Blacklists Compared

16 June 2012

[ Fighting Spam | Dialup Zones | Blacklists Compared | Current Blacklist Comparison | Sendmail Configuration ]


Survey results for all known public IP-based DNS blacklists. Lookups were done on connecting IP addresses. The "union of most IP zones" line excludes the hostkarma.junkemailfilter.com (all results but 127.0.0.2, 127.0.0.3, and 127.0.0.4), exemptions.ahbl.org, query.bondedsender.org, list.dnswl.org, accredit.habeas.com, iadb.isipp.com, iadb2.isipp.com, swl.spamhaus.org, and wl.mailspike.net zones because they are not blacklists. Because they are too aggressive to be widely useful the spam.dnsbl.sorbs.net and l2.apews.org zones are also excluded from the union.

HitsDNS Zone
39428(total number of IP addresses tested, including 168 at SDSC)
35788(union of most IP zones)
27717l2.apews.org
27687ip.v4bl.org
27318b.barracudacentral.org
27185zen.spamhaus.org (union of all results)
25482cbl.abuseat.org
25479zen.spamhaus.org (result 127.0.0.4 = Composite Blocking List)
22813bl.tiopan.com
17911hostkarma.junkemailfilter.com (result 127.0.0.2 = spam source)
17448zen.spamhaus.org (result 127.0.0.11 = Spamhaus PBL, Spamhaus entry)
16085bl.mailspike.net (union of all results)
15725dnsbl-1.uceprotect.net
15547hostkarma.junkemailfilter.com (result 127.0.1.1 = MTA sends QUIT)
13186all.spamrats.com (union of all results)
12549bl.mailspike.net (result 127.0.0.2 = distributed spam wave participant)
11958dnsbl-2.uceprotect.net
11491spam.dnsbl.sorbs.net
11326dnsbl-3.uceprotect.net
10843psbl.surriel.com
10151dnsbl.sorbs.net (union of all results)
9830ubl.unsubscore.com
8607bl.spameatingmonkey.net
7491all.spamrats.com (result 127.0.0.36 = dialup)
6331list.dnswl.org (not a blacklist!)
5970dnsbl.inps.de
5465dnsbl.sorbs.net (result 127.0.0.7 = hacked/vulnerable)
5276all.spamrats.com (result 127.0.0.37 = no reverse DNS entry)
5202dnsbl.sorbs.net (result 127.0.0.10 = dialup)
4840truncate.gbudb.net
3343db.wpbl.info
3108bl.spamcop.net
3010hostkarma.junkemailfilter.com (result 127.0.0.1 = whitelisted)
2578wl.mailspike.net (union of all results) (not a blacklist!)
2515bl.mailspike.net (result 127.0.0.12 = bad reputation)
2506zen.spamhaus.org (result 127.0.0.10 = Spamhaus PBL, ISP contributed)
2424hostkarma.junkemailfilter.com (result 127.0.1.2 = MTA does not send QUIT)
2389hostkarma.junkemailfilter.com (result 127.0.0.3 = mix of spam and nonspam)
2328ips.backscatterer.org
1843ix.dnsbl.manitu.net
1655wl.mailspike.net (result 127.0.0.18 = good reputation) (not a blacklist!)
1482bl.score.senderscore.com
1398zen.spamhaus.org (union of SBL and SBLCSS results)
1382hostkarma.junkemailfilter.com (result 127.0.0.5 = do not blacklist)
1286bl.mailspike.net (result 127.0.0.13 = suspicious behavior)
1111korea.services.net
993spamsources.fabel.dk
968bl.spamcannibal.org
854wl.mailspike.net (result 127.0.0.17 = possible legitimate sender) (not a blacklist!)
751accredit.habeas.com (not a blacklist!)
728zen.spamhaus.org (result 127.0.0.3 = Spamhaus SBLCSS)
670zen.spamhaus.org (result 127.0.0.2 = Spamhaus SBL)
604query.bondedsender.org (not a blacklist!)
457all.spamrats.com (result 127.0.0.38 = spam source)
419bl.mailspike.net (result 127.0.0.11 = very bad reputation)
364bl.mailspike.net (result 127.0.0.10 = worst possible reputation)
355tr.countries.nerd.dk
321l2.bbfh.ext.sorbs.net
292mail-abuse.blacklist.jippg.org
258dnsbl.njabl.org (union of all results)
254aspews.ext.sorbs.net
232iadb.isipp.com (not a blacklist!)
229hostkarma.junkemailfilter.com (result 127.0.0.4 = spam source aspirant)
190dnsbl.njabl.org (result 127.0.0.9 = open proxy)
188dnsbl.sorbs.net (result 127.0.0.6 = spam source)
148dnsbl.ahbl.org (union of all results)
109dnsbl.ahbl.org (result 127.0.0.4 = spam source)
73all.s5h.net
57iadb2.isipp.com (not a blacklist!)
45tor.dnsbl.sectoor.de (union of all results)
44tor.dnsbl.sectoor.de (result 127.0.0.2 = /24 contains a Tor server)
38wl.mailspike.net (result 127.0.0.19 = very good reputation) (not a blacklist!)
37dnsbl.njabl.org (result 127.0.0.4 = spam source)
31wl.mailspike.net (result 127.0.0.20 = excellent reputation) (not a blacklist!)
31dnsbl.njabl.org (result 127.0.0.2 = open relay)
30dnsbl.sorbs.net (result 127.0.0.3 = open socks proxy)
30dnsbl.sorbs.net (result 127.0.0.4 = open proxy)
30dnsbl.sorbs.net (result 127.0.0.2 = open http proxy)
24dnsbl.ahbl.org (result 127.0.0.3 = open proxy)
20spamguard.leadmon.net (union of all results)
19spamguard.leadmon.net (result 127.0.0.9 = abused DNS server)
15dnsbl.ahbl.org (result 127.0.0.10 = shoot on sight spammer)
11swl.spamhaus.org (union of all results) (not a blacklist!)
9multi.surbl.org
9bl.deadbeef.com
8hostkarma.junkemailfilter.com (result 127.0.2.3 = domain first seen more than 7 days ago)
6swl.spamhaus.org (result 127.0.2.3 = sends transactions) (not a blacklist!)
4multi.uribl.com (result 127.0.0.2 = spam resource)
4multi.uribl.com (union of all results)
3dnsbl-0.uceprotect.net
3swl.spamhaus.org (result 127.0.2.103 = sends transactions - temporary listing) (not a blacklist!)
2swl.spamhaus.org (result 127.0.2.2 = sends individual mail) (not a blacklist!)
1tor.dnsbl.sectoor.de (result 127.0.0.1 = Tor server)
1dnsbl.sorbs.net (result 127.0.0.9 = zombie network)
1spamguard.leadmon.net (result 127.0.0.3 = spam source)

