🏆 ✓ Trusted since 1992 - 34 Years of Excellence

🗺️ Central Mail Blacklist - Just £1/Month

Real-time spam intelligence platform powered by CentralMail.co.uk. Live threat map, honeypot network monitoring thousands of domains, blacklists updated every 15 minutes. Professional spam protection with instant IP/domain blocking.

* All prices include UK VAT at 20% • Cancel anytime • No setup fees • Instant activation

15-Minute Updates Real-Time Intelligence
🌍
Live Threat Map Geographic Tracking
🍯
Honeypot Network Thousands of Domains
📊
132K+ IPs Tracked Daily Consolidated List

🎯 Professional Spam Intelligence Platform

Central Mail Blacklist is a real-time spam threat intelligence platform operated by CentralMail.co.uk for just £1 per month. Our sophisticated honeypot network spans thousands of monitored domains, capturing and analyzing spam attempts in real-time from sources worldwide. Unlike static blacklists updated daily or weekly, our multi-vector detection system provides blacklist updates every 15 minutes, ensuring maximum protection against emerging threats. The platform includes direct honeypot monitoring across unused domains configured as spam traps, open relay detection simulating vulnerable mail servers to catch exploitation attempts, and production mail analysis from real-world email security appliances. All intelligence feeds into a live threat map showing geographic origins and attack patterns. Perfect for mail server administrators, hosting providers, security professionals, and anyone requiring cutting-edge spam protection with instant threat identification and blocking.

Real-Time Threat Intelligence

15-Minute Blacklist Updates

Blacklists update every 15 minutes for maximum protection. New spam sources are identified and blocked within minutes of first detection, not hours or days like traditional lists.

🗺️

Live Threat Map

Interactive geographic visualization showing real-time spam origins worldwide. Watch attacks as they happen with country-level threat correlation and attack pattern analysis.

🍯

Massive Honeypot Network

Thousands of monitored domains acting as spam traps. Unused domains configured to attract and catalog unsolicited communications from spammers worldwide.

🔓

Open Relay Detection

Simulated open relay services capture spammers attempting to exploit mail servers for unauthorized relay. Identifies abuse attempts instantly.

📧

Production Mail Analysis

Real-time feed from production email security appliances forwarding all detected spam for comprehensive analysis and immediate blacklist addition.

🌍

Geographic Intelligence

IP geolocation tracking identifies spam origins by country. Threat correlation shows which regions produce the most attacks and emerging patterns.

🧠

Behavioral Analysis

Automated threat level assessment based on spam frequency, domain patterns, attack vectors, and historical behavior. Multi-dimensional threat scoring.

📊

Multiple Blacklist Formats

Distributed in formats for seamless integration: Postfix, SpamAssassin, raw IP lists, domain lists, consolidated daily lists. Ready-to-use configurations provided.

⚙️ Technical Specifications

Powered by CentralMail.co.uk spam intelligence platform

Feature Specification
Update Frequency Every 15 minutes (real-time streaming + scheduled consolidation)
Daily Consolidated List 132,360+ IPs updated at 0200 UTC daily
Real-Time Stream 996+ IPs in honeypot stream (continuously updated)
Blocked Domains 706+ malicious domains identified
Honeypot Network Thousands of monitored domains worldwide
Detection Methods Honeypots, open relay traps, production mail analysis
Geographic Tracking IP geolocation with country-level threat correlation
Threat Levels Critical, High, Medium, Low classification
Live Threat Map Real-time visualization at centralmail.co.uk
Dashboard Refresh Auto-refresh every 60 seconds
Attack Analytics 24-hour activity analysis, peak hour tracking, trends
Response Time Zero latency - threats flagged within seconds
Data Sources Honeypots (682), Relay attempts (548), EFA production feed
AbuseIPDB Integration Contributing data to global abuse database
IP List Format Plain text, one IP per line, HTTP accessible
Domain List Format Plain text, one domain per line
Postfix Integration Pre-formatted postfix-centralmail.txt with hash format
SpamAssassin Integration Domain list formatted for blacklist_from rules
Automated Updates Cron job recommended every 15 minutes
IP Status Check Web interface to verify if your IP is blacklisted
API Access HTTP downloads, automated retrieval supported
Platform Compatibility All mail servers supporting DNSBL/RBL integration
Data Retention Historical threat data maintained
False Positive Rate Extremely low - verified spam sources only
Support 24/7 technical support for integration

