I operate several DNS blacklists which are available for anyone to use. They are safe and secure, running from
several diverse nameservers in multiple locations. These DNS blacklists are also reachable via IPv6.
NOTE: The DNS blacklists are now DNSSEC signed with a full chain from root to individual entries.
There are no query limits on this service, and they are used by many people already including several IRC networks.
.tor.dan.me.uk
This DNS blacklist contains ALL tor nodes (entry, transit and exit nodes) - think carefully before choosing to use this list for blocking purposes.
.torexit.dan.me.uk
This DNS blacklist contains only tor EXIT nodes
Updates/Complaints
The tor nodelist is updated every hour automatically from the live tor network.
There is no complaint procedure to have an IP address removed from this list as it will be
automatically removed once the tor node ceases to run (with a maximum of 1 hour delay).
Details on how to use them
To query the DNS blacklist, you must first reverse the IP address. This is called inverse
addressing.
e.g. if the IP was 1.2.3.4, you reverse it to 4.3.2.1 and add on the dns blacklist you require.
e.g. 4.3.2.1.torexit.dan.me.uk
If the IP has a match, the DNS server will respond with an "A" record of 127.0.0.100.
It will also respond with a "TXT" record with extra information as per below:
N:<nodename>/P:<port1[,port2]>/F:<flags>