Summary
- Draft 6 made an
abuse-crecord mandatory for specified number-resource objects and described an initial validation period of no more than 15 days, an escalation to other LIR contacts for a second period of no more than 15 days, validation at least every six months and revalidation in specified circumstances. It did not itself state a penalty for failure. - The proposal’s language moved beyond simple mailbox delivery when its validation objectives referred to regular monitoring, measures taken and a response to reports. Those matters must not be mistaken for proof that an abuse allegation was true or that a substantive response was correct.
- The online AFRINIC32 discussion and subsequent mailing-list notice preserved five distinct objection clusters. Virtual participation supplied relevant evidence and criticism, but neither attendance nor message writers provided a representative denominator or sovereign mandate.
- A proportionate alternative is a narrow validation receipt: identify the object and contact tested, record the method and time, give dated notice and a correction window, log the correction and re-test, then publish only the validation state. Complaint merits and punitive action remain outside a private registry bookkeeper’s determination.
L3 — What Draft 6 actually asked a mailbox to prove
On 5 August 2020, a sixth version of an abuse-contact proposal entered AFRINIC’s policy process. The archived proposal page identifies it as AFPUB-2018-GEN-001-DRAFT06, version 6.0, and says it would amend article 8.0 of the Consolidated Policy Manual. Six weeks later, on 17 September, the proposal was discussed at the online AFRINIC32 meeting. On 21 September, the co-chairs reported to the mailing list that there was no rough consensus and set out five clusters of objection.
That sequence is more than scene-setting. The proposal was being read in a changed participation environment: an online session followed by written interventions, rather than a physical room that could at least be observed as one bounded gathering. The digital medium did not make a participant’s expertise less real, an objection less serious or the discussion invalid. It did, however, make disciplined record-keeping indispensable. A video audience is not a constituency. A mailing list is not a roll of eligible voters.
Without a reliable denominator, the visible people cannot be converted into percentages of an affected public, and the volume of interventions cannot manufacture authority that the private institution does not possess.
The right starting point is therefore the actual text, not an impression of what supporters or critics thought it meant. Draft 6 required an abuse-c attribute on inetnum, inet6num and aut-num objects. The referenced person or role object had to contain an abuse-mailbox that was valid, monitored and actively managed. The proposal also protected the reporter’s ability to communicate in a practical way: a reporter could not be forced to use a prescribed form, and the mailbox had to be able to receive reports and supporting material, including such things as logs, headers and examples.
At that level, the mechanism answered a familiar administrative problem. A number-resource record can point to an address that no longer works, is not watched or cannot accept the material needed to describe a reported incident. Requiring a machine-discoverable contact and checking it periodically can reduce the search for the correct recipient. It can expose a stale entry. It can allow a holder to correct an objective defect before further reports disappear into it.
This is the strongest benign case for the proposal, and it should be stated without caricature: accurate contact data lowers needless friction for both the person sending a report and the operator expected to receive it.
Draft 6 did not stop at the bare existence of an address, however. Its stated validation objectives included confirming that the holder had read the procedure and policy, regularly monitored the mailbox, took measures and provided a response to reports. These are not equivalent propositions. Reading a policy is a claim about awareness. Monitoring is a continuing operational practice. Taking measures is an assessment whose answer depends on which measures, in response to what facts, under what duties and judged by whom.
Providing a response can be checked at the level of whether a message was sent, but the correctness or adequacy of that response is a different question again.
A careful analysis must therefore split the single word “validation” into several tests. The first is syntactic or record-level: does the relevant object contain the required attribute and does that attribute point to a properly formed address? The second is delivery-level: can a defined test message reach the destination, and can a deterministic challenge or acknowledgement return? The third is process-level: did a holder receive notice of a failed test, correct the record and pass a re-test within a stated period? Those are all capable of being documented by a registry.
