Spamhaus Technology and abuse.ch Logo
Solutions
Data
Email & Network
Cyber Threat Intelligence
Resources
About

Rspamd
Plug-in

Rspamd is a free, open-source spam filtering solution, renowned for its precise spam detection. With this spam filtering system and Spamhaus’ real-time DNS blocklists, take your spam filtering capabilities to the next level. The plug-in is ready to access and once configured provides instant email protection.

Ready-made plug-in

No need to build complex integrations — the plugin is easy to install, configure, and maintain.

Enhance spam filtering capability

Block more than 99% of spam with industry leading low false positive rates.

Flexible integration

Adjust the settings for your specific needs and email flow.

Spamhaus Real Time DNSBLs via Rspamd

By combining Spamhaus’ industry-leading threat intelligence data with Rspamd’s spam filtering engine, you gain real-time protection against over 99% of malicious email.

With this plug-in access an additional layer of protection for your email infrastructure, protecting users from threats like spam, phishing and malware.

Minimize security risks

Save on associated remediation costs and protect your reputation.

Reduce operational costs

Block a large amount of unwanted email before it reaches your systems, saving on processing and storage costs.

Free up internal resources

With less time focused on remediation, boost productivity and time available for other issues.

Plug-in details

  • Suitable users

    Anyone using Rspamd 3.x installation on your system.

    You’ll also need access to the real-time DNSBLs via Spamhaus’ Data Query Service (DQS) - this includes non-commercial users with a free DQS account.

  • Access the plug-in

    Go here to access the configuration files for the plug-in and supporting documentation.

  • How the plug-in works

    First, sign up for a Spamhaus DQS account to get your unique API key. There’s a free account for low-volume users. Without a valid API key, the plugin won’t be able to query Spamhaus' data.

    Using the API Key, the plugin connects your Rspamd spam filter to Spamhaus’ DNSBLs via DQS. This enables Rspamd to query Spamhaus’ DNSBLs in real-time to determine if an email’s IP, domain, or other internet resources (including email addresses, malicious files, URLs and, crypto wallets) are listed.

  • Datasets included

    The following data is available to users of the commercial Spamhaus DQS:

    • Bruteforce IPs (AuthBL)

    IP addresses known to host bots using stolen credentials or brute-forcing SMTP-AUTH (and other authentication protocols), helping detect and mitigate ongoing abuse from malicious login attempts.

    • Compromised IPs (Exploits Blocklist)

    IP addresses exhibiting signs of compromise, which can include downloaded malware, security vulnerabilities allowing unauthorized access, etc. Designed to protect networks from malware and spam by preventing connections from these IPs. Available in binary and contextual format.

    • Email Spam IPs (Combined Spam Sources Blocklist)

    Spam-emitting IPs that are direct snowshoe spam sources or senders posing a risk. This includes emails showing indications of an unsolicited nature, sending malicious emails due to a compromise, and other indicators of low reputation or abuse.

    • Highly malicious networks (DROP)

    The worst of the worst malicious traffic IPs - an advisory to “drop all traffic” - with activity directly originating from rogue networks, such as encryption via ransomware, DNS-hijacking, authentication attacks, harvesting, DDoS attacks, and spam campaigns.

    • Low reputation domains (Domain Blocklist)

    Domains and hosts used for suspicious or malicious activity, e.g., those associated with phishing, spam, malware, botnet command and controllers (C2s), and redirector domains; may be owned by malicious actors or have been hijacked. Available in binary and contextual formats.

    • Low reputation resources (Hash Blocklist)

    The worst of the worst IP traffic - it is an advisory to “drop all traffic” from these IPs. DROP seeks out activity directly originating from rogue networks, such as encryption via ransomware, DNS-hijacking and exploit attempts, authentication attacks to discover working access credentials, harvesting, DDoS attacks, and spam campaigns.

    • Malicious network ranges (Spamhaus Blocklist)

    This dataset exposes IPs being observed in a range of adversarial activities, derived through Open Source Intelligence (OSINT) from Spamhaus' most specialized and experienced researchers.

    • Non-mail emitting IPs (Policy Blocklist)

    IPs that should never send email directly to the MX servers of third parties. Networks add and maintain many of these ranges, resulting in strong data efficacy. Spamhaus supplements by identifying end-user IP space that is observed as having high concentrations of botnet zombies.

    • Zero reputation domains (Zero Reputation Domains)

    Newly registered or newly observed domains. These domains are included in this dataset for 24 hours; newly created domains are rarely used for legitimate purposes within 24 hours of registration, which provides a strong indicator of potential malicious behavior.


    For a free non-commercial DQS account, all the datasets listed are available to query, with the exception of Low Reputation Resources (Hash Blocklist).


    Why are there two names for the data?

    We are moving to more transparent naming conventions. However, some organizations have been consuming these datasets for decades. To save any confusion, for old or new users, we’re currently documenting both names.

  • Pricing

    The plugin itself is free to use, and can be accessed here.

    Subscriptions for the commercial DQS is based on monthly and per-second query volume, with final costs provided after the trial based on actual usage. Alternatively please contact our sales team.

    If you are a non-commercial entity or a small business with low query volumes, you may qualify for a Data Query Service account to access our real-time DNSBLs with no subscription costs. Here are the terms related to this service.

Need a
DQS Key?

Get a free 30-day trial of Spamhaus’ real-time DNSBLs to access a DQS Key and start using the Rspamd plug-in. No credit card details required.

Sign up
Speechmarks
Speechmarks

There are a lot of blocklists out there but the only one that’s ever been super trustworthy has been Spamhaus.

Tara Natanson

Manager of ISP Relations , Constant Contact

Trial more data

Data Access

Rsync

Incremental synchronization of binary and contextual datasets to local servers, including access to our entire binary DNS blocklist data. Efficiently transfer data by only copying changes between the source and destination.

Learn More

Data Access

Intelligence API

Integrate context-rich metadata relating to IP and domain reputation to enhance existing data feeds, or consume as an independent data source. Gain additional intelligence to monitor, assess and remediate as required.

Learn More

Data Access

DNS Response Policy Zones

Access our wide variety of DNS Response Policy Zone files to block or redirect access based on your appetite for risk. We provide the data, you set the terms, configurable to your business’ needs and company requirements/policies.

Learn More