Popular topics: Spam blocklist Abuse Contact ValidationPolicy blocklistWelcome listPotentially compromised accountsExploit blocklistCombined blocklistDomain blocklistRspamdWhat is XARF?

backscatter

IP blocklist of hosts that are sending backscatter to our traps

Status: Beta
Type: IPv4, IPv6
Cloud DNS namespace: N/A, not currently published
Rsync File: beta-lists/backscatter.zone
Return Codes: 127.0.0.6
Test Points: 127.0.0.2, 127.0.0.6, ::FFFF:7F00:2, ::FFFF:7F00:6
Listing Duration: Approximately 5.2 days after last seen

Description

This lists IPs that have sent bounce messages to our traps.

Our trap domains are never used to send email, so any bounce messages we receive are because someone else forged our domain, so any host sending us bounce messages is because they incorrectly accepted one of these messages and are therefore sending us "backscatter".

Backscatter can be a big problem if a domain is forged and used for a large spam run and this zone can be used to help mitigate the fallout from this.

Unlike other blacklists our only inclusion criteria is DSN/MDN messages, we do not consider "Sender Verification" or "Sender Callouts" as backscatter.

Warning

This zone should NEVER be used as a regular DNSBL, it should only ever be applied to messages that have a null Return-Path (e.g. MAIL FROM:<>)

Was this article helpful?

Can’t find what you’re looking for?

Our award-winning customer care team is here for you.

Contact Support