Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About

MDaemon®
integration

MDaemon® Email Server gives customers greater control and privacy over email. When paired with Spamhaus’ real-time DNS blocklists (DNSBLs), users gain highly efficient, robust, and cost-effective protection against unwanted and malicious traffic.

By enabling MDaemon®’s pre-configured Spamhaus integration, you instantly add an extra layer of security protection.

Block email-borne threats

Block more than 99% of spam with industry leading false positive rates.

Real time updates

As soon as Spamhaus list threats, you are protected.

Simple administration

Easily activate the service within the MDaemon® admin console settings

MDaemon® and Spamhaus Real-Time DNSBLs

With Spamhaus integrated into MDaemon® Email Server, administrators can easily enable an additional layer of email protection against email-borne threats with industry-leading, real time DNSBLs.

Protect you and your organization from incoming email threats, whether it be from hostile domains, IP addresses, phishing emails, or messages containing cryptographic hashes associated with malicious content.

24/7 Protection

As soon as a malicious resource is identified, users are protected.

Save time and avoid user complaints

Adding additional layers of antispam protection means cleaner inboxes, less complaints, and more time to focus on other networking tasks.

Minimize the risk of security incidents

Save on associated remediation costs and the potential loss of reputation.

Integration details

  • Accessing the integration

    Spamhaus’ real-time DNSBLs come pre-configured in the MDaemon® Email Server and can be enabled within the Remote Administration settings.

    These DNSBLs are delivered via the Spamhaus’ Data Query Service (DQS), and you’ll need to create a Spamhaus account as part of the set up process.

    To get started, see "Starting a 30-day free trial of Spamhaus Data Query Service”.

  • Suitable users

    Any MDaemon® Email Server customer can use this integration. Set up is quick, and you can try the data free for 30 days.

  • Included datasets

    The following data is included:

    • Bruteforce IPs (AuthBL)

    IP addresses known to host bots using stolen credentials or brute-forcing SMTP-AUTH (and other authentication protocols), helping detect and mitigate ongoing abuse from malicious login attempts.

    • Compromised IPs (Exploits Blocklist)

    IP addresses exhibiting signs of compromise, which can include downloaded malware, security vulnerabilities allowing unauthorized access, etc. Designed to protect networks from malware and spam by preventing connections from these IPs. Available in binary and contextual format.

    • Email Spam IPs (Combined Spam Sources Blocklist)

    Spam-emitting IPs that are direct snowshoe spam sources or senders posing a risk. This includes emails showing indications of an unsolicited nature, sending malicious emails due to a compromise, and other indicators of low reputation or abuse.

    • Highly malicious networks (DROP)

    The worst of the worst malicious traffic IPs - an advisory to “drop all traffic” - with activity directly originating from rogue networks, such as encryption via ransomware, DNS-hijacking, authentication attacks, harvesting, DDoS attacks, and spam campaigns.

    • Low reputation domains (Domain Blocklist)

    Domains and hosts used for suspicious or malicious activity, e.g., those associated with phishing, spam, malware, botnet command and controllers (C2s), and redirector domains; may be owned by malicious actors or have been hijacked. Available in binary and contextual formats.

    • Low reputation resources (Hash Blocklist)

    The worst of the worst IP traffic - it is an advisory to “drop all traffic” from these IPs. DROP seeks out activity directly originating from rogue networks, such as encryption via ransomware, DNS-hijacking and exploit attempts, authentication attacks to discover working access credentials, harvesting, DDoS attacks, and spam campaigns.

    • Malicious network ranges (Spamhaus Blocklist)

    This dataset exposes IPs being observed in a range of adversarial activities, derived through Open Source Intelligence (OSINT) from Spamhaus' most specialized and experienced researchers.

    • Non-mail emitting IPs (Policy Blocklist)

    IPs that should never send email directly to the MX servers of third parties. Networks add and maintain many of these ranges, resulting in strong data efficacy. Spamhaus supplements by identifying end-user IP space that is observed as having high concentrations of botnet zombies.

    • Zero reputation domains (Zero Reputation Domains)

    Newly registered or newly observed domains. These domains are included in this dataset for 24 hours; newly created domains are rarely used for legitimate purposes within 24 hours of registration, which provides a strong indicator of potential malicious behavior.


    Why does the data have two labels?

    We are moving to more transparent naming conventions. However, some organizations have been consuming these datasets for decades. To save any confusion, for old or new users, we’re currently documenting both names.

  • Starting a 30-day free trial of Spamhaus Data Query Service

    To gain FREE unlimited access for 30 days to the Spamhaus’ Data Query Service and MDaemon® integration, simply complete this form. You’ll receive an email asking you to verify your email address. If you haven’t already, you’ll be prompted to create an account with Spamhaus.

    What happens next?

    Once verified, log in to the Spamhaus Customer portal to view your API key, to input into MDaemon® ’s Remote Administration page.

    Overall this process should take just minutes and as soon as you reach the last step of inputting your query key into MDaemon®‘s platform, your email stream will be immediately protected in real time.

    Need help?

    If you have any questions, please add them to the comments box below. Once you gain access to the data, technical support is available via our Customer Portal.

    Trial duration

    A free trial lasts for 30 days. You’ll receive an email notification before the trial expires. To continue accessing the services, simply log into the Customer Portal, and click “request quote” to upgrade to a paid subscription.

Ready to start
your free trial?

Get a free 30-day trial to the Mdaemon® Email Server integration with Spamhaus’ real-time DNSBLs. No credit card or payment details required.

Sign up
Speechmarks
Speechmarks

There are a lot of blocklists out there but the only one that’s ever been super trustworthy has been Spamhaus.

Tara Natanson

Manager of ISP Relations, Constant Contact

Trial more data

Data Access

Rsync

Incremental synchronization of binary and contextual datasets to local servers, including access to our entire binary DNS blocklist data. Efficiently transfer data by only copying changes between the source and destination.

Learn More

Data Access

Intelligence API

Integrate context-rich metadata relating to IP and domain reputation to enhance existing data feeds, or consume as an independent data source. Gain additional intelligence to monitor, assess and remediate as required.

Learn More

Data Access

DNS Response Policy Zones

Access our wide variety of DNS Response Policy Zone files to block or redirect access based on your appetite for risk. We provide the data, you set the terms, configurable to your business’ needs and company requirements/policies.

Learn More