How do you include high-risk domains? So, how is this balcklist created? Only manually or is there any automatic process? If yes, how does it choose high-risk domains?
It’s a manual process with a tool assist. We tweaked the tool a little bit, which may have led to @pocketapocketa’s domain being included where it wasn’t previously.
That definitely shouldn’t be on the list. Looks like we have a bug where SQL errors (e.g. a connection problem or a timeout) when checking the blacklist get turned into “Name is blacklisted.” This is obviously wrong and confusing. I’ve filed a bug, and we’ll fix: https://github.com/letsencrypt/boulder/issues/1491. Thanks for reporting!