• Blocked subcodes added

    December 14, 2015

    Today we added blocked notifications for use in SpamAssassin. This allows people to see if they are beeing blocked by policy/overusage.

    #SURBL BLOCK RULES - Bit 1 means your DNS has been blocked and this rule should be triggered to notify you.
    urirhssub       SURBL_BLOCKED        A   1
    body            SURBL_BLOCKED   eval:check_uridnsbl('SURBL_BLOCKED')
    describe        SURBL_BLOCKED   ADMINISTRATOR NOTICE: The query to SURBL was blocked.  See for more information.
    tflags          SURBL_BLOCKED   net noautolearn

    This will help notify people if they should subscribe to the paid service we offer.

SURBL Data Feed Request

SURBL Data Feeds offer higher performance for professional users through faster updates and resulting fresher data. Freshness matters since the threat behavior is often highly dynamic, so Data Feed users can expect higher detection rates and lower false negatives.

The main data set is available in different formats:

Rsync and DNS are typically used for mail filtering and RPZ for web filtering. High-volume systems and non-filter uses such as security research should use rsync.

For more information, please contact your SURBL reseller or see the references in Links.

Sign up for SURBL Data Feed Access.

  • Sign up for data feed access

    Direct data feed access offers better filtering performance with fresher data than is available on the public mirrors. Sign up for SURBL Data Feed Access.

  • Applications supporting SURBL

  • Learn about SURBL lists