Blacklists Compared

2 December 2006

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the exemptions.ahbl.org and query.bondedsender.org zones because they are not blacklists, and because it is too aggressive to be widely useful the block.blars.org zone is also excluded.

HitsDNS Zone
169835(total number of IP addresses tested, including 505 at SDSC)
157087(union of most IP zones)
128934t1.dnsbl.net.au
96672block.blars.org
93462sbl-xbl.spamhaus.org (union of all results)
93375zen.spamhaus.org (union of all results)
92893xbl.spamhaus.org (union of all results)
91849sbl-xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
91802xbl.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
91762zen.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
91475cbl.abuseat.org
89860dnsbl.sorbs.net (union of all results)
81863no-more-funn.moensted.dk (union of all results)
80254blackholes.five-ten-sg.com (union of all results)
80051dnsbl.sorbs.net (result 127.0.0.10 = dialup)
78567blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
70326dnsbl.tqmcube.com (union of all results)
61850dnsbl-1.uceprotect.net
59112psbl.surriel.com
55822dynablock.njabl.org
55395no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
51380dnsbl-2.uceprotect.net
34580dnsbl.tqmcube.com (result 127.0.0.2 = dialup)
25760bl.spamcop.net
23794dnsbl-3.uceprotect.net
19908no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
17702ubl.unsubscore.com
16462cn-kr.blackholes.us (result 127.0.0.2 = China)
16462cn-kr.blackholes.us (union of all results)
15684unconfirmed.dsbl.org
15485list.dsbl.org
15459dsbl.dnsbl.net.au
14521dnsbl.tqmcube.com (result 127.0.0.3 = spam source)
13851bl.csma.biz
12994dnsbl.tqmcube.com (result 127.0.0.5 = China)
11491blacklist.spambag.org
10868china.blackholes.us
9113korea.services.net
8806dnsbl.njabl.org (union of all results)
8623dnsbl.sorbs.net (result 127.0.0.7 = hacked/vulnerable)
8232dnsbl.tqmcube.com (result 127.0.0.4 = South Korea)
7580wpbl.dnsbl.net.au
6767rmst.dnsbl.net.au
6121korea.blackholes.us
5978no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
5739dnsbl.njabl.org (result 127.0.0.9 = open proxy)
5550mail-abuse.blacklist.jippg.org
5248unsure.nether.net
4416tr.countries.nerd.dk
3912dnsbl.sorbs.net (result 127.0.0.6 = spam source)
3810spamsources.fabel.dk
3785dnsbl.ahbl.org (union of all results)
3394dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
3385zen.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
3385sbl-xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
3384xbl.spamhaus.org (result 127.0.0.5 = time-expired NJABL open proxy)
3075turkey.blackholes.us
2868brazil.blackholes.us
2846bl.spamcannibal.org
2779dnsbl.njabl.org (result 127.0.0.3 = dialup)
2403spews.dnsbl.net.au
2339probes.dnsbl.net.au
1790taiwan.blackholes.us
1717russia.blackholes.us
1664japan.blackholes.us
1508dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
1244argentina.blackholes.us
1054malaysia.blackholes.us
958dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
881blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
850thailand.blackholes.us
693zen.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
693sbl-xbl.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
693sbl.spamhaus.org
628ricn.dnsbl.net.au
580hongkong.blackholes.us
513blackholes.uceb.org (union of all results)
489l1.spews.dnsbl.sorbs.net
474mexico.blackholes.us
446singapore.blackholes.us
432no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
418blackholes.uceb.org (result 127.0.0.6 = spam haven)
411blackholes.five-ten-sg.com (result 127.0.0.7 = spam haven)
408no-more-funn.moensted.dk (result 127.0.0.9 = misc)
386l2.spews.dnsbl.sorbs.net
364dnsbl.ahbl.org (result 127.0.0.4 = spam source)
311blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
272work.drbl.croco.net
227sbl.csma.biz
223blackholes.uceb.org (result 127.0.0.3 = spam source)
151dnsbl.njabl.org (result 127.0.0.2 = open relay)
144multihop.dsbl.org
140dnsbl.njabl.org (result 127.0.0.4 = spam source)
139query.bondedsender.org (not a blacklist!)
93dnsbl.antispam.or.id
78relays.ordb.org
77flowgoaway.com
76blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
68spam.wytnij.to
68dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
67relays.nether.net
61dnsbl.ahbl.org (result 127.0.0.7 = spam haven)
58blackholes.uceb.org (result 127.0.0.5 = dialup)
32ohps.dnsbl.net.au
28dnsbl.ahbl.org (result 127.0.0.15 = open relay)
27tor.dnsbl.sectoor.de (result 127.0.0.2 = /24 contains a Tor server)
27tor.dnsbl.sectoor.de (union of all results)
26exemptions.ahbl.org (not a blacklist!)
25multi.surbl.org
21no-more-funn.moensted.dk (result 127.0.0.5 = relay output)
20osps.dnsbl.net.au
18spamguard.leadmon.net (union of all results)
17rdts.dnsbl.net.au
15spamguard.leadmon.net (result 127.0.0.7 = spam source netblock)
14blackholes.uceb.org (result 127.0.0.2 = open relay)
13bl.deadbeef.com
11blackholes.brainerd.net
11dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)
7dnsbl.sorbs.net (result 127.0.0.5 = open relay)
7osrs.dnsbl.net.au
6nigeria.blackholes.us
6dnsbl.ahbl.org (result 127.0.0.19 = open proxy test zone)
3owps.dnsbl.net.au
3spamguard.leadmon.net (result 127.0.0.3 = spam source)
3blackholes.five-ten-sg.com (result 127.0.0.11 = TCPA violator)
2no-more-funn.moensted.dk (result 127.0.0.4 = unconfirmed opt-in)
2blackholes.five-ten-sg.com (result 127.0.0.10 = virus notices)
1blackholes.uceb.org (result 127.0.0.8 = spam source with fake sender)
1dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
1blackholes.five-ten-sg.com (result 127.0.0.8 = open web form)
1blackholes.five-ten-sg.com (result 127.0.0.6 = open relay)
1blackholes.five-ten-sg.com (result 127.0.0.5 = relay output)
1dnsbl.ahbl.org (result 127.0.0.14 = denial-of-service attacker)


