Blacklists Compared

27 May 2006

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
79375(total number of IP addresses tested, including 505 at SDSC)
70234(union of most IP zones)
50694block.blars.org
41432dnsbl.sorbs.net (union of all results)
34472t1.dnsbl.net.au
33412blackholes.five-ten-sg.com (union of all results)
32680dnsbl.sorbs.net (result 127.0.0.10 = dialup)
32452blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
27332sbl-xbl.spamhaus.org (union of all results)
25977xbl.spamhaus.org (union of all results)
25631dynablock.njabl.org
24774cbl.abuseat.org
24756xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
24755sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
20979cn-kr.blackholes.us (result 127.0.0.2 = China)
20979cn-kr.blackholes.us (union of all results)
16141no-more-funn.moensted.dk (union of all results)
15822china.blackholes.us
14969sbl.csma.biz
11078unconfirmed.dsbl.org
10960list.dsbl.org
10958dsbl.dnsbl.net.au
9815bl.spamcop.net
9137blacklist.spambag.org
8779dnsbl-1.uceprotect.net
8747dnsbl-2.uceprotect.net
7386dnsbl.sorbs.net (result 127.0.0.6 = spam source)
7338combined-hib.dnsiplists.completewhois.com (union of all results)
7051bl.csma.biz
6099psbl.surriel.com
6098no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
6078no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
5794combined-hib.dnsiplists.completewhois.com (result 127.0.0.4 = bad whois data)
5583wpbl.dnsbl.net.au
5304korea.services.net
5159korea.blackholes.us
4817dnsbl.njabl.org (union of all results)
4146l2.spews.dnsbl.sorbs.net
3717unsure.nether.net
3630rmst.dnsbl.net.au
3620spamsources.fabel.dk
3473dnsbl.njabl.org (result 127.0.0.9 = open proxy)
3454no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
3376l1.spews.dnsbl.sorbs.net
3076dnsbl.sorbs.net (result 127.0.0.7 = open formmail.cgi)
3040dnsbl.ahbl.org (union of all results)
2616dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
2425ricn.dnsbl.net.au
2364brazil.blackholes.us
2227xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
2227sbl-xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
1746sbl.spamhaus.org
1737sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
1616combined-hib.dnsiplists.completewhois.com (result 127.0.0.2 = unallocated IP address)
1513dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1486japan.blackholes.us
1486dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
1411tr.countries.nerd.dk
1405turkey.blackholes.us
1339mail-abuse.blacklist.jippg.org
1182spews.dnsbl.net.au
1172taiwan.blackholes.us
1160bl.spamcannibal.org
1078dnsbl.njabl.org (result 127.0.0.3 = dialup)
843probes.dnsbl.net.au
810russia.blackholes.us
807dnsbl-3.uceprotect.net
775mexico.blackholes.us
732argentina.blackholes.us
608blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
488spam.wytnij.to
389dnsbl.ahbl.org (result 127.0.0.4 = spam source)
327malaysia.blackholes.us
322dnsbl.antispam.or.id
279thailand.blackholes.us
266hongkong.blackholes.us
259no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
252no-more-funn.moensted.dk (result 127.0.0.9 = misc)
172query.bondedsender.org (not a blacklist!)
161singapore.blackholes.us
160blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
156blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
149work.drbl.croco.net
144blackholes.intersil.net
138dnsbl.njabl.org (result 127.0.0.4 = spam source)
136dnsbl.njabl.org (result 127.0.0.2 = open relay)
118ohps.dnsbl.net.au
115dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
96multihop.dsbl.org
92relays.ordb.org
89dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
82flowgoaway.com
30osps.dnsbl.net.au
29blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
23dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
23tor.dnsbl.sectoor.de (union of all results)
22tor.dnsbl.sectoor.de (result 127.0.0.2 = /24 contains a Tor server)
19dnsbl.ahbl.org (result 127.0.0.15 = open relay)
18dnsbl.sorbs.net (result 127.0.0.5 = open relay)
18relays.nether.net
18blackholes.uceb.org (union of all results)
15rdts.dnsbl.net.au
14exemptions.ahbl.org (not a blacklist!)
12nigeria.blackholes.us
12spamguard.leadmon.net (union of all results)
10spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
9osrs.dnsbl.net.au
9hil.habeas.com
8dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)
7blackholes.uceb.org (result 127.0.0.3 = spam source)
7blackholes.uceb.org (result 127.0.0.2 = open relay)
5vox.schpider.com
5owps.dnsbl.net.au
5blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
5blackholes.brainerd.net
4blackholes.uceb.org (result 127.0.0.5 = dialup)
1tor.dnsbl.sectoor.de (result 127.0.0.1 = Tor server)
1dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
1spamguard.leadmon.net (result 127.0.0.3 = spam source)
1spamguard.leadmon.net (result 127.0.0.8 = open proxy)
1no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
1dnsbl.ahbl.org (result 127.0.0.18 = virus source)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
79375(total number of IP addresses whose names were tested, including 505 at SDSC)
41018(union of all domain zones)
30919abuse.rfc-ignorant.org
27079rddn.dnsbl.net.au
21333dynamic.rhs.mailpolice.com
19820whois.rfc-ignorant.org (union of all results)
15290whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
4532whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2586webmail.rhs.mailpolice.com
505adv.rhs.mailpolice.com
496rhsbl.ahbl.org
227postmaster.rfc-ignorant.org
94bogusmx.rfc-ignorant.org
85dsn.rfc-ignorant.org (zone not intended for this use)
79bulk.rhs.mailpolice.com
4porn.rhs.mailpolice.com
1cart00ney.surriel.com


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
45148(total number of domains tested, including 407 at SDSC)
9994(union of all domain zones)
4268whois.rfc-ignorant.org (union of all results)
3668whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
3239abuse.rfc-ignorant.org
1568webmail.rhs.mailpolice.com
1306rhsbl.ahbl.org
1271postmaster.rfc-ignorant.org
949dsn.rfc-ignorant.org
805bogusmx.rfc-ignorant.org
600whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
280porn.rhs.mailpolice.com
208bulk.rhs.mailpolice.com
186adv.rhs.mailpolice.com
165blackhole.securitysage.com
43rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
43rhsbl.sorbs.net (union of all results)
30rddn.dnsbl.net.au (zone not intended for this use)
17ex.dnsbl.org
13dynamic.rhs.mailpolice.com
2cart00ney.surriel.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 15 June 2006.