Blacklists Compared

15 January 2005

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
36039(total number of IP addresses tested, including 422 at SDSC)
31169(union of most IP zones)
25876t1.dnsbl.net.au
22700blackholes.five-ten-sg.com (union of all results)
21872blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
18037dnsbl.sorbs.net (union of all results)
14525sbl-xbl.spamhaus.org (union of all results)
13814cn-kr.blackholes.us (union of all results)
13553no-more-funn.moensted.dk (union of all results)
13427xbl.spamhaus.org (union of all results)
12669cbl.abuseat.org
12621xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
12617sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
12445dnsbl.sorbs.net (result 127.0.0.10 = dialup)
11061cn-kr.blackholes.us (result 127.0.0.3 = Korea)
11061korea.blackholes.us
11053korea.services.net
10566dynablock.njabl.org
10227no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
10084unconfirmed.dsbl.org
9965list.dsbl.org
9951dsbl.dnsbl.net.au
8321combined-hib.dnsiplists.completewhois.com (union of all results)
8304combined-hib.dnsiplists.completewhois.com (result 127.0.0.4 = bad whois data)
8226rmst.dnsbl.net.au
7376sbl.csma.biz
4907psbl.surriel.com
4863bl.csma.biz
3970dnsbl.njabl.org (union of all results)
3862bl.spamcop.net
3828blacklist.spambag.org
3505dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
3369wpbl.dnsbl.net.au
2862dnsbl.njabl.org (result 127.0.0.9 = open proxy)
2753cn-kr.blackholes.us (result 127.0.0.2 = China)
2753china.blackholes.us
2678dnsbl.ahbl.org (union of all results)
2621spamsources.fabel.dk
2607ricn.dnsbl.net.au
2390l2.spews.dnsbl.sorbs.net
2384opm.blitzed.org
2367xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
2366sbl-xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
2130spews.dnsbl.net.au
2118dnsbl.sorbs.net (result 127.0.0.6 = spam source)
2022l1.spews.dnsbl.sorbs.net
1949pdl.blackholes.us
1897block.blars.org
1875dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
1676spam.wytnij.to
1557no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1448dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1402dnsbl.regedit64.net
1270sbl.spamhaus.org
1250sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1176dnsbl.rangers.eu.org (union of all results)
1169unsure.nether.net
1125dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
1083probes.dnsbl.net.au
1020bl.spamcannibal.org
974no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
960dnsbl.rangers.eu.org (result 127.0.0.2 = dialup)
890dnsbl.antispam.or.id
863dnsbl.njabl.org (result 127.0.0.3 = dialup)
772work.drbl.croco.net
760dnsbl.ahbl.org (result 127.0.0.4 = spam source)
729brazil.blackholes.us
586no-more-funn.moensted.dk (result 127.0.0.9 = misc)
543ybl.megacity.org
535level3.blackholes.us
489blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
471japan.blackholes.us
441taiwan.blackholes.us
378comcast.blackholes.us
342rr.blackholes.us
284cw.blackholes.us
267charter.blackholes.us
256interbusiness.blackholes.us
230mexico.blackholes.us
227russia.blackholes.us
225no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
225blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
201blackholes.intersil.net
200argentina.blackholes.us
196mail-abuse.blacklist.jippg.org
177qwest.blackholes.us
161turkey.blackholes.us
157hongkong.blackholes.us
156dnsbl.njabl.org (result 127.0.0.4 = spam source)
154wanadoo-fr.blackholes.us
148ohps.dnsbl.net.au
141tr.countries.nerd.dk
134query.bondedsender.org (not a blacklist!)
127malaysia.blackholes.us
123xo.blackholes.us
122verio.blackholes.us
122dnsbl.rangers.eu.org (result 127.0.0.16 = spam haven)
108dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
108dialup.blacklist.jippg.org (union of all results)
105dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
102multihop.dsbl.org
99dnsbl.njabl.org (result 127.0.0.2 = source or relay)
95relays.ordb.org
88internap.blackholes.us
88flowgoaway.com
86singapore.blackholes.us
74above.blackholes.us
74dnsbl.rangers.eu.org (result 127.0.0.8 = spam source)
