Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this. 172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL? ~Seth
Seems to be a Cloudflare issue. Radioactive network: About the DROP list Don't Route Or Peer (DROP) lists the worst of the worst IP traffic. It is an advisory “drop all traffic”, containing IP ranges which are so dangerous to internet users that Spamhaus provides access to anyone who wants to add this layer of protection, free of charge. ~ Matt On Thu, Sep 17, 2026 at 4:36 PM Seth Mattinen via NANOG < nanog@lists.nanog.org> wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
~Seth _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/2UWHHVZQ...
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
These are your only complaints with Cloudflare hosting? I think of Cloudflare as the Mos Eisley of the Internet. Cloudflare has made the decision that getting paid for hosting abuse (spammers, spamvertized content, etc.) is preferable to turning that business away to other providers...because let's face it, if Cloudflare doesn't host the content, someone else will get paid to host it. Also, I find it amusing that Cloudflare appears to be hosting someone/something that presumably is sending spam masquerading as *.googleusercontent.com. googleusercontent.com (i.e. Google Cloud) seems to have a serious spammer infestation that they either can't or won't do anything about. Initially, I thought it might be an exploit of some commonly used software across different customers, but I've seen enough now to hop to the conclusion that it's just a spammer abusing random 3rd party domains in their from addresses. i.e. spams claiming to be from support@amazon.com, support@linux.org, support@wikipedia.org. Coincidentally, I got tired of seeing their spam today and wrote a custom Spamassassin rule to start blocking it at SMTP time. ---------------------------------------------------------------------- Jon Lewis, MCP :) | I route Blue Stream Fiber, Sr. Neteng | therefore you are _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________
On 9/17/26 14:08, Jon Lewis wrote:
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
These are your only complaints with Cloudflare hosting?
I don't have a complaint. A customer brought this issue up, so I am just curious how everyone feels about things like this today. The customer feels one way since they pay Cloudflare (it's not me). I'm in the middle because I've used the DROP list for well over two decades as a border filter, before companies like Cloudflare were founded, but over time if the DROP list ends up full of "too big to care" listings, then that makes its utility less than what it once was. ~Seth
I punt most phishing/fraud emails I receive through Cisco Spamcop. Out of 15 or so I received today, the phishing website appeared to be on Cloudflare. Spamcop reports that Cloudflare does not accept their reports, so those just go to /dev/null Gerry On 17 Sep 2026, at 15:35, Seth Mattinen via NANOG wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
~Seth _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/2UWHHVZQ...
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
On 9/17/26 14:08, Jon Lewis wrote:
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
These are your only complaints with Cloudflare hosting?
I don't have a complaint. A customer brought this issue up, so I am just curious how everyone feels about things like this today. The customer feels one way since they pay Cloudflare (it's not me).
I'm in the middle because I've used the DROP list for well over two decades as a border filter, before companies like Cloudflare were founded, but over time if the DROP list ends up full of "too big to care" listings, then that makes its utility less than what it once was.
Ah, so you and Cloudflare have a mutual customer being impacted by their use of a Cloudflare IP in one of those ranges? Have you suggested that they complain to Cloudflare and suggest to Cloudflare that they "clean up their network" and reputation? Assuming the listings are legitimate, I don't see how the IP space belonging to a "too big to care" network makes DROP any less relevant. Would you really want Spamhaus to make exceptions and turn a blind eye to abuse hosting for the top hosting providers? That seems like it'd make DROP less effective/useful. But that's only if the listings are legit. ---------------------------------------------------------------------- Jon Lewis, MCP :) | I route Blue Stream Fiber, Sr. Neteng | therefore you are _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________
On 9/17/26 15:17, Jon Lewis wrote:
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
On 9/17/26 14:08, Jon Lewis wrote:
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
These are your only complaints with Cloudflare hosting?
I don't have a complaint. A customer brought this issue up, so I am just curious how everyone feels about things like this today. The customer feels one way since they pay Cloudflare (it's not me).
I'm in the middle because I've used the DROP list for well over two decades as a border filter, before companies like Cloudflare were founded, but over time if the DROP list ends up full of "too big to care" listings, then that makes its utility less than what it once was.
Ah, so you and Cloudflare have a mutual customer being impacted by their use of a Cloudflare IP in one of those ranges? Have you suggested that they complain to Cloudflare and suggest to Cloudflare that they "clean up their network" and reputation?
They already tried to work with Cloudflare and were told that "the resolution is for all of their IPs to be specifically allowed." ~Seth
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
Ah, so you and Cloudflare have a mutual customer being impacted by their use of a Cloudflare IP in one of those ranges? Have you suggested that they complain to Cloudflare and suggest to Cloudflare that they "clean up their network" and reputation?
They already tried to work with Cloudflare and were told that "the resolution is for all of their IPs to be specifically allowed."
