Blacklists Compared

2 July 2005

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
40824(total number of IP addresses tested, including 409 at SDSC)
35242(union of most IP zones)
29605block.blars.org
23694t1.dnsbl.net.au
16850dnsbl.sorbs.net (union of all results)
15794sbl-xbl.spamhaus.org (union of all results)
13914xbl.spamhaus.org (union of all results)
12508sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
12506xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
12503cbl.abuseat.org
12297cn-kr.blackholes.us (union of all results)
11889dnsbl.sorbs.net (result 127.0.0.10 = dialup)
10519rmst.dnsbl.net.au
9831dynablock.njabl.org
9638no-more-funn.moensted.dk (union of all results)
9439unconfirmed.dsbl.org
9380list.dsbl.org
9375dsbl.dnsbl.net.au
9244blackholes.five-ten-sg.com (union of all results)
8867blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
6524sbl.csma.biz
6271korea.services.net
6243cn-kr.blackholes.us (result 127.0.0.3 = Korea)
6243korea.blackholes.us
6054cn-kr.blackholes.us (result 127.0.0.2 = China)
6054china.blackholes.us
5738combined-hib.dnsiplists.completewhois.com (union of all results)
5699combined-hib.dnsiplists.completewhois.com (result 127.0.0.4 = bad whois data)
5470no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
5150psbl.surriel.com
4644blacklist.spambag.org
4529bl.spamcop.net
3528l2.spews.dnsbl.sorbs.net
3320bl.csma.biz
3298dnsbl.njabl.org (union of all results)
3099l1.spews.dnsbl.sorbs.net
2969dnsbl.ahbl.org (union of all results)
2884spews.dnsbl.net.au
2717spamsources.fabel.dk
2502dnsbl.njabl.org (result 127.0.0.9 = open proxy)
2473dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
2433opm.blitzed.org
2425sbl-xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
2421xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
2292wpbl.dnsbl.net.au
2164ricn.dnsbl.net.au
1971sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1971sbl.spamhaus.org
1964dnsbl.rangers.eu.org (union of all results)
1905dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
1902dnsbl.regedit64.net
1833dnsbl.sorbs.net (result 127.0.0.6 = spam source)
1724dnsbl.rangers.eu.org (result 127.0.0.2 = dialup)
1715no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
1689no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1530dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1408brazil.blackholes.us
1319xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
1319sbl-xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
1179unsure.nether.net
1172pdl.blackholes.us
1155bl.spamcannibal.org
1016dnsbl.antispam.or.id
973dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
955spam.wytnij.to
953comcast.blackholes.us
923japan.blackholes.us
742taiwan.blackholes.us
640rr.blackholes.us
607no-more-funn.moensted.dk (result 127.0.0.9 = misc)
579probes.dnsbl.net.au
518dnsbl.njabl.org (result 127.0.0.3 = dialup)
486dnsbl.ahbl.org (result 127.0.0.4 = spam source)
478hongkong.blackholes.us
462argentina.blackholes.us
384charter.blackholes.us
368mci.blackholes.us
283mexico.blackholes.us
265tr.countries.nerd.dk
244cw.blackholes.us
208dnsbl.njabl.org (result 127.0.0.2 = open relay)
206blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
193query.bondedsender.org (not a blacklist!)
187blackholes.intersil.net
180turkey.blackholes.us
173thailand.blackholes.us
168mail-abuse.blacklist.jippg.org
165no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
160level3.blackholes.us
157qwest.blackholes.us
150dnsbl.rangers.eu.org (result 127.0.0.16 = spam haven)
124singapore.blackholes.us
115malaysia.blackholes.us
111ohps.dnsbl.net.au
110russia.blackholes.us
109verio.blackholes.us
108relays.ordb.org
107ybl.megacity.org
107blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
106dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
106dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
96flowgoaway.com
85internap.blackholes.us
79bellsouth.blackholes.us
79dnsbl.njabl.org (result 127.0.0.4 = spam source)
77multihop.dsbl.org
75xo.blackholes.us
74dnsbl.rangers.eu.org (result 127.0.0.8 = spam source)
68cybercon.blackholes.us
65osps.dnsbl.net.au
60above.blackholes.us
56wanadoo-fr.blackholes.us
50he.blackholes.us
50blackholes.brainerd.net
45broadwing.blackholes.us
36telstra.blackholes.us
36osrs.dnsbl.net.au
34rogers.blackholes.us
33a2000.blackholes.us
32inflow.blackholes.us
32covad.blackholes.us
32exemptions.ahbl.org (not a blacklist!)
29combined-hib.dnsiplists.completewhois.com (result 127.0.0.2 = unallocated IP address)
28interbusiness.blackholes.us
26relays.nether.net
24blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
22blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
21eli.blackholes.us
20spamguard.leadmon.net (union of all results)
18spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
17rdts.dnsbl.net.au
16infolink.blackholes.us
16dnsbl.sorbs.net (result 127.0.0.5 = open relay)
14dnsbl.rangers.eu.org (result 127.0.0.4 = virus notices)
14blackholes.uceb.org (union of all results)
13swbell.blackholes.us
13rackspace.blackholes.us
12yipes.blackholes.us
10lauderdale.blackholes.us
10combined-hib.dnsiplists.completewhois.com (result 127.0.0.3 = hijacked network)
9hil.habeas.com
8nigeria.blackholes.us
8maxim.blackholes.us
8blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
8dialup.blacklist.jippg.org (union of all results)
7olm.blackholes.us
7navisite.blackholes.us
7epoch.blackholes.us
7blackholes.uceb.org (result 127.0.0.2 = open relay)
7dnsbl.ahbl.org (result 127.0.0.15 = open relay)
7dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
6pajo.blackholes.us
6dialup.blacklist.jippg.org (result 127.0.0.4 = dialup in Japan)
5affinity.blackholes.us
5owps.dnsbl.net.au
4blackholes.uceb.org (result 127.0.0.3 = spam source)
4dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
4blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
3burst.blackholes.us
3blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
3blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
2blackholes.uceb.org (result 127.0.0.6 = spam haven)
2dnsbl.rangers.eu.org (result 127.0.0.32 = worm source)
2spamguard.leadmon.net (result 127.0.0.3 = spam source)
2dialup.blacklist.jippg.org (result 127.0.0.3 = dialup outside Japan)
1blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
1spamsites.dnsbl.net.au
1omrs.dnsbl.net.au
1owfs.dnsbl.net.au
1no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
1bl.deadbeef.com