73cybercon.blackholes.us
66bellsouth.blackholes.us
65thailand.blackholes.us
63blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
59nigeria.blackholes.us
52osps.dnsbl.net.au
47rogers.blackholes.us
44inflow.blackholes.us
42dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
40telstra.blackholes.us
39ph.rbl.cluecentral.net
37he.blackholes.us
36covad.blackholes.us
35relays.nether.net
30dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
29osrs.dnsbl.net.au
29blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
28a2000.blackholes.us
27blackholes.uceb.org (union of all results)
26eli.blackholes.us
25rdts.dnsbl.net.au
23dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
19dnsbl.rangers.eu.org (result 127.0.0.4 = virus notices)
18blackholes.uceb.org (result 127.0.0.3 = spam source)
17combined-hib.dnsiplists.completewhois.com (result 127.0.0.2 = unallocated IP address)
16yipes.blackholes.us
16dnsbl.sorbs.net (result 127.0.0.5 = open relay)
16blackholes.brainerd.net
16exemptions.ahbl.org (not a blacklist!)
15swbell.blackholes.us
13rackspace.blackholes.us
13blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
13satos.rbl.cluecentral.net
12dnsbl.ahbl.org (result 127.0.0.15 = open relay)
11broadwing.blackholes.us
10infolink.blackholes.us
10affinity.blackholes.us
10hil.habeas.com
9blackholes.uceb.org (result 127.0.0.2 = open relay)
9spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
9spamguard.leadmon.net (union of all results)
8navisite.blackholes.us
8maxim.blackholes.us
7epoch.blackholes.us
7bl.deadbeef.com
6olm.blackholes.us
6relaywatcher.n13mbl.com
5blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
4pajo.blackholes.us
4burst.blackholes.us
4omrs.dnsbl.net.au
3dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
3no-more-funn.moensted.dk (result 127.0.0.11 = repeated probes)
2blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1ciberlynx.blackholes.us
1dnsbl.rangers.eu.org (result 127.0.0.32 = worm source)
1owps.dnsbl.net.au
1spamsites.dnsbl.net.au
1dev.null.dk
1dnsbl.njabl.org (result 127.0.0.8 = open formmail.cgi)
1relays.bl.kundenserver.de
1no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
1no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
1blackholes.five-ten-sg.com (result 127.0.0.11 = TCPA violator)
1blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
1dnsbl.ahbl.org (result 127.0.0.14 = denial-of-service attacker)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
36039(total number of IP addresses whose names were tested, including 422 at SDSC)
13096(union of all domain zones)
9753abuse.rfc-ignorant.org
6992rddn.dnsbl.net.au
3391whois.rfc-ignorant.org (union of all results)
2803dynamic.rhs.mailpolice.com
2376whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
1432webmail.rhs.mailpolice.com
1017whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
409bulk.rhs.mailpolice.com
408rhsbl.ahbl.org
329adv.rhs.mailpolice.com
239bl.deadbeef.com
22postmaster.rfc-ignorant.org
17dsn.rfc-ignorant.org (zone not intended for this use)
6fraud.rhs.mailpolice.com
5porn.rhs.mailpolice.com
2cart00ney.surriel.com
1blackhole.securitysage.com


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
26690(total number of domains tested, including 305 at SDSC)
7758(union of all domain zones)
3266whois.rfc-ignorant.org (union of all results)
2797whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2382abuse.rfc-ignorant.org
1241postmaster.rfc-ignorant.org
970webmail.rhs.mailpolice.com
938dsn.rfc-ignorant.org
701rhsbl.ahbl.org
668bulk.rhs.mailpolice.com
469whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
373bogusmx.rfc-ignorant.org
255bl.deadbeef.com
221blackhole.securitysage.com
206adv.rhs.mailpolice.com
73rddn.dnsbl.net.au (zone not intended for this use)
65rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
65rhsbl.sorbs.net (union of all results)
60porn.rhs.mailpolice.com
43dynamic.rhs.mailpolice.com
17ex.dnsbl.org
3cart00ney.surriel.com
1fraud.rhs.mailpolice.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 28 January 2005.