An S3 Policy to Block Semalt Referral Traffic

A lot of people have noticed shit tons of ferferral spam from and their various other domains.

It’s fucking annoying.

I found a short S3 policy here that blocked from accessing static sites hosted on S3 and adapted it to include larger list of all know domains as well as some from my logs.

I created a repo for the policy and you can find it here.


The policy blocks variations and subdomains of the given sites: ie,,,,


Copy and past the contents of blocklist.txt to your S3 bucket policy and change the two instances of YOURBUCKETNAME to the actual name of your bucket.


The following sites are blocked: