DNSBL - DNS-basierte Blacklist12 min read4 sections

Scoring Model, States & Return Codes

Detailed explanation of the multi-level scoring model, listing states, signal weights, score decay, and the DNS return codes.

01

Signal-based Scoring

Every report, detection, or piece of evidence is recorded as a signal with a specific weight. The total score of an IP is the sum of all active (non-decayed) signal weights.

Signal Types & Weights

Signal TypeBase WeightDescriptionDecay Rate
Normal User Report+8Report from an unverified userFast (3d half-life)
Trusted Reporter+15Report from a verified reporter with API tokenNormal (7d)
Independent Report+12Additional independent corroborating reportNormal (7d)
Heuristic / Pattern+15Suspicious pattern detected by automated analysisNormal (7d)
Honeypot+25Caught by a spam trap / honeypotNormal (7d)
Trusted External Feed+40Data from an established threat intelligence sourceSlow (14d)
Spamtrap Hit+60Email sent to a known spamtrap addressSlow (14d)
Manual Verification+80Admin-confirmed after manual reviewVery Slow (30d)
Confirmed Malware+100Verified malware distributionVery Slow (30d)
Confirmed Phishing+100Verified phishing activityVery Slow (30d)
Confirmed Botnet+100Verified botnet membershipVery Slow (30d)

Reporter Reputation

Signal weights are multiplied by the reporter's trust multiplier (0.25x–2.0x). New/unknown reporters start low (~0.75x), while reporters with a proven track record of accurate reports can reach up to 2.0x. False positives reduce the multiplier.

Key Rule

A single normal user report (weight 8 × ~0.75 multiplier ≈ 6 points) can NEVER exceed the watchlist threshold (20). Hard-listing requires either:

  • At least 2 independent corroborating signals, OR
  • 1 critical confirmed signal (Malware, Phishing, Botnet, Spamtrap, Manual Verification)
02

Listing States

Four States

ScoreStateDNS ResponseRecommended Action
0–19🟢 CleanNXDOMAINAccept - no issues detected.
20–49🟡 WatchlistNXDOMAINInternal monitoring only. Not publicly listed. No DNS response.
50–89🟠 Soft-ListedA record (low confidence)Tag, quarantine, greylist, or increase spam score. Do NOT reject.
90+🔴 Hard-ListedA record (high confidence)Reject is appropriate. Multiple corroborating signals or critical evidence.

Important: Soft-listed IPs return a DNS response, but it signals low confidence. Mail servers should use this for scoring/tagging, not for outright rejection. Only hard-listed IPs have enough evidence to warrant rejection.

03

DNS Return Codes

Our DNSBL uses differentiated return codes that encode both the threat category and the confidence level:

Return CodeCategoryDescriptionRecommended Action
127.0.0.2Spam (low confidence)Suspected spam, but limited evidence. Soft-listed.Tag only. Increase spam score, quarantine, greylist. Do NOT reject.
127.0.0.3Spam (high confidence)Confirmed spam with strong evidence. Hard-listed.May reject. Multiple independent signals confirm spam activity.
127.0.0.4MalwareIP distributing malware via email.Reject immediately.
127.0.0.5PhishingIP involved in phishing campaigns.Reject immediately.
127.0.0.6BotnetIP is part of a known botnet.Reject immediately.
127.0.0.7Exploit/ScannerIP performing exploit scans or vulnerability probing.Reject or quarantine.
127.0.0.8Abuse/PolicyIP violating acceptable use policies.Reject or quarantine.
127.0.0.9Manual BlockManually blocked by administrator.Reject.
NXDOMAINClean / WatchlistNot listed or under observation only.Accept.

TXT Records

Each listed IP also returns a TXT record with detailed information:

"Listed: spam | state: soft-listed | confidence: medium | score: 65"

Critical Enforcement Rule

  • 127.0.0.4 (malware), 127.0.0.5 (phishing), 127.0.0.6 (botnet): May reject immediately.
  • 127.0.0.3 (spam high confidence): May reject.
  • 127.0.0.2 (spam low confidence): Do NOT reject directly! Use for tagging, quarantine, greylisting, or increasing the spam score.
04

Score Decay & Auto-Delisting

Time-based Decay

Every signal loses weight over time using exponential decay with a configurable half-life:

Decay RateHalf-LifeUsed For
Fast3 daysNormal user reports
Normal7 daysTrusted reports, heuristics, honeypots
Slow14 daysExternal feeds, spamtrap hits
Very Slow30 daysManual verification, confirmed malware/phishing/botnet

Example: A user report with weight 8 will have only ~4 weight after 3 days, ~2 after 6 days, and become negligible after ~15 days.

Automatic Delisting

If no new signals are received, the IP is automatically delisted after:

  • Spam / Open Relay: 14 days
  • Exploit / Abuse: 21 days
  • Phishing: 30 days
  • Malware / Botnet: 60 days

The auto-delist date is shown in the lookup results.