Over the past few years, while managing several mail servers — initially under cPanel and later under Enhance — I have been collecting a large amount of real-world data from Rspamd and Postfix logs, which I now apply within cPFence.
To help strengthen spam and phishing protection, I have compiled three curated blocklists that can be freely used to enhance the security of your servers and your clients:
Spam Domains List – domains frequently associated with spam, phishing, and disposable email services
Spam IP Ranges List – IP networks repeatedly observed sending abusive or fraudulent email traffic
Spam Email Addresses List – individual sender addresses involved in mass unsolicited campaigns or impersonation attempts
In addition, I am building a Spam ASN Blacklist (Autonomous System Numbers). That list is still relatively sparse at the moment; I am validating ASN entries daily and will add them progressively. The ASN blacklist will be made available here as it grows.
All lists are continuously reviewed and refined to exclude legitimate services (Gmail, Outlook, iCloud, ProtonMail, and others), reducing the risk of false positives. They are manually updated and based on real-world abuse patterns observed over time.
Where to Use
These lists can be applied directly in the following cPFence sections:
Access
You can access all current lists here: https://gist.github.com/webdighost
If any users or administrators are interested, you are welcome to use these lists to improve the protection of your systems and clients. The goal is simple: to make email cleaner and safer for everyone using cPFence.