
Blacklists have their place for detecting and identifying malicious content and activity, with the whole signature-based malware detection industry effectively being built around the concept that blacklists are reliable mechanisms. <A HREF="http://www.theregister.co.uk/2007/07/08/blacklists_are_baaad/">The only problem is that they aren't.</A>
They certainly are an important element of security models, but the last couple of decades of security research has shown that they quickly become ineffective in the face of a rapidly evolving threat.
Blacklists of known spam-generating IPs and malware-serving sites, we start to see significant problems emerge with this particular approach to protection.
Many mail server administrators will have encountered at least one period where they have found their IP on an RBL (Real Time Block List) alongside IPs that have seen to be spewing spam across networks (or they could have just had AOL mailing list subscribers who find it easier to report as spam than unsubscribe from something they manually subscribed to). With the use of dynamic IP addresses and virtual hosts, many have found that if they have a bad network neighbor, they can be hit with the same blocking (we've had it happen a few times) from indiscriminate RBL maintainers.
Even important registries are not immune from arbitrary blockage and ongoing annoyance from poorly developed RBLs.