Is FraudBL.org dead?

No!

We have evolved!

FraudBL.org may look unusually quiet if you only visit the public website. Most of the development and daily operation have moved to Tornevall Networks Tools, where FraudBL is now part of a larger DNSBL and abuse-protection platform.

The original FraudBL website remains as a landing page and historical reference. The actual machinery is now running through ToolsAPI at tools.tornevall.net.

From a standalone service to a DNS-first platform

The older FraudBL and DNSBL systems relied heavily on a traditional database API. That model has gradually been replaced by a DNS-first architecture.

Reputation data is now distributed through DNS zones and consumed through ordinary DNS lookups. ToolsAPI manages the underlying records, publication flows, permissions, cache handling and administrative operations.

The primary zones are:

  • dnsbl.tornevall.org
  • bl.fraudbl.org
  • ecom.fraudbl.org

The regular DNSBL handles spam, abuse and other unwanted network activity. FraudBL provides classifications related to phishing, fraud infrastructure and other activity that may cause financial harm. The separate commerce zone is used for classifications connected to e-commerce fraud.

A new API model

The historical DNSBL v5 and API v3 interfaces are now deprecated. They are still documented for migration and compatibility work, although they are no longer the primary integration model.

The current DNSBL API is exposed through ToolsAPI and provides endpoints for:

  • Checking whether an IP address is listed.
  • Validating DNSBL access tokens.
  • Adding, updating and removing records.
  • Submitting bulk operations.
  • Inspecting DNSBL statistics.
  • Receiving specialized reports, including DMARC-based review material.

The API also supports dry-run operations. Integrators can validate permissions, payloads, publication rules and deletion limits without making actual DNS changes.

Safer listing and removal workflows

Clients no longer need to determine every DNS zone or reversed DNS record involved in a removal.

When a removal request is submitted, ToolsAPI performs a live DNS inspection and determines which records currently exist in the relevant zones. It then builds the required DNS operations from the actual published state.

This reduces the risk of incomplete removals, incorrect zone selections and outdated assumptions in external clients.

Delegated tokens can also be restricted through removal guardrails. These controls include CIDR limits, daily limits, request throttling and maximum operation sizes.

FraudBL is still DNS-compatible

Consumers do not need to use the HTTP API for ordinary blacklist checks.

Services can continue querying FraudBL through DNS and decoding the returned 127.0.0.X address as a bitmask. Multiple classifications can be active simultaneously, allowing one address to be marked for several forms of abuse.

The WordPress DNSBL plugin follows this model. It performs direct DNS lookups, keeps a local cache and stores local activity statistics. ToolsAPI is used when additional functionality is needed, such as token validation, administration or removal requests.

Better privacy handling

The rebuilt platform also changes how contextual information is handled.

Older blacklist systems could store more information about why an address or message was flagged. The current design focuses on data minimization. Information must be anonymized and reduced before it reaches the published DNS layer.

Only information required for classification, abuse prevention and fraud protection should be exposed through DNS.

Public statistics and documentation

Tools now includes public DNSBL statistics showing API activity and selected public whitelist information. The documentation describes the current bitmask model, DNS publication rules, token handling, removal limits and integration workflows.

FraudBL.org remains the recognizable home of the FraudBL name. Development, automation and operational control now live inside a broader platform built to handle DNSBL, FraudBL and related reputation services together.

När du får bedrägerimail

Mail header content.

Visste du att du kan få bedrägerimail svartlistade och därmed i längden bidra till ett renare internet? FraudBL tar emot bedrägerimail om de kan levereras i sin helhet. Om du vet med dig att du har fått ett sånt mail kan du skicka det till oss på support@fraudbl.org – glöm bara inte att hela mailet måste vara med, inte bara själva meddelandet. Du kan klicka på bilden till höger för att se ett exempel på det som kallas för mailhuvud..

Det kommer komma en uppdatering på den tidigare instruktionssidan då det finns misstankar om att den måste uppdateras. Annars bör den åtminstone kunna ge ett hum om hur du faktiskt gör.

Läs mer på https://docs.tornevall.net/x/ZoBq för information.

DNSBL & FraudBL rule updates

As of 22 October, we have changed the behaviour of message analyzing.

If a message contains known hosts, discard the message as already listed but reset “deleted”-dates and relist if necessary.

Messages are no longer discarded with a “already listed”. This behaviour was built to save data storage. Data storage is a problem, but we have to live with that even if some cases is automatically solved by our orphan-cleaner (DNSBL-46). So, for each message found as “already listed”, we are incrementing the hostcount. This means that, the more hits from a server the harder rules are applied on the host.

Source: DNSBL-54

FraudBL status

FraudBL is currently up and running and while we are typing this post, we are collecting spam from “phishing sites”. As we are counting, approximately 1200 hosts are flagged “phishing” in our database. In short, this database will get a zone update so we can start using it. What we are actually waiting for is dnsbl.tornevall.org and the last migration steps.

To be continued…

What FraudBL is

Den här sidan finns även översatt på svenska.

FraudBL is an open source DNS Blacklist server, a part of the more common dnsbl.tornevall.org DNS Blacklist. FraudBL stands for Fraud Blacklist. This site itself is a landing page for Tornevall Networks blacklisting services and the real site, where most of our information resides can be reached via Tornevall Networks portal (which is currently under construction). FraudBL is, what tornevall.org is: While dnsbl.tornevall.org blocks regular spam, proxies and webabuse, FraudBL explicitly blocks servers known of sending spam based on phishing or anything else that would cause any economic loss for the receiver.

The purpose of FraudBL is about stopping fraudalent/phishinglike e-mail sent from different servers, that looks like they are sent from banks and others. FraudBL uses a separate spamresolver with the suffix bl.fraudbl.org. However, we are also using dnsbl.tornevall.org and hosts that is considered phishy/fraudalent are marked up with an extra TXT-entry.

To report fraudalent e-mail to us, send the mail content (important: with full header) to spam@fraudbl.org. To extract a message header, you may see a few examples at http://docs.tornevall.net/x/ZoBq how to do this (covers gmail, outlook/hotmail/thunderbird/etc). The goal with this, is to block the server sources of the sent mail, not the sender itself, so it’s actually the “Receved”-headers we are looking for primarilly.

Examples on where spoofed e-mail may come from:

  • Paypal
  • Skatteverket (Sweden)
  • Swedbank (Sweden)
  • Apple/itunes
  • Telia Sonera
  • Nordea (Sweden)
  • Bank of America
  • And many many more…

The site FraudBL is located in Sweden.