|
![]() |
||||
|
The Spamhaus Don't Route Or Peer List DROP (Don't Route Or Peer) is an advisory "drop all traffic" list, consisting of stolen 'hijacked' netblocks and netblocks controlled entirely by professional spammers. DROP is a tiny subset of the SBL designed for use by firewalls and routing equipment. The DROP list will not include any IP address space under the control of any legitimate network - even if being used by "the spammers from hell". DROP will only include netblocks allocated directly by an established Regional Internet Registry (RIR) or National Internet Registry (NIR) such as ARIN, RIPE, AFRINIC, APNIC, LACNIC or KRNIC or direct RIR allocations illicitly taken from the original allocatee, that is, the troubling run of "hijacked" IP address blocks that have been snatched away from their original owners (which in most cases are long dead corporations) and are now controlled by spammers or netblock thieves who resell the space to spammers. When implemented at a network or ISP's 'core routers', DROP will help protect the network's users from spamming, scanning, harvesting, DNS-hijacking and DDoS attacks originating on rogue netblocks. Spamhaus strongly encourages the use of DROP by tier-1s and backbones. See the DROP FAQ for information on use and implementation. DROP is currently available only as a simple text list but may be available in the future by BGP, announced via an Autonomous System Number (ASN). DROP users could then choose to peer with that ASN to null those prefixes as being ranges for which they do not wish to route traffic. |
Almost all allocations change over time. Please check regularly to ensure you have the latest version of the DROP list. The DROP list should not be imported into your networks filters and forgotten about. If you do not keep this type of filter data up to date, over time you will eventually encounter problems reaching areas of the Internet if allocations listed in an old version of the DROP list get reassigned to new networks. Before applying any filters or blocks to your network always carefully consider the ramifications of such filters. |
|