Survey results for all known public domain-name-based DNS blacklists. Lookups were done on the domain names of connecting IP addresses. The "union of most domain zones" line includes data from the hostkarma.junkemailfilter.com zone only when the results are 127.0.0.2, 127.0.0.3, or 127.0.0.4 because other results are not blacklists.

HitsDNS Zone
39428(total number of IP addresses whose names were tested, including 168 at SDSC)
22365hostkarma.junkemailfilter.com (result 127.0.2.3 = domain first seen more than 7 days ago)
17799hostkarma.junkemailfilter.com (result 127.0.1.1 = MTA sends QUIT)
13521(union of most domain zones)
10739abuse.rfc-ignorant.org
7995l1.apews.org
5365whois.rfc-ignorant.org (union of all results)
4592whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
3050hostkarma.junkemailfilter.com (result 127.0.0.5 = do not blacklist)
2955hostkarma.junkemailfilter.com (result 127.0.0.1 = whitelisted)
773whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
431hostkarma.junkemailfilter.com (result 127.0.0.2 = spam source)
390dbl.spamhaus.org (result 127.0.1.2 = spam source)
390dbl.spamhaus.org (union of all results)
258urired.spameatingmonkey.net
244hostkarma.junkemailfilter.com (result 127.0.0.3 = mix of spam and nonspam)
218hostkarma.junkemailfilter.com (result 127.0.1.4 = no verify host)
122hostkarma.junkemailfilter.com (result 127.0.2.2 = domain first seen in last 7 days)
80hostkarma.junkemailfilter.com (result 127.0.1.2 = MTA does not send QUIT)
41multi.surbl.org
35bogusmx.rfc-ignorant.org
34postmaster.rfc-ignorant.org
21rhsbl.ahbl.org
19multi.uribl.com (union of all results)
18multi.uribl.com (result 127.0.0.2 = spam resource)
9fresh.spameatingmonkey.net
5dob.sibl.support-intelligence.net
4dsn.rfc-ignorant.org (zone not intended for this use)
3hostkarma.junkemailfilter.com (result 127.0.2.1 = domain first seen today)
2bl.deadbeef.com
1multi.uribl.com (result 127.0.0.8 = new domain or concealed contact)

Survey results for all known public domain-name-based DNS blacklists. Lookups were done on SMTP sender domains. The "union of most domain zones" line includes data from the hostkarma.junkemailfilter.com zone only when the results are 127.0.0.2, 127.0.0.3, or 127.0.0.4 because other results are not blacklists.

HitsDNS Zone
24754(total number of domains tested, including 131 at SDSC)
20017hostkarma.junkemailfilter.com (result 127.0.2.3 = domain first seen more than 7 days ago)
6884(union of most domain zones)
3666hostkarma.junkemailfilter.com (result 127.0.1.1 = MTA sends QUIT)
2792whois.rfc-ignorant.org (union of all results)
2676whois.rfc-ignorant.org (result 127.0.0.7 = no whois data at all)
2100dbl.spamhaus.org (result 127.0.1.2 = spam source)
2100dbl.spamhaus.org (union of all results)
2053hostkarma.junkemailfilter.com (result 127.0.0.1 = whitelisted)
1861hostkarma.junkemailfilter.com (result 127.0.0.2 = spam source)
1736hostkarma.junkemailfilter.com (result 127.0.0.5 = do not blacklist)
1518urired.spameatingmonkey.net
1514hostkarma.junkemailfilter.com (result 127.0.2.2 = domain first seen in last 7 days)
1302multi.surbl.org
1176abuse.rfc-ignorant.org
1052multi.uribl.com (union of all results)
1030multi.uribl.com (result 127.0.0.2 = spam resource)
586postmaster.rfc-ignorant.org
468l1.apews.org
390bogusmx.rfc-ignorant.org
244fresh.spameatingmonkey.net
227hostkarma.junkemailfilter.com (result 127.0.0.3 = mix of spam and nonspam)
158dsn.rfc-ignorant.org
116whois.rfc-ignorant.org (result 127.0.0.5 = bad whois data)
22rhsbl.ahbl.org
19multi.uribl.com (result 127.0.0.4 = opt-out spam resource)
18hostkarma.junkemailfilter.com (result 127.0.1.4 = no verify host)
17hostkarma.junkemailfilter.com (result 127.0.2.1 = domain first seen today)
15hostkarma.junkemailfilter.com (result 127.0.1.2 = MTA does not send QUIT)
7ex.dnsbl.org
5dob.sibl.support-intelligence.net
3multi.uribl.com (result 127.0.0.8 = new domain or concealed contact)
3hostkarma.junkemailfilter.com (result 127.0.1.3 = MTA somtimes sends QUIT)

This document was last updated by Jeff Makey <jeff@sdsc.edu> on 18 June 2012.