DEV Community

zihuama
zihuama

Posted on Originally published at pureip.app

Two Chinese cloud providers have the same broken IP metadata. One is 6x more likely to be blacklisted.

Tencent Cloud and Alibaba Cloud look identical on paper. Both assign IPs with essentially no reverse DNS — Tencent at 29/30 missing, Alibaba at 30/30. Neither publishes a registrant organisation in RDAP — every single Tencent IP in this sample (30/30) returns no registrant on record, the only provider of the twelve at 100%.

Their blocklist rates are not identical.

Provider PTR missing No registrant On a blocklist
Tencent Cloud 29/30 30/30 6/30 (20%)
Alibaba Cloud 30/30 18/30 1/30 (3.3%)

Six times the listing rate, from two providers whose IP metadata is equally broken.

Metadata cannot tell them apart

Everything you can look up without querying a blocklist — PTR record, RDAP registrant, abuse contact — comes back equally empty for both. Tencent publishes an abuse role on 10/30 of its IPs, Alibaba on 12/30. Statistically indistinguishable.

If you were screening a VPS by checking its reverse DNS and WHOIS, you would have no way of telling the Tencent range from the Alibaba range. One carries six times the blocklist risk.

The listings are scattered, not network-wide

All six of Tencent's listed IPs appear on exactly one list — dnsbl.spfbl.net — the same single automated list that dominates the entire dataset (41 of 47 listed IPs across all 12 providers).

But unlike RackNerd, whose 25 listed IPs spread across 25 different /24 blocks look like one operator's policy applied network-wide, Tencent's six listings sit in six separate /24 ranges with no neighbours listed. That pattern reads as individual instances doing something that triggered one automated list, not a network-level decision.

The "Chinese IPs are dirty" assumption doesn't hold either

Pooling the two Chinese providers against the other ten:

IPs Listed Rate
Tencent + Alibaba 60 7 11.7%
Other 10 providers 300 40 13.3%

The Chinese providers come in slightly cleaner than the rest of the sample. Whatever explains Tencent's 6/30, it is not the country.

What to actually check

Neither reverse DNS nor RDAP records will tell you whether an IP is clean. The only query that answers the question is the blocklist query itself.

  1. Check the blocklists directly — all eight, not one. A single listing from dnsbl.spfbl.net means something different from a listing on SpamCop or UCEProtect.
  2. Check how many lists. In this dataset no IP appears on more than one list — a single listing is the norm, and 87% of all listings trace back to SPFBL alone.
  3. Ignore PTR and registrant as reputation signals. They describe how the provider provisions IPs, not how the IP has been used.

Method

360 IPs, 30 per provider, across 12 providers: RackNerd, BandwagonHost, Vultr, DigitalOcean, Linode, Hetzner, OVH, Contabo, Oracle Cloud, Alibaba Cloud, Tencent Cloud, and DMIT.

PTR looked up via direct DNS query, classified as named or none. Blocklists checked against 8 public DNSBLs: all.s5h.net, dnsbl-1.uceprotect.net, bl.spamcop.net, dnsbl.dronebl.org, dnsbl.spfbl.net, hostkarma.junkemailfilter.com, psbl.surriel.com, and bl.blocklist.de. RDAP queried against the relevant registry.

Full data: pureip.app/research/vps-audit-2026-09/en/

Blocklist check for any specific IP: pureip.app

Top comments (0)