Summary
- The RIPE abuse-contact regime validates that abuse-mailbox addresses are technically deliverable; nothing it publishes measures what happens to a report after delivery.
- A four-layer framework — transport, content, process, governance — separates compliance (a working mailbox) from accountability (a disposition someone can audit).
- Applying the framework to RIPE's own documents shows every published metric sits at the transport layer; the process- and governance-layer measures exist only as an unadopted 2019 proposal.
A correction before the framework
One document must be named correctly before anything else is built on it. Early framing of this subject sometimes reached for ripe-686; the research for this report found that ripe-686 is the RIPE NCC Charging Scheme 2018, not an abuse-contact policy. The governing policy is ripe-705, "Abuse Contact Management in the RIPE Database", which superseded ripe-563, the 2012 document that first introduced the abuse-c attribute without any validation mechanism at all. Getting the mandate right matters, because the framework below tests the mandate that actually exists.
The mandate as written
Ripe-705 requires an abuse-c attribute on all autonomous-system objects and directly allocated address objects, referencing a role object that must contain a single abuse-mailbox attribute, available without restriction via whois and APIs, and validated by the RIPE NCC at least annually ripe-705, abuse-c Information, database documentation, FAQs for abuse-c.
The critical boundary is in the policy proposal that created the validation requirement, 2017-02: validation is scoped to technical correctness — syntax, domain, mail-server configuration. The proposal states explicitly that scenarios where the mailbox works but reports are not followed up as the reporter wants are out of scope, because the RIPE NCC has no mandate to interfere with the internal abuse-handling procedures of resource holders. The registry's own user-facing pages repeat the same line: reports of spam and phishing from outside its network are not its responsibility, and "there is nothing we can do if a network operator chooses not to reply" Reporting Procedure, How to Find Abuse Contact Information, ripe-858, ripe-658.
What the registry actually measures
The published metrics all sit at layer (a) — transport. Per RIPE 87 NCC Services data (November 2023), the validation tool checks formatting, DNS and mailbox existence without sending email; roughly 2,000 contacts are checked weekly with a 6–8% failure rate, and invalid abuse-c values in resource objects are replaced by a working LIR abuse-c RIPE 87 AAWG presentation. Prior BTW coverage of the validation campaign recorded sweep sizes of 77,168 mailboxes in 2019, 84,868 in 2023, 83,509 in 2024 and 86,959 in 2025, with a manual-intervention tail growing from 649 to 851 to 899 across those years — contact-quality input metrics, never remediation outcomes prior BTW analysis.
The escalation machinery exists and demonstrably fires — ripe-858 defines unresponsiveness to a specific NCC request about an incorrect registration, with a 30/60/90-day ladder ending in a Managing Director termination notice — but its trigger is a registry request, not a third-party abuse report. RIPE 90 registry highlights (May 2025) report 2,445 Assisted Registry Checks in 2024 with about 5,500 corrective actions, member-services tickets up 19.4% to 32,514, and an intent to extend verification to organisation and registry contacts RIPE 90 presentation — again, all input-side statistics.
The framework
A complaint channel can be evaluated at four separable layers:
- Transport — does the mailbox receive messages? RIPE measures this annually.
- Content — does the response engage the specific case, or is it a templated autoreply? Not measured.
- Process — is closure of a report tied to a documented, auditable remediation disposition? Not measured.
- Governance — is there an escalation path with named roles and thresholds when layers 1–3 fail? Documented machinery exists, but it has never fired for a third-party abuse report.
The published record 2019-04 proposal shows RIPE's community came within one step of building layers 3 and 4: proposal 2019-04 would have required mailboxes to actually receive messages, barred forced web forms, and required the NCC to collect and periodically publish anonymised escalation statistics. The impact analysis noted the validation tool did not send email and that 92.5% of addresses passed the automated check. The escalation-statistics mechanism remained a proposal-level aspiration; no published anonymised statistics are located in this research.
What follows
A validated mailbox is a working entrance, not an accountability system. On RIPE's own published documents, layers (a) and (b) of the entrance are measured and the layers (c) and (d) measures that would show what happens after arrival either do not exist or exist only as an unexercised proposal. The disclosed record therefore proves compliance of contact data, not remediation of complaints. That is a structural finding, not an accusation: the mandate excludes interference with operators' internal handling by design, and the record is honest about that exclusion.
But honesty about the boundary does not make the boundary measurable, and no external party can currently distinguish a responsive abuse desk from an ignored report using anything RIPE publishes.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