That's certainly an option. However you're consuming DROP, you should be able to whitelist IPs or reject some of the DROP data. If that's really Cloudflare's position (from the top...not just what some low level support person suggested), then that's indicative of their problem. i.e. That they seem to operate under the belief that there's no form of Internet abuse too offensive for them to host. It seems to me, that's exactly what DROP is for and the solution is for more networks to use DROP. ---------------------------------------------------------------------- Jon Lewis, MCP :) | I route Blue Stream Fiber, Sr. Neteng | therefore you are _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________
Might also be worth mentioning to your customer that while you can potentially unblock the subnets for your network, they will still be blocked on other networks if they have users elsewhere. On Thu, Sep 17, 2026, 18:53 Jon Lewis via NANOG - nanog at lists.nanog.org < nanog@lists.nanog.org> wrote:
On Thu, 17 Sep 2026, Seth Mattinen via NANOG wrote:
Ah, so you and Cloudflare have a mutual customer being impacted by their use of a Cloudflare IP in one of those ranges? Have you suggested that they complain to Cloudflare and suggest to Cloudflare that they "clean up their network" and reputation?
They already tried to work with Cloudflare and were told that "the resolution is for all of their IPs to be specifically allowed."
That's certainly an option. However you're consuming DROP, you should be able to whitelist IPs or reject some of the DROP data.
If that's really Cloudflare's position (from the top...not just what some low level support person suggested), then that's indicative of their problem. i.e. That they seem to operate under the belief that there's no form of Internet abuse too offensive for them to host. It seems to me, that's exactly what DROP is for and the solution is for more networks to use DROP.
---------------------------------------------------------------------- Jon Lewis, MCP :) | I route Blue Stream Fiber, Sr. Neteng | therefore you are _________ http://www.lewis.org/~jlewis/pgp for PGP public key_________ _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/P5MUTNNC...
It's your choice to obey the Spamhaus DROP list or not. If they are blocking things you want to talk to, that's a good indication you should ignore the DROP list. If a third party is blocking things you want to talk to based on this list, you'd have to talk to that third party. You are free to also talk to Spamhaus, but they're very stubborn. This isn't the only incident with Spamhaus listing things that should not be listed, and it isn't the only incident of someone attacking Cloudflare as a whole (see: Italy, Spain...). "Might makes right" refers to people using the list versus ignoring it. Obviously nobody but Spamhaus controls the Spamhaus list. And nobody but, say, Telstra, controls whether Telstra is blocking packets to destinations on the list. Telstra's customers may or may not have a cause of legal action if they want to communicate with someone on the list and Telstra refuses to unblock them. If /you/ have contractual obligations requiring you to honour the list, well... maybe obey the list for those customers only, and make it their problem. On 17/09/2026 22:35, Seth Mattinen via NANOG wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
~Seth _______________________________________________ NANOG mailing list https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/2UWHHVZQ...
It's your choice to obey the Spamhaus DROP list or not. If they are blocking things you want to talk to, that's a good indication you should ignore the DROP list.
This. Your network's needs will not always align perfectly with the reasons a 3rd party added something to a block list. If you're going to use these things, you can't just take them blindly and not have the ability to modify for your own reasons. On Fri, Sep 18, 2026 at 1:22 PM Kevin Tillery via NANOG < nanog@lists.nanog.org> wrote:
It's your choice to obey the Spamhaus DROP list or not. If they are blocking things you want to talk to, that's a good indication you should ignore the DROP list.
If a third party is blocking things you want to talk to based on this list, you'd have to talk to that third party. You are free to also talk to Spamhaus, but they're very stubborn.
This isn't the only incident with Spamhaus listing things that should not be listed, and it isn't the only incident of someone attacking Cloudflare as a whole (see: Italy, Spain...).
"Might makes right" refers to people using the list versus ignoring it. Obviously nobody but Spamhaus controls the Spamhaus list. And nobody but, say, Telstra, controls whether Telstra is blocking packets to destinations on the list. Telstra's customers may or may not have a cause of legal action if they want to communicate with someone on the list and Telstra refuses to unblock them. If /you/ have contractual obligations requiring you to honour the list, well... maybe obey the list for those customers only, and make it their problem.
On 17/09/2026 22:35, Seth Mattinen via NANOG wrote:
Cloudflare has IP ranges all the way up on the Spamhaus DROP list. Cloudflare says they cannot control this.
172.70.206.0/23 (Spamhaus SBL687772) 512 addresses 172.70.214.0/23 (Spamhaus SBL687314) 512 addresses
Is Cloudflare in a "might makes right" position, or should someone be working to resolve the issues causing the SBL?
~Seth _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/2UWHHVZQ... _______________________________________________ NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/message/UZVKX2WM...
On 9/18/26 10:22, Kevin Tillery via NANOG wrote:
It's your choice to obey the Spamhaus DROP list or not. If they are blocking things you want to talk to, that's a good indication you should ignore the DROP list.
If a third party is blocking things you want to talk to based on this list, you'd have to talk to that third party. You are free to also talk to Spamhaus, but they're very stubborn.
In any case, since I first mentioned it the two listings have since been removed. It wasn't anything I did though, unless someone is reading this and silently pulled some string behind the curtain. ~Seth
participants (7)
-
Gerry Boudreaux -
Jon Lewis -
Kevin Tillery -
Matt Vernhout -
nanog.org@junk-mail.us -
Seth Mattinen -
Tom Beecher