🔧 How Central Mail Blacklist Works

🍯 Honeypot Network Detection

We operate thousands of unused domains specifically configured as spam traps. These domains receive no legitimate mail, so any attempt to send email to them is definitively spam. When spammers send to these honeypot addresses, their IPs are immediately logged, analyzed, and added to our real-time blacklist stream. This provides instant identification of new spam sources before they can harm production mail servers.

🔓 Open Relay Exploitation Traps

Our platform simulates open relay mail servers - a common target for spammers who search for vulnerable servers to relay their spam. When spammers attempt to exploit these "open relays," we capture their IPs, relay targets, and attack patterns. This identifies both spam sources and the domains they're trying to reach, providing comprehensive threat intelligence.

📧 Production Mail Intelligence

Real production email security appliances (EFA) forward all spam they detect directly to our analysis system. This provides insight into attacks against real mail infrastructure, capturing spam that targets actual users. The combination of honeypots, relay traps, and production feeds creates multi-vector detection that identifies threats from multiple angles.

🌍 Geographic Threat Mapping

Every captured spam source is geolocated to determine country of origin. Our live threat map visualizes attacks geographically in real-time, showing which countries are producing the most spam, emerging threat patterns, and attack intensity by region. This geographic intelligence helps identify coordinated campaigns and regional spam operations.

⚡ Real-Time Streaming Updates

Unlike traditional blacklists updated daily, our honeypot and relay trap data streams in real-time with zero latency. New threats are flagged within seconds of detection. For operational consistency, we also consolidate all sources into master lists updated at 0200 UTC daily. You can choose between 15-minute automated updates (recommended) or daily updates depending on your needs.

📊 Threat Analysis & Scoring

Sophisticated algorithms analyze each spam source across multiple dimensions: attack frequency, number of targeted domains, historical patterns, geographic correlation, and behavioral indicators. Threats are automatically classified as Critical, High, Medium, or Low severity. This intelligent scoring helps prioritize response to the most dangerous sources.

📥 Available Blacklist Feeds

🚫
Honeypot IP Stream (996 IPs)
Real-time confirmed spam IPs from honeypot network
http://blacklist.centralmail.co.uk/ips.txt
🌐
Honeypot Domain Stream (706 domains)
Malicious domains identified through honeypot monitoring
http://blacklist.centralmail.co.uk/domains.txt
📊
Consolidated Daily List (132,360 IPs)
Master list combining all sources, updated 0200 UTC daily
http://blacklist.centralmail.co.uk/ips-combined.txt
📈
Open Relay Targets (20 domains, 548 hits)
Domains targeted by spammers for relay exploitation
http://blacklist.centralmail.co.uk/relay-targets.txt
📧
Postfix Pre-Formatted List
Ready-to-use Postfix hash format for instant integration
http://blacklist.centralmail.co.uk/postfix-centralmail.txt
🗺️
Live Threat Map
Interactive real-time visualization of global spam attacks
https://centralmail.co.uk/threat-map.php

🔧 Quick Integration Guide

📧 Postfix Integration

1. Download pre-formatted list: wget http://blacklist.centralmail.co.uk/postfix-centralmail.txt -O /etc/postfix/centralmail_blacklist

2. Add to main.cf: smtpd_client_restrictions = check_client_access hash:/etc/postfix/centralmail_blacklist

3. Hash and reload: postmap /etc/postfix/centralmail_blacklist && postfix reload

📧 SpamAssassin Integration

1. Download domain list: wget http://blacklist.centralmail.co.uk/domains.txt

2. Add to local.cf: blacklist_from *@domain.com (for each domain)

3. Restart SpamAssassin service

⏰ Automated Updates (Recommended)

Set up cron job to download lists every 15 minutes for maximum protection:

*/15 * * * * wget http://blacklist.centralmail.co.uk/ips.txt -O /etc/mail/blacklist.txt && postmap /etc/mail/blacklist.txt && postfix reload