The fourth possible test is substantive: was a reported event abuse, did the operator investigate it properly, were its measures sufficient, and was its answer correct? That is not a more sophisticated version of mailbox validation. It is a different institutional activity. It depends upon the underlying facts, applicable law, contractual arrangements and a competent decision-maker. A private technical registry that maintains unique number-resource records does not acquire the public authority to decide those matters merely because a complaint arrived through a field in its database.
Delivery is not agreement
Draft 6’s treatment of reports makes the boundary especially important. The mailbox had to accept reports without forcing the reporter through one prescribed form, and it needed to receive supporting material. That design could improve delivery: it avoids a channel so brittle that an otherwise usable report is rejected for failing to match a template. Yet the freedom to send a narrative, logs, headers or examples does not certify the narrative. Supporting material can be relevant without being conclusive. The fact that a message reached a monitored address says nothing by itself about whether the sender’s characterisation was accurate.
Nor does an acknowledgement concede the merits. A test can show that a mailbox received a challenge and that somebody or some defined system returned the expected token. It cannot show that an operator accepted an accusation, agreed with a proposed remedy or admitted a legal duty. Even a more detailed reply cannot safely be labelled “correct” by the registry unless “correct” has been reduced to an objective delivery property. Once correctness means that the recipient gave the answer a complainant, staff member or other observer preferred, the registry has left record validation and entered dispute adjudication.
The proposal’s revalidation trigger sharpened this risk. Draft 6 allowed alleged fraudulent behaviour, or an incorrect or absent response to an abuse report, to be reported to AFRINIC for revalidation. There is a narrow and defensible reading: a report may alert the registry that the published address is unreachable, causing the registry to repeat the same objective contact test. There is also a much broader reading: AFRINIC might examine the allegation, decide whether the operator’s reply was substantively satisfactory and allow that view to influence a registry consequence. Only the narrow reading fits a bookkeeper’s mandate.
The word “alleged” matters. The available record does not establish the truth of any particular complaint, the quality of any particular response or the performance of any holder under a Draft 6-style process. A trigger is not a finding. A complainant’s notice can justifiably start a fresh mailbox test without becoming evidence sufficient to determine misconduct. The validation record should say why a test was initiated and what delivery result followed, while refusing to transform the trigger into a verdict.
Accuracy is useful precisely because it is narrow
The case for accurate abuse contacts does not need an enforcement theory to be worthwhile. A valid contact record can reduce the time spent discovering where to send an operational warning. Periodic checking can catch decay before the next real report. A transparent failure notice can show the holder the precise record that needs attention. A correction and re-test can close the administrative loop. Each step produces a fact that another reviewer can reproduce or inspect.
This narrowness is not weakness. It is what makes the mechanism credible. The registry can show the target, method, timestamp and result of a challenge. It can show that notice was sent through a documented channel and that a corrected value was later tested. Those statements remain true regardless of which party is more persuasive in an underlying abuse dispute. A validation state tied to this evidence is less vulnerable to personal discretion because it does not require the bookkeeper to decide whether an operator’s security, legal or commercial judgement was right.
By contrast, “took measures” has no stable administrative meaning without more text. A measure could be immediate containment, investigation, preservation of evidence, a request for further information, referral to another service provider, or a conclusion that the report does not concern the recipient. Draft 6 did not furnish a merits code by which AFRINIC could rank those possibilities, and AFRINIC would not become the proper authority to apply such a code simply by creating one. The registry’s task is to keep the contact route accurate, not to occupy the many roles that may arise after the route is used.
That distinction also protects reporters. A process that promises only an accurate delivery channel makes a claim it can audit. A process that appears to promise registry validation of a complaint’s substance may mislead a reporter about the institution receiving it and the relief available. Clean institutional boundaries allow a report to reach the operator while leaving legal, contractual or other competent remedies where they belong.
Draft 6 should therefore be assessed neither as a trivial address-cleaning exercise nor as a ready-made abuse court. Its operative requirements contained a useful record function and language capable of spilling beyond that function. The job of the text-to-objection ledger is to identify that boundary sentence by sentence, before process interpretations acquire the coercive force of words that the proposal itself never enacted.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
