Blacklists Compared

12 August 2006

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
93704(total number of IP addresses tested, including 526 at SDSC)
80019(union of most IP zones)
58275t1.dnsbl.net.au
58054block.blars.org
50474dnsbl.sorbs.net (union of all results)
43437blackholes.five-ten-sg.com (union of all results)
41900blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
39101dnsbl.tqmcube.com (union of all results)
36894dnsbl.sorbs.net (result 127.0.0.10 = dialup)
30482sbl-xbl.spamhaus.org (union of all results)
29744xbl.spamhaus.org (union of all results)
27691cbl.abuseat.org
27659xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
27659sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
27226psbl.surriel.com
26019dynablock.njabl.org
18664cn-kr.blackholes.us (result 127.0.0.2 = China)
18664cn-kr.blackholes.us (union of all results)
17901no-more-funn.moensted.dk (union of all results)
15090dnsbl.tqmcube.com (result 127.0.0.2 = dialup)
12996dnsbl-2.uceprotect.net
12752china.blackholes.us
12598dnsbl.tqmcube.com (result 127.0.0.5 = China)
12425dnsbl.sorbs.net (result 127.0.0.7 = hacked/vulnerable)
11393unconfirmed.dsbl.org
11243list.dsbl.org
11238dsbl.dnsbl.net.au
10336blacklist.spambag.org
10267bl.csma.biz
9487dnsbl-1.uceprotect.net
8844bl.spamcop.net
7433dnsbl.tqmcube.com (result 127.0.0.3 = spam source)
7155combined-hib.dnsiplists.completewhois.com (result 127.0.0.4 = bad whois data)
7155combined-hib.dnsiplists.completewhois.com (union of all results)
6999no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
6820wpbl.dnsbl.net.au
6621dnsbl.sorbs.net (result 127.0.0.6 = spam source)
6521dnsbl.njabl.org (union of all results)
6182korea.services.net
5919korea.blackholes.us
5460no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
5260dnsbl.njabl.org (result 127.0.0.9 = open proxy)
5218dnsbl.tqmcube.com (result 127.0.0.4 = South Korea)
5022no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
4546l2.spews.dnsbl.sorbs.net
4078xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
4078sbl-xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
3795dnsbl.ahbl.org (union of all results)
3678unsure.nether.net
3530dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
3502l1.spews.dnsbl.sorbs.net
3309rmst.dnsbl.net.au
3105brazil.blackholes.us
3050spamsources.fabel.dk
2641ubl.unsubscore.com
2620spam.wytnij.to
2314dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
2018taiwan.blackholes.us
2007japan.blackholes.us
1771mail-abuse.blacklist.jippg.org
1634spews.dnsbl.net.au
1576turkey.blackholes.us
1574tr.countries.nerd.dk
1524dnsbl-3.uceprotect.net
1506dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
1210bl.spamcannibal.org
930dnsbl.njabl.org (result 127.0.0.3 = dialup)
923sbl.spamhaus.org
921sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
908ricn.dnsbl.net.au
836blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
821sbl.csma.biz
782russia.blackholes.us
726argentina.blackholes.us
655mexico.blackholes.us
597probes.dnsbl.net.au
506hongkong.blackholes.us
480thailand.blackholes.us
451malaysia.blackholes.us
408no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
355blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
314blackholes.uceb.org (union of all results)
279blackholes.uceb.org (result 127.0.0.3 = spam source)
267blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
261singapore.blackholes.us
234dnsbl.ahbl.org (result 127.0.0.4 = spam source)
223no-more-funn.moensted.dk (result 127.0.0.9 = misc)
209dnsbl.njabl.org (result 127.0.0.4 = spam source)
172blackholes.intersil.net
161query.bondedsender.org (not a blacklist!)
138ohps.dnsbl.net.au
130dnsbl.njabl.org (result 127.0.0.2 = open relay)
121work.drbl.croco.net
120multihop.dsbl.org
109dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
92relays.nether.net
85flowgoaway.com
84relays.ordb.org
65dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
60blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
51no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
49dnsbl.antispam.or.id
34osps.dnsbl.net.au
33exemptions.ahbl.org (not a blacklist!)
32blackholes.uceb.org (result 127.0.0.2 = open relay)
29dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
27spamguard.leadmon.net (union of all results)
23tor.dnsbl.sectoor.de (result 127.0.0.2 = /24 contains a Tor server)
23tor.dnsbl.sectoor.de (union of all results)
21spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
16osrs.dnsbl.net.au
16rdts.dnsbl.net.au
15blackholes.brainerd.net
12dnsbl.sorbs.net (result 127.0.0.5 = open relay)
11nigeria.blackholes.us
11blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
10hil.habeas.com
6owps.dnsbl.net.au
4dnsbl.ahbl.org (result 127.0.0.15 = open relay)
3spamguard.leadmon.net (result 127.0.0.3 = spam source)
3spamguard.leadmon.net (result 127.0.0.8 = open proxy)
3blackholes.five-ten-sg.com (result 127.0.0.11 = TCPA violator)
3blackholes.five-ten-sg.com (result 127.0.0.13 = challenge-response source)
3bl.deadbeef.com
2blackholes.uceb.org (result 127.0.0.5 = dialup)
2no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
1blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
1dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
1omrs.dnsbl.net.au
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
1dnsbl.ahbl.org (result 127.0.0.11 = no postmaster or abuse e-mail)
1dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)

The blackholes.intersil.net zone "lists entrenched spammers, mainsleaze and mainsleaze wannabes who have pestered users at Intersil." The flowgoaway.com zone lists FloNetwork systems.


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
93704(total number of IP addresses whose names were tested, including 526 at SDSC)
47428(union of all domain zones)
33443abuse.rfc-ignorant.org
33088rddn.dnsbl.net.au
23269whois.rfc-ignorant.org (union of all results)
22695dynamic.rhs.mailpolice.com
17869whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
5404whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
3292webmail.rhs.mailpolice.com
781rhsbl.ahbl.org
527adv.rhs.mailpolice.com
352postmaster.rfc-ignorant.org
100dsn.rfc-ignorant.org (zone not intended for this use)
95bulk.rhs.mailpolice.com
91bogusmx.rfc-ignorant.org
18porn.rhs.mailpolice.com
2blackhole.securitysage.com
2ex.dnsbl.org
1bl.deadbeef.com


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
46358(total number of domains tested, including 486 at SDSC)
8482(union of all domain zones)
3208whois.rfc-ignorant.org (union of all results)
3077abuse.rfc-ignorant.org
2580whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
1357webmail.rhs.mailpolice.com
1261postmaster.rfc-ignorant.org
1017rhsbl.ahbl.org
986dsn.rfc-ignorant.org
748bogusmx.rfc-ignorant.org
628whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
262porn.rhs.mailpolice.com
209bulk.rhs.mailpolice.com
190adv.rhs.mailpolice.com
166blackhole.securitysage.com
53rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
53rhsbl.sorbs.net (union of all results)
29rddn.dnsbl.net.au (zone not intended for this use)
18ex.dnsbl.org
13dynamic.rhs.mailpolice.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 26 August 2006.