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
40824(total number of IP addresses whose names were tested, including 409 at SDSC)
18334(union of all domain zones)
14309abuse.rfc-ignorant.org
8599rddn.dnsbl.net.au
8546whois.rfc-ignorant.org (union of all results)
6854whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
4798dynamic.rhs.mailpolice.com
1693whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
1402webmail.rhs.mailpolice.com
859rhsbl.ahbl.org
589bulk.rhs.mailpolice.com
463bl.deadbeef.com
340adv.rhs.mailpolice.com
86postmaster.rfc-ignorant.org
28dsn.rfc-ignorant.org (zone not intended for this use)
6bogusmx.rfc-ignorant.org
6porn.rhs.mailpolice.com
4blackhole.securitysage.com


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
25996(total number of domains tested, including 354 at SDSC)
7032(union of all domain zones)
2862whois.rfc-ignorant.org (union of all results)
2296whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2215abuse.rfc-ignorant.org
1261webmail.rhs.mailpolice.com
1212postmaster.rfc-ignorant.org
932rhsbl.ahbl.org
895dsn.rfc-ignorant.org
566whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
489bogusmx.rfc-ignorant.org
472bulk.rhs.mailpolice.com
202blackhole.securitysage.com
186adv.rhs.mailpolice.com
175bl.deadbeef.com
88porn.rhs.mailpolice.com
51rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
51rhsbl.sorbs.net (union of all results)
43rddn.dnsbl.net.au (zone not intended for this use)
27dynamic.rhs.mailpolice.com
16ex.dnsbl.org
3cart00ney.surriel.com
2fraud.rhs.mailpolice.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 15 July 2005.