Summary

  • ARIN closed ACSP Suggestion 2023.18 as completed on 26 August 2026, saying that investigating abuse of addresses issued under NRPM §4.10 was one focus of a dedicated Internet number resource fraud-and-abuse team.
  • The current Fraud Reporting Process page now expressly includes abuse of Internet number resource policies and misuse of reserved pools, with §§4.4 and 4.10 given as examples.
  • The live public form’s visible instructions name two other situations: resources suspected of having been obtained fraudulently and unauthorized modifications to ARIN records. Its Description prompt repeats those two situations.
  • Nothing in the inspected material proves that a free-text submission about §4.10 would be rejected, ignored or misrouted. The narrower wording is an interface-accountability problem: users should not have to infer that a published category is accepted by a form that does not name it.

The third path appears before the click

A reporter begins with a surprisingly broad invitation. ARIN’s Fraud Reporting Process page says the organisation accepts reports covering fraudulent acquisition of Internet number resources, unauthorized changes to registration records, abuse of Internet number resource policies and misuse of reserved address pools. For the last category, it gives two concrete examples: the micro-allocation pool in NRPM §4.4 and the IPv6-deployment pool in §4.10.

That list matters because it tells a potential reporter what ARIN considers within scope. It is more than a general warning against dishonesty. It names policy abuse as an evidentiary object, and it names reserved pools whose conditions can be assessed against registration, allocation and operational records. The same page then describes a process with email confirmation, a report identifier, confidential investigation and eventual public reporting. It asks for factual and verifiable information. In other words, the page does not merely offer a mailbox; it describes a controlled intake.

The next click changes the vocabulary. The public form opens by asking whether the visitor suspects that Internet number resources were fraudulently obtained or that ARIN records were modified without authorization. Its Description field again asks for the basis for one of those two suspicions. The visible controls captured for this review are a free-text Description, contact fields and a CAPTCHA. The client component contains no reader-visible string naming §4.10, reserved pools, policy abuse or a Report Type selector.

This is not a contradiction in the logical sense. A large free-text box can accept a description of almost anything. Staff can read it, classify it and pass it to the right team. An internal system may add categories that the public never sees. A deliberately simple form can also be good design: it avoids forcing a reporter to make a premature legal or policy classification before the evidence has been examined.

But those possibilities do not erase the public discrepancy. The process page has told the user that a third family of cases is in scope. The form immediately recasts the task as a choice between two named suspicions. A careful reporter can ignore the prompt and write about policy misuse anyway. A less confident reporter may reasonably conclude that they have followed the wrong link, that their concern does not qualify, or that “fraud” requires proof of deceptive acquisition rather than evidence of use outside a pool’s conditions.

The issue is not whether the box is technically capable of receiving the report. It is whether the public journey carries the same scope all the way to submission.

What “completed” established — and what it did not

The history begins with ACSP Suggestion 2023.18, submitted anonymously on 27 October 2023. The submitter asked ARIN to broaden its fraud-reporting tool to cover alleged leasing or other misuse of IPv4 space issued under NRPM §4.10. The allegation in that suggestion remains an allegation; ARIN’s page does not turn it into a finding about any holder.

On 31 October 2023, ARIN said it was evaluating and updating the fraud-reporting process and would keep the suggestion open during that review. On 26 August 2026, ARIN posted its closing response. It said that a dedicated team for Internet number resource fraud and abuse had been formed, that investigation of §4.10 address abuse was one focus of the team’s mandate, and that the language of the Fraud Reporting Process had been amended. The suggestion moved to “completed,” a disposition also shown in ARIN’s closed-suggestions index.

Those statements establish a real institutional change. They connect a policy-specific concern to a named operational mandate, and the current process page carries the expanded language. They do not establish that every customer-facing surface changed at the same time, that the form has no internal routing logic, or that ARIN promised a particular form design. “Completed” is ARIN’s disposition of a community suggestion, not a universal certification of every interface and workflow that a reporter might encounter.

That distinction makes the present gap narrower, and more useful, than a claim of failure. ARIN did not merely acknowledge the suggestion. It identified the team, the focus and the amended public process. The remaining question is whether the last step should echo the scope that the preceding page now publishes.

Why §4.10 is not just another fraud label

NRPM §4.10 reserves a /10 of IPv4 address space to facilitate IPv6 deployment. An applicant must show immediate IPv6-deployment requirements, and earlier allocations or assignments under the section must continue to meet its justification requirements before another one is issued. Those policy conditions make §4.10 a distinct reporting context. Evidence might concern how an allocation is being used, how continuing justification is represented, or whether reserved-purpose conditions remain satisfied. None of that necessarily arrives packaged as a claim that the resources were originally obtained by fraud.

Nor should a public form invite reporters to declare a violation that only an investigation can determine. The better interface is not a prosecutorial checklist. It is a scope-preserving intake. A short line such as “This form also accepts reports about abuse of number-resource policies or reserved pools, including NRPM §§4.4 and 4.10” would carry the process-page promise into the form without asking the visitor to decide the case.

A small optional field could go further: “What does this concern?” with plain choices matching the published categories and an “unsure/other” option. That would improve routing evidence while protecting the reporter from overclassification. Yet even that field is not essential. The minimum repair is parity of language. If ARIN wants one free-text intake for every category, the form should say so.

A form is part of the evidence chain

Institutional reporting channels are often judged by their back-office handling: whether staff confirm receipt, preserve confidentiality, investigate competently and publish aggregate results. The public interface is earlier in the chain. It decides which observations are converted into reports at all.

Wording can filter evidence without rejecting a single submission. When the landing page names policy misuse but the form names only fraudulent acquisition and record tampering, the channel imposes an inference cost. Insiders who know the organisation will treat the Description box as universal. Outsiders must guess. That asymmetry is especially important for number-resource governance, where the relevant facts may sit with operators, brokers, customers or technical staff who do not share ARIN’s internal vocabulary.

The remedy should remain bounded. The public does not need access to reporter identities, confidential evidence, investigative notes or live case status. It does need a stable statement of accepted scope, a consistent form version and a receipt that echoes the category selected or inferred at intake. Those elements make it possible to tell whether a submission entered under the policy-abuse mandate without revealing what the investigation found.

The form capture used here is also time-bounded. It shows the reader-visible component delivered during this review. The hashed software asset can change, and it does not prove what every historical version said. That is another reason to make scope a controlled content object rather than scattered prose: one vocabulary can feed the process page, the form instructions and the acknowledgement receipt, with a version recorded when a report is submitted.

The strongest defence is also the design opportunity

ARIN’s strongest answer is straightforward: the form is intentionally generic, the Description box accepts any relevant concern, and trained staff perform the classification. That may be entirely true. Nothing in the public evidence inspected here disproves it. Simplicity can reduce abandonment, and a visible list of technical policy categories can overwhelm users who only know that something looks wrong.

The answer becomes stronger if the form says one extra sentence: “You may use this form for every category listed in the Fraud Reporting Process, even if you are unsure how to classify your report.” Such a sentence preserves simplicity while removing the inference. It also makes the dedicated team’s expanded mandate legible at the point where evidence is handed over.

The question raised by ACSP 2023.18 was whether §4.10 misuse belonged inside the reporting process. ARIN’s 2026 response says yes. The current process page says yes. The public form should let that answer survive the click.

Sources