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses.

HitsDNS Zone
169835(total number of IP addresses whose names were tested, including 505 at SDSC)
103007(union of all domain zones)
75541rddn.dnsbl.net.au
72074abuse.rfc-ignorant.org
51376dynamic.rhs.mailpolice.com
46681whois.rfc-ignorant.org (union of all results)
28870whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
17815whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
4384webmail.rhs.mailpolice.com
904postmaster.rfc-ignorant.org
540adv.rhs.mailpolice.com
289rhsbl.ahbl.org
221multi.surbl.org
132bulk.rhs.mailpolice.com
123bl.deadbeef.com
105dsn.rfc-ignorant.org (zone not intended for this use)
100bogusmx.rfc-ignorant.org
8porn.rhs.mailpolice.com
1blackhole.securitysage.com


Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains.

HitsDNS Zone
108863(total number of domains tested, including 463 at SDSC)
19326(union of all domain zones)
9332whois.rfc-ignorant.org (union of all results)
8496whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
4722abuse.rfc-ignorant.org
2408webmail.rhs.mailpolice.com
2261multi.surbl.org
1778postmaster.rfc-ignorant.org
1123bogusmx.rfc-ignorant.org
1051dsn.rfc-ignorant.org
1025rhsbl.ahbl.org
836whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
458porn.rhs.mailpolice.com
271bulk.rhs.mailpolice.com
266adv.rhs.mailpolice.com
183blackhole.securitysage.com
70rhsbl.sorbs.net (result 127.0.0.11 = domain uses bad address space)
70rhsbl.sorbs.net (union of all results)
32rddn.dnsbl.net.au (zone not intended for this use)
16ex.dnsbl.org
10dynamic.rhs.mailpolice.com
1fraud.rhs.mailpolice.com
1bl.deadbeef.com
1cart00ney.surriel.com


This document was last updated by Jeff Makey <jeff@sdsc.edu> on 8 December 2006.