Blacklists Compared

21 January 2012

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the hostkarma.junkemailfilter.com (all results but 127.0.0.2, 127.0.0.3, and 127.0.0.4), exemptions.ahbl.org, query.bondedsender.org, list.dnswl.org, accredit.habeas.com, iadb.isipp.com, iadb2.isipp.com, swl.spamhaus.org, and wl.mailspike.net zones because they are not blacklists. Because they are too aggressive to be widely useful the spam.dnsbl.sorbs.net and l2.apews.org zones are also excluded from the union.

HitsDNS Zone
53283(total number of IP addresses tested, including 172 at SDSC)
50466(union of most IP zones)
42138b.barracudacentral.org
40796zen.spamhaus.org (union of all results)
38347zen.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
38297cbl.abuseat.org
35756ip.v4bl.org
29696bl.tiopan.com
28382spam.dnsbl.sorbs.net
28330hostkarma.junkemailfilter.com (result 127.0.0.2 = spam source)
27551zen.spamhaus.org (result 127.0.0.11 = Spamhaus PBL, Spamhaus entry)
24875dnsbl-1.uceprotect.net
24197dnsbl-3.uceprotect.net
23534dnsbl-2.uceprotect.net
22350bl.mailspike.net (union of all results)
21329dnsbl.sorbs.net (union of all results)
20902truncate.gbudb.net
17616bl.spameatingmonkey.net
16900psbl.surriel.com
15175hostkarma.junkemailfilter.com (result 127.0.1.1 = MTA sends QUIT)
14960ubl.unsubscore.com
13953blackholes.five-ten-sg.com (union of all results)
11841dnsbl.sorbs.net (result 127.0.0.7 = hacked/vulnerable)
9892bl.mailspike.net (result 127.0.0.2 = distributed spam wave participant)
9715bl.mailspike.net (result 127.0.0.11 = very bad reputation)
8481dnsbl.sorbs.net (result 127.0.0.10 = dialup)
8012bl.mailspike.net (result 127.0.0.10 = worst possible reputation)
7014bl.spamcop.net
6793blackholes.five-ten-sg.com (result 127.0.0.9 = misc)
6780l2.apews.org
5777db.wpbl.info
5760blackholes.five-ten-sg.com (result 127.0.0.2 = spam source)
5706list.dnswl.org (not a blacklist!)
5520dnsbl.sorbs.net (result 127.0.0.6 = spam source)
5209hostkarma.junkemailfilter.com (result 127.0.1.2 = MTA does not send QUIT)
5135zen.spamhaus.org (result 127.0.0.10 = Spamhaus PBL, ISP contributed)
3635wl.mailspike.net (union of all results) (not a blacklist!)
3542no-more-funn.moensted.dk (union of all results)
3462bl.score.senderscore.com
3384dnsbl.inps.de
2776ips.backscatterer.org
2694ix.dnsbl.manitu.net
2427hostkarma.junkemailfilter.com (result 127.0.0.1 = whitelisted)
2354wl.mailspike.net (result 127.0.0.17 = possible legitimate sender) (not a blacklist!)
2210hostkarma.junkemailfilter.com (result 127.0.0.3 = mix of spam and nonspam)
1754no-more-funn.moensted.dk (result 127.0.0.3 = dialup)
1723no-more-funn.moensted.dk (result 127.0.0.2 = spam source)
1671hostkarma.junkemailfilter.com (result 127.0.0.5 = do not blacklist)
1394blackholes.five-ten-sg.com (result 127.0.0.4 = unconfirmed opt-in)
1306korea.services.net
1277wl.mailspike.net (result 127.0.0.18 = good reputation) (not a blacklist!)
1227bl.spamcannibal.org
919spamsources.fabel.dk
770mail-abuse.blacklist.jippg.org
640accredit.habeas.com (not a blacklist!)
585query.bondedsender.org (not a blacklist!)
462zen.spamhaus.org (union of SBL and SBLCSS results)
385zen.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
350l2.bbfh.ext.sorbs.net
339dnsbl.njabl.org (union of all results)
338l1.bbfh.ext.sorbs.net
316aspews.ext.sorbs.net
279dnsbl.njabl.org (result 127.0.0.9 = open proxy)
239dnsbl.ahbl.org (union of all results)
220tr.countries.nerd.dk
219iadb.isipp.com (not a blacklist!)
162hostkarma.junkemailfilter.com (result 127.0.0.4 = spam source aspirant)
144dnsbl.ahbl.org (result 127.0.0.4 = spam source)
108iadb2.isipp.com (not a blacklist!)
86dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
77zen.spamhaus.org (result 127.0.0.3 = Spamhaus SBLCSS)
65dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
65dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
65dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
53tor.dnsbl.sectoor.de (union of all results)
52tor.dnsbl.sectoor.de (result 127.0.0.2 = /24 contains a Tor server)
49no-more-funn.moensted.dk (result 127.0.0.9 = misc)
36dnsbl.njabl.org (result 127.0.0.2 = open relay)
32hostkarma.junkemailfilter.com (result 127.0.2.3 = domain first seen more than 7 days ago)
28dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
28no-more-funn.moensted.dk (result 127.0.0.7 = spam haven)
24dnsbl.njabl.org (result 127.0.0.4 = spam source)
14swl.spamhaus.org (union of all results) (not a blacklist!)
9no-more-funn.moensted.dk (result 127.0.0.10 = open proxy)
9bl.deadbeef.com
9dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)
9spamguard.leadmon.net (union of all results)
7multi.surbl.org
7spamguard.leadmon.net (result 127.0.0.9 = abused DNS server)
6swl.spamhaus.org (result 127.0.2.103 = sends transactions - temporary listing) (not a blacklist!)
6swl.spamhaus.org (result 127.0.2.3 = sends transactions) (not a blacklist!)
6blackholes.five-ten-sg.com (result 127.0.0.12 = spam-friendly freemail provider)
4wl.mailspike.net (result 127.0.0.19 = very good reputation) (not a blacklist!)
3multi.uribl.com (result 127.0.0.2 = spam resource)
3multi.uribl.com (union of all results)
2dnsbl-0.uceprotect.net
2swl.spamhaus.org (result 127.0.2.2 = sends individual mail) (not a blacklist!)
2spamguard.leadmon.net (result 127.0.0.3 = spam source)
1tor.dnsbl.sectoor.de (result 127.0.0.1 = Tor server)

Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses. The "union of most domain zones" line includes data from the hostkarma.junkemailfilter.com zone only when the results are 127.0.0.2, 127.0.0.3, or 127.0.0.4 because other results are not blacklists.

HitsDNS Zone
53283(total number of IP addresses whose names were tested, including 172 at SDSC)
27122hostkarma.junkemailfilter.com (result 127.0.2.3 = domain first seen more than 7 days ago)
21386hostkarma.junkemailfilter.com (result 127.0.1.1 = MTA sends QUIT)
17464(union of most domain zones)
14067abuse.rfc-ignorant.org
7050whois.rfc-ignorant.org (union of all results)
6065whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
3649hostkarma.junkemailfilter.com (result 127.0.0.5 = do not blacklist)
2459hostkarma.junkemailfilter.com (result 127.0.0.1 = whitelisted)
1671l1.apews.org
985whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
292hostkarma.junkemailfilter.com (result 127.0.0.3 = mix of spam and nonspam)
268hostkarma.junkemailfilter.com (result 127.0.0.2 = spam source)
220dbl.spamhaus.org (result 127.0.1.2 = spam source)
220dbl.spamhaus.org (union of all results)
190hostkarma.junkemailfilter.com (result 127.0.1.4 = no verify host)
173urired.spameatingmonkey.net
155hostkarma.junkemailfilter.com (result 127.0.2.2 = domain first seen in last 7 days)
127hostkarma.junkemailfilter.com (result 127.0.1.2 = MTA does not send QUIT)
44postmaster.rfc-ignorant.org
22bogusmx.rfc-ignorant.org
17multi.surbl.org
16rhsbl.ahbl.org
13multi.uribl.com (union of all results)
12multi.uribl.com (result 127.0.0.2 = spam resource)
9fresh.spameatingmonkey.net
6dob.sibl.support-intelligence.net
4dsn.rfc-ignorant.org (zone not intended for this use)
3hostkarma.junkemailfilter.com (result 127.0.2.1 = domain first seen today)
1multi.uribl.com (result 127.0.0.8 = new domain or concealed contact)
1bl.deadbeef.com

Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains. The "union of most domain zones" line includes data from the hostkarma.junkemailfilter.com zone only when the results are 127.0.0.2, 127.0.0.3, or 127.0.0.4 because other results are not blacklists.

HitsDNS Zone
15921(total number of domains tested, including 147 at SDSC)
13769hostkarma.junkemailfilter.com (result 127.0.2.3 = domain first seen more than 7 days ago)
4004(union of most domain zones)
3464hostkarma.junkemailfilter.com (result 127.0.1.1 = MTA sends QUIT)
1912hostkarma.junkemailfilter.com (result 127.0.0.1 = whitelisted)
1802hostkarma.junkemailfilter.com (result 127.0.0.5 = do not blacklist)
1332whois.rfc-ignorant.org (union of all results)
1219whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
1213abuse.rfc-ignorant.org
663postmaster.rfc-ignorant.org
649dbl.spamhaus.org (result 127.0.1.2 = spam source)
649dbl.spamhaus.org (union of all results)
590hostkarma.junkemailfilter.com (result 127.0.0.2 = spam source)
451multi.uribl.com (union of all results)
450hostkarma.junkemailfilter.com (result 127.0.2.2 = domain first seen in last 7 days)
440multi.uribl.com (result 127.0.0.2 = spam resource)
410urired.spameatingmonkey.net
399multi.surbl.org
285bogusmx.rfc-ignorant.org
277hostkarma.junkemailfilter.com (result 127.0.0.3 = mix of spam and nonspam)
176dsn.rfc-ignorant.org
113whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
105fresh.spameatingmonkey.net
67dob.sibl.support-intelligence.net
19rhsbl.ahbl.org
12hostkarma.junkemailfilter.com (result 127.0.1.4 = no verify host)
12hostkarma.junkemailfilter.com (result 127.0.1.2 = MTA does not send QUIT)
11multi.uribl.com (result 127.0.0.4 = opt-out spam resource)
10hostkarma.junkemailfilter.com (result 127.0.2.1 = domain first seen today)
9ex.dnsbl.org
3hostkarma.junkemailfilter.com (result 127.0.1.3 = MTA somtimes sends QUIT)

This document was last updated by Jeff Makey <jeff@sdsc.edu> on 24 January 2012.