorant.org


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
28364(total number of domains tested, including 345 at SDSC)
8665(union of all domain zones)
3449whois.rfc-ignorant.org (union of all results)
2980whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2509abuse.rfc-ignorant.org
1161postmaster.rfc-ignorant.org
1160bulk.rhs.mailpolice.com
1122webmail.rhs.mailpolice.com
1091rhsbl.ahbl.org
966dsn.rfc-ignorant.org
469whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
352blackhole.securitysage.com
337bogusmx.rfc-ignorant.org
256bl.deadbeef.com
226adv.rhs.mailpolice.com
76rddn.dnsbl.net.au (zone not intended for this use)
73porn.rhs.mailpolice.com
54rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
54rhsbl.sorbs.net (union of all results)
35dynamic.rhs.mailpolice.com
19ex.dnsbl.org
1cart00ney.surriel.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 2 December 2004.