Blacklists Compared

5 August 2006

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
98314(total number of IP addresses tested, including 538 at SDSC)
82096(union of most IP zones)
60528block.blars.org
56180t1.dnsbl.net.au
51088dnsbl.sorbs.net (union of all results)
44828blackholes.five-ten-sg.com (union of all results)
43223blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
39989dnsbl.tqmcube.com (union of all results)
37680dnsbl.sorbs.net (result 127.0.0.10 = dialup)
27528sbl-xbl.spamhaus.org (union of all results)
27065dynablock.njabl.org
26675xbl.spamhaus.org (union of all results)
24457psbl.surriel.com
24143cbl.abuseat.org
24114sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
24111xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
18902cn-kr.blackholes.us (result 127.0.0.2 = China)
18902cn-kr.blackholes.us (union of all results)
15472dnsbl.tqmcube.com (result 127.0.0.2 = dialup)
15356no-more-funn.moensted.dk (union of all results)
13386china.blackholes.us
13100dnsbl.tqmcube.com (result 127.0.0.5 = China)
12633bl.csma.biz
12146unconfirmed.dsbl.org
11974list.dsbl.org
11967dsbl.dnsbl.net.au
10895dnsbl.sorbs.net (result 127.0.0.7 = hacked/vulnerable)
10146blacklist.spambag.org
9130dnsbl-2.uceprotect.net
8705bl.spamcop.net
8427wpbl.dnsbl.net.au
8084dnsbl-1.uceprotect.net
7987dnsbl.tqmcube.com (result 127.0.0.3 = spam source)
7483dnsbl.sorbs.net (result 127.0.0.6 = spam source)
7102combined-hib.dnsiplists.completewhois.com (union of all results)
7098combined-hib.dnsiplists.completewhois.com (result 127.0.0.4 = bad whois data)
7065dnsbl.njabl.org (union of all results)
6538no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
5760korea.services.net
5587dnsbl.njabl.org (result 127.0.0.9 = open proxy)
5528korea.blackholes.us
4880dnsbl.tqmcube.com (result 127.0.0.4 = South Korea)
4658l2.spews.dnsbl.sorbs.net
4523no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
4399xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
4399sbl-xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
4103dnsbl.ahbl.org (union of all results)
3791dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
3769brazil.blackholes.us
3767no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
3717unsure.nether.net
3565l1.spews.dnsbl.sorbs.net
3513rmst.dnsbl.net.au
3020spamsources.fabel.dk
2964spam.wytnij.to
2607ubl.unsubscore.com
2586dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
2021japan.blackholes.us
1806mail-abuse.blacklist.jippg.org
1760taiwan.blackholes.us
1561dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1558ricn.dnsbl.net.au
1476tr.countries.nerd.dk
1467turkey.blackholes.us
1437dnsbl-3.uceprotect.net
1219bl.spamcannibal.org
993spews.dnsbl.net.au
990sbl.spamhaus.org
989sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
986argentina.blackholes.us
986dnsbl.njabl.org (result 127.0.0.3 = dialup)
965sbl.csma.biz
827blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
763mexico.blackholes.us
693russia.blackholes.us
672probes.dnsbl.net.au
579hongkong.blackholes.us
445malaysia.blackholes.us
426no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
422blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
393thailand.blackholes.us
333dnsbl.njabl.org (result 127.0.0.4 = spam source)
320singapore.blackholes.us
287dnsbl.ahbl.org (result 127.0.0.4 = spam source)
286no-more-funn.moensted.dk (result 127.0.0.9 = misc)
257blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
248blackholes.uceb.org (union of all results)
219blackholes.uceb.org (result 127.0.0.3 = spam source)
169dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
169dnsbl.njabl.org (result 127.0.0.2 = open relay)
167blackholes.intersil.net
145query.bondedsender.org (not a blacklist!)
141ohps.dnsbl.net.au
140multihop.dsbl.org
137work.drbl.croco.net
96dnsbl.antispam.or.id
95relays.nether.net
82flowgoaway.com
79blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
70dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
61relays.ordb.org
50blackholes.brainerd.net
30no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
29blackholes.uceb.org (result 127.0.0.2 = open relay)
29osps.dnsbl.net.au
28exemptions.ahbl.org (not a blacklist!)
24rdts.dnsbl.net.au
23tor.dnsbl.sectoor.de (union of all results)
22tor.dnsbl.sectoor.de (result 127.0.0.2 = /24 contains a Tor server)
16nigeria.blackholes.us
14dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
14spamguard.leadmon.net (union of all results)
13dnsbl.sorbs.net (result 127.0.0.5 = open relay)
12blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
12dnsbl.ahbl.org (result 127.0.0.15 = open relay)
10spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
9osrs.dnsbl.net.au
9hil.habeas.com
4blackholes.five-ten-sg.com (result 127.0.0.11 = TCPA violator)
4bl.deadbeef.com
4combined-hib.dnsiplists.completewhois.com (result 127.0.0.2 = unallocated IP address)
3owps.dnsbl.net.au
3spamsites.dnsbl.net.au
3spamguard.leadmon.net (result 127.0.0.8 = open proxy)
2blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
1tor.dnsbl.sectoor.de (result 127.0.0.1 = Tor server)
1dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
1omrs.dnsbl.net.au
1spamguard.leadmon.net (result 127.0.0.3 = spam source)
1no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1blackholes.five-ten-sg.com (result 127.0.0.13 = challenge-response source)
1dnsbl.ahbl.org (result 127.0.0.11 = no postmaster or abuse e-mail)
1dnsbl.ahbl.org (result 127.0.0.14 = denial-of-service attacker)
1dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
98314(total number of IP addresses whose names were tested, including 538 at SDSC)
49993(union of all domain zones)
36200abuse.rfc-ignorant.org
33976rddn.dnsbl.net.au
24729whois.rfc-ignorant.org (union of all results)
23212dynamic.rhs.mailpolice.com
18207whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
6528whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
3356webmail.rhs.mailpolice.com
777rhsbl.ahbl.org
507adv.rhs.mailpolice.com
307postmaster.rfc-ignorant.org
106dsn.rfc-ignorant.org (zone not intended for this use)
101bulk.rhs.mailpolice.com
90bogusmx.rfc-ignorant.org
14porn.rhs.mailpolice.com
3blackhole.securitysage.com
1ex.dnsbl.org
1bl.deadbeef.com


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
51461(total number of domains tested, including 443 at SDSC)
9348(union of all domain zones)
3661whois.rfc-ignorant.org (union of all results)
3323abuse.rfc-ignorant.org
2990whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
1464webmail.rhs.mailpolice.com
1362postmaster.rfc-ignorant.org
1126rhsbl.ahbl.org
1015dsn.rfc-ignorant.org
750bogusmx.rfc-ignorant.org
671whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
276bulk.rhs.mailpolice.com
268porn.rhs.mailpolice.com
185adv.rhs.mailpolice.com
159blackhole.securitysage.com
53rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
53rhsbl.sorbs.net (union of all results)
24rddn.dnsbl.net.au (zone not intended for this use)
15ex.dnsbl.org
9dynamic.rhs.mailpolice.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 23 August 2006.