Blacklists Compared

15 October 2005

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
49165(total number of IP addresses tested, including 483 at SDSC)
42519(union of most IP zones)
33905block.blars.org
26163dnsbl.sorbs.net (union of all results)
25572blackholes.five-ten-sg.com (union of all results)
25013t1.dnsbl.net.au
24584blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
20578sbl-xbl.spamhaus.org (union of all results)
19511xbl.spamhaus.org (union of all results)
18626xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
18624sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
18590cbl.abuseat.org
18183dnsbl.sorbs.net (result 127.0.0.10 = dialup)
12907psbl.surriel.com
12228dynablock.njabl.org
11540cn-kr.blackholes.us (result 127.0.0.2 = China)
11540cn-kr.blackholes.us (union of all results)
11195no-more-funn.moensted.dk (union of all results)
9222sbl.csma.biz
9213unconfirmed.dsbl.org
9142list.dsbl.org
9138dsbl.dnsbl.net.au
7577china.blackholes.us
5543bl.spamcop.net
5386combined-hib.dnsiplists.completewhois.com (union of all results)
5377combined-hib.dnsiplists.completewhois.com (result 127.0.0.4 = bad whois data)
4924dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
4851blacklist.spambag.org
4573bl.csma.biz
4466no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
3990no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
3963korea.blackholes.us
3947korea.services.net
3776l2.spews.dnsbl.sorbs.net
3726dnsbl.sorbs.net (result 127.0.0.6 = spam source)
3529dnsbl.rangers.eu.org (union of all results)
3462dnsbl.njabl.org (union of all results)
3325dnsbl.rangers.eu.org (result 127.0.0.2 = dialup)
3223rmst.dnsbl.net.au
3219l1.spews.dnsbl.sorbs.net
3218spews.dnsbl.net.au
2823dnsbl.ahbl.org (union of all results)
2781spamsources.fabel.dk
2639dnsbl.njabl.org (result 127.0.0.9 = open proxy)
2576wpbl.dnsbl.net.au
2522brazil.blackholes.us
2490ricn.dnsbl.net.au
2315dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
2201unsure.nether.net
2164dnsbl.regedit64.net
2027no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1667opm.blitzed.org
1666xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
1664sbl-xbl.spamhaus.org (result 127.0.0.6 = Blitzed Open Proxy Monitor List)
1533dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1394xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
1394sbl-xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
1299sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1299sbl.spamhaus.org
1056japan.blackholes.us
1000bl.spamcannibal.org
994dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
977spam.wytnij.to
878dnsbl.antispam.or.id
751russia.blackholes.us
720taiwan.blackholes.us
583mexico.blackholes.us
550probes.dnsbl.net.au
538dnsbl.njabl.org (result 127.0.0.3 = dialup)
531no-more-funn.moensted.dk (result 127.0.0.9 = misc)
526hongkong.blackholes.us
512tr.countries.nerd.dk
509turkey.blackholes.us
493dnsbl.ahbl.org (result 127.0.0.4 = spam source)
489blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
450argentina.blackholes.us
350blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
272malaysia.blackholes.us
221thailand.blackholes.us
205query.bondedsender.org (not a blacklist!)
189singapore.blackholes.us
185no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
157dnsbl.njabl.org (result 127.0.0.4 = spam source)
145dnsbl.njabl.org (result 127.0.0.2 = open relay)
145blackholes.intersil.net
132relays.ordb.org
130dnsbl.rangers.eu.org (result 127.0.0.16 = spam haven)
128dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
120mail-abuse.blacklist.jippg.org
109dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
80blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
76flowgoaway.com
69ohps.dnsbl.net.au
64dnsbl.rangers.eu.org (result 127.0.0.8 = spam source)
62multihop.dsbl.org
55blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
33exemptions.ahbl.org (not a blacklist!)
30osps.dnsbl.net.au
23relays.nether.net
19rdts.dnsbl.net.au
18blackholes.uceb.org (union of all results)
16osrs.dnsbl.net.au
15blackholes.brainerd.net
14hil.habeas.com
13blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
13dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
11dnsbl.sorbs.net (result 127.0.0.5 = open relay)
10spamguard.leadmon.net (union of all results)
9dnsbl.rangers.eu.org (result 127.0.0.4 = virus notices)
9spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
9combined-hib.dnsiplists.completewhois.com (result 127.0.0.2 = unallocated IP address)
6blackholes.uceb.org (result 127.0.0.2 = open relay)
6blackholes.uceb.org (result 127.0.0.6 = spam haven)
5blackholes.uceb.org (result 127.0.0.3 = spam source)
5tor.dnsbl.sectoor.de (result 127.0.0.2 = /24 contains a Tor server)
5tor.dnsbl.sectoor.de (union of all results)
3owps.dnsbl.net.au
3dnsbl.ahbl.org (result 127.0.0.15 = open relay)
2no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
2no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
2dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)
1blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
1dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
1dnsbl.rangers.eu.org (result 127.0.0.32 = worm source)
1spamsites.dnsbl.net.au
1omrs.dnsbl.net.au
1spamguard.leadmon.net (result 127.0.0.3 = spam source)
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1bl.deadbeef.com

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
49165(total number of IP addresses whose names were tested, including 483 at SDSC)
24437(union of all domain zones)
18263abuse.rfc-ignorant.org
14634rddn.dnsbl.net.au
11318whois.rfc-ignorant.org (union of all results)
9074whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
7285dynamic.rhs.mailpolice.com
2248whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2123webmail.rhs.mailpolice.com
983rhsbl.ahbl.org
452adv.rhs.mailpolice.com
412bl.deadbeef.com
343bulk.rhs.mailpolice.com
334postmaster.rfc-ignorant.org
196dsn.rfc-ignorant.org (zone not intended for this use)
191bogusmx.rfc-ignorant.org
2blackhole.securitysage.com
2porn.rhs.mailpolice.com


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
25714(total number of domains tested, including 430 at SDSC)
6744(union of all domain zones)
2729whois.rfc-ignorant.org (union of all results)
2342abuse.rfc-ignorant.org
2256whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
1220postmaster.rfc-ignorant.org
1048webmail.rhs.mailpolice.com
934rhsbl.ahbl.org
859dsn.rfc-ignorant.org
490bogusmx.rfc-ignorant.org
473whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
287bulk.rhs.mailpolice.com
214adv.rhs.mailpolice.com
157bl.deadbeef.com
140blackhole.securitysage.com
87porn.rhs.mailpolice.com
47rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
47rhsbl.sorbs.net (union of all results)
28rddn.dnsbl.net.au (zone not intended for this use)
14ex.dnsbl.org
10dynamic.rhs.mailpolice.com
1fraud.rhs.mailpolice.com
1cart00ney.surriel.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 29 October 2005.