Perfect For

🖥️
Mail Server Administrators
Protect production mail servers with real-time threat intelligence
☁️
Hosting Providers
Defend customer mail infrastructure against emerging spam threats
🏢
Enterprise IT Departments
Enterprise-grade spam protection with geographic threat visibility
🔒
Security Professionals
Real-time threat intelligence for proactive security monitoring
📊
Security Researchers
Study spam patterns, geographic origins, attack methodologies
🌐
ISPs & Network Operators
Protect network infrastructure with continuously updated blacklists

Frequently Asked Questions

How often are the blacklists updated?
Our real-time honeypot and relay streams update continuously with zero latency - new spam sources are flagged within seconds of detection. For automated integration, we recommend downloading blacklists every 15 minutes via cron job. Additionally, a comprehensive consolidated list combining all sources is generated daily at 0200 UTC. You get both real-time protection and daily comprehensive coverage.
What is the live threat map?
The live threat map at centralmail.co.uk provides real-time geographic visualization of spam attacks worldwide. Watch attacks as they happen, see which countries are producing the most spam, identify emerging patterns, and track attack intensity by region. The map updates continuously showing the latest threats detected across our honeypot network, relay traps, and production mail feeds.
How does the honeypot network work?
We operate thousands of unused domains specifically configured as spam traps. These domains receive no legitimate mail whatsoever, so any email attempt is definitively spam. When spammers send to honeypot addresses, their IPs are instantly logged and blacklisted. This provides early detection of new spam sources before they can harm production servers. Combined with open relay traps and production mail analysis, we capture spam from multiple angles.
What makes this different from other blacklists?
Most blacklists update once daily or even less frequently. Our platform provides 15-minute update intervals with real-time streaming for immediate threat detection. We operate thousands of honeypot domains plus open relay traps plus production mail feeds - multi-vector detection that traditional blacklists lack. The live threat map provides geographic visibility other lists don't offer. You get cutting-edge protection, not yesterday's threats.
Can I integrate this with my existing mail server?
Yes, easily. We provide lists in multiple formats: raw IP lists, domain lists, pre-formatted Postfix hash files, and SpamAssassin-compatible domain lists. Integration with Postfix takes about 5 minutes. SpamAssassin integration is similarly straightforward. We provide exact commands and configuration examples. Works with all mail servers supporting standard blacklist integration.
What is the false positive rate?
Extremely low. Our honeypot domains receive zero legitimate mail, so any attempt is verified spam. Open relay traps similarly only catch abuse attempts. Production mail feeds are pre-filtered by security appliances. Multi-stage analysis algorithms score threats before blacklisting. We only list confirmed spam sources with high confidence, not borderline cases. False positives are rare and quickly resolved.
How many IP addresses are in the blacklist?
The real-time honeypot stream contains approximately 996 IPs continuously updated. The daily consolidated master list combining all sources contains 132,360+ IPs and is generated at 0200 UTC every day. We also track 706+ malicious domains and 548 relay attempt IPs. These numbers change constantly as new threats emerge and old ones age out.
What if my IP is mistakenly blacklisted?
Use our web interface at centralmail.co.uk to check your IP status. If legitimately blacklisted due to misconfiguration or compromise, fix the underlying issue first (stop the spam), then contact support for delisting consideration. We investigate all delisting requests. However, if your IP appears in our honeypots or relay traps, it definitively sent spam - the evidence is clear.
Do you contribute to other blacklists?
Yes, we're an active contributor to AbuseIPDB, the global IP address abuse database. Our threat intelligence helps protect the broader internet community beyond just our subscribers. When we detect spam, we report it to AbuseIPDB so other security systems can benefit from our findings.
Can I see historical threat data?
Yes, the platform maintains historical threat data including 24-hour activity analysis, peak hour tracking, trending, and attack pattern evolution. The dashboard shows total threats, active hours, average per hour, and threat level distribution over time. This helps identify patterns and anticipate future attacks.

Ready for Real-Time Spam Protection?

Join the fight against spam with live threat intelligence

£1/month
Get Central Mail Blacklist →

No contracts • Cancel anytime • Updates every 15 minutes