Summary
- The abuse-c validation campaign is a community-mandated, annually recurring check that abuse-mailbox attributes in the RIPE Database can receive mail — not that anyone reads or acts on what arrives.
- Its published numbers are substantial and consistent: 77,168 mailboxes in the initial 2019 sweep, then 84,868 (2023), 83,509 (2024) and 86,959 (2025), with a recurring 6–8% failure band and a growing manual-workload tail.
- No published statistic anywhere in the campaign's documentation or the registry's annual reports tracks what happens to an abuse report after it reaches a validated mailbox.
- The validation campaign functions as proof of procedural compliance; whether it has ever functioned as accountability evidence is a question the record does not answer.
The RIPE NCC is the only party that can be shown, on paper, to do something measurable about abuse contact data in its service region. Since late 2019 it has validated every abuse-mailbox attribute in the RIPE Database at least once a year, and it reports the results with chart-level precision: how many addresses were tested, how many passed automatically, how many needed a human being to chase them down. The numbers are real, public and auditable. This report takes them seriously enough to read them closely.
The mandate
The campaign exists because the RIPE community decided it should. Policy proposal 2017-02, "Regular abuse-c Validation", reached final consensus on 1 June 2018 and was fully implemented on 10 October 2019 (source 1). The governing policy text, published as RIPE-705 on the same consensus date, requires the RIPE NCC to validate the "abuse-mailbox:" attribute at least annually, requires each abuse-c role object to contain a single abuse-mailbox attribute, and requires that attribute to be "available in an unrestricted way via whois, APIs and future techniques". Where the attribute is deemed incorrect, the policy instructs the registry to "follow up in compliance with relevant RIPE Policies and RIPE NCC procedures" (source 0).
Read precisely, the mandate has two halves. The first is unambiguous: test the mailbox, at least once a year. The second — follow up on incorrect attributes "in compliance with relevant policies" — delegates the substance to other documents and, as this report will show, produces in practice a technical remediation ladder rather than any accountability for the abuse reports themselves.
The method the registry announced before it started
In October 2018, before the first sweep, RIPE NCC staff published the intended methodology on RIPE Labs, and it has remained the campaign's operating description since. The automated verification tool checks for formatting errors in the email address, verifies DNS entries, looks for bogus or honeypot addresses, and pings the mail server to confirm the mailbox exists and can accept mail. Crucially, the tool "does not send any emails and won't require any action on the part of the abuse contact" — a deliberate design choice that reduces burden but also means the test never confirms a human reads the mailbox (source 2).
Addresses that fail receive a validation link, with follow-up emails at one-week intervals up to three times; staff intervene only after roughly three weeks. Legacy resources sit outside the policy's scope. And the registry stated the boundary of its own mandate in one sentence that has defined the campaign ever since: "We have no say in what network operators do with any abuse reports they receive" (source 2).
That sentence is the hinge of everything that follows. It means validation measures deliverability, full stop. The registry's own framing draws the line between a working mailbox and a functioning abuse-handling process, and the published numbers stay entirely on the deliverability side.
2019: the initial sweep
The initial validation ran from February to October 2019 across roughly 77,200 distinct abuse-mailbox attributes. The results, presented by RIPE NCC staff at RIPE 79: 77,168 distinct attributes checked, of which 71,711 — 93% — passed automated validation and 5,457 — 7% — failed. About 8,000 abuse-mailbox attributes were updated in 2019 as a result. The workload was non-trivial: three temporary full-time staff for several months, and 20–25% of tickets requiring manual follow-up (source 4).
An interim progress report from May 2019 fills in the mechanics: roughly 67,000 contacts checked at that point and about 9,500 updated (a count that includes duplicates, as the report itself cautions); about 60% of cases resolved through the automated process with no staff involvement; and, once the initial round finished, ongoing validation of new members and updated contacts at roughly ten new tickets per day (source 3).
Two things in the initial campaign deserve attention that later reporting tends to skip. First, the failure rate was not a rounding artifact: one mailbox in fourteen, on the day the community's policy took full effect, could not receive the mail the entire abuse-reporting route depends on. Second, the remediation worked at the level of the attribute: mailboxes were updated, tickets closed, the database corrected. What the numbers cannot show is whether any of those mailboxes, once working, received and acted on a real complaint. The campaign's completion criterion was defined in advance as database-wide first-pass validation (source 1) — an entirely internal measure.
Steady state: the annual machine
After 2019, the campaign became an annually recurring operation whose shape was documented at RIPE 87 in late 2023: the annual validation covers roughly 19,600 abuse contacts in LIR organisation objects, roughly 58,100 in LIR resource objects, and roughly 15,400 in independent resource objects (PI and ASN) — around 93,000 contact placements overall, with about 2,000 contacts checked weekly, and a 6–8% failure rate on each pass (source 5).
The same presentation states the enforcement consequences, and they are asymmetric. An invalid abuse-c inside a resource object is simply replaced with the LIR's working abuse-c — an administrative fix the registry performs unilaterally. An invalid abuse-c on the LIR organisation object itself triggers "extensive investigation" and can, at the end of the ladder, lead to membership termination (source 5). The severity ladder, in other words, exists and is real — but every rung of it is triggered by deliverability, never by conduct. A member whose mailbox passes every annual test but whose abuse queue is ignored year after year never touches a single rung.
What the annual reports count, 2023–2025
The most recent three annual reports give the trend line in the registry's own audited numbers.
The Annual Report 2023 records 84,868 abuse-c email addresses validated in 2023, of which 84,219 passed the automated process and 649 required manual intervention; 2,503 abuse-c validation investigations, broken down as 910 LIR resources, 853 LIRs and 740 End Users; and 149,228 abuse-c role objects created and/or updated during the year (source 6).
The Annual Report 2024 records 83,509 validated addresses — 82,658 automated, 851 manual — alongside 2,366 validation investigations (841 LIR accounts, 774 LIR resources, 751 End Users) and 2,445 Assisted Registry Checks that yielded 5,500 corrective actions including abuse-c policy compliance (source 7; Annual Report 2024, RIPE-840 document page).
The Annual Report 2025 records 86,959 validated addresses against 83,509 the year before, with 899 requiring manual intervention versus 851 in 2024; 2,320 validation investigations (801 LIR accounts, 764 LIR resources, 755 End Users); and 2,825 Assisted Registry Checks completed against a target of 2,400. The report's prose rounds the investigation figure as "more than 2,300" and states plainly: "we also successfully validated all abuse-c addresses to comply with RIPE-705" (source 9; RIPE-855 PDF, ripe.net mirror).
Three observations emerge from reading these three years together.
First, the validated population is not shrinking into a stable, clean core. It grew from 83,509 to 86,959 between 2024 and 2025 — a 4.1% increase in mailboxes to test — and the manual-intervention tail grew with it, from 649 (2023) to 851 (2024) to 899 (2025), a 38.5% rise over two years. The machine scales, but the human work scales with it.
Second, the yearly "validation investigations" figure — around 2,300 to 2,500 — is a workload metric, not an outcome metric. It counts cases opened, distributed across account types. It does not say how many were resolved by the holder, how many ended in a replaced attribute, how many reached the termination-ladder investigation stage, or how many never responded at all. None of the three reports publishes a resolution breakdown.
Third, the completeness claim in the 2025 report — "all abuse-c addresses" validated — is a population assertion. It confirms coverage, not results. The same report's chart shows 899 addresses that failed automation and needed humans; the prose assertion and the chart coexist because validation-complete and validation-successful are different claims, and the report does not distinguish them in the sentence that a reader is most likely to quote.
The absence that the numbers are built around
Set the campaign's own documents side by side and the structural pattern is visible without any external data. The mandate tests deliverability (source 0). The method explicitly does not test whether mail is read or acted upon (source 2). The enforcement ladder fires on deliverability, never on conduct (source 5). And the annual reports measure validated addresses, investigations opened and checks completed (source 6; source 7; source 9) — with no published figure anywhere in the chain for how many third-party abuse reports were delivered to validated mailboxes, how many received a response, or how many ended in verified remediation of the reported abuse.
This is not a claim that the registry has failed at a task it was given. On the record assembled here, it was never given that task. RIPE-705 instructs follow-up on incorrect attributes "in compliance with relevant RIPE Policies and RIPE NCC procedures" — a technical-remediation instruction (source 0). The registry's disavowal of any say over operator conduct was published in the same document set that launched the campaign (source 2). The accurate description is narrower and more uncomfortable: the region's only measurable, recurring, publicly reported abuse-contact process is designed to measure exactly the part of the problem that least determines outcomes for the people filing reports.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
