Summary

  • RIPE-705 requires annual validation of the public abuse-mailbox attribute and follow-up when it is considered incorrect. That is a registry-accuracy control.
  • Neither a directory pointer nor a technical mailbox check measures whether a real abuse report reaches the right team, is triaged, or results in a remedy.

A contact field is a route, not a service guarantee

When an operator, victim or security team needs to report harmful traffic, the first practical problem is often finding the right address. RIPE’s database structure is designed to make that route visible. An abuse-c attribute points to a role object, which contains an abuse-mailbox address; resource records can make that contact discoverable through the registry.

That is a real public function. A contact that cannot be found, has a malformed address or points to an unusable mail domain defeats the purpose of publishing it. RIPE-705 says the address is intended for automatic and manual reports about abusive behaviour originating in resource holders’ networks, and requires unrestricted access to the attribute through Whois, APIs and future methods.

But the record is the beginning of a communication path, not a record of what an organisation does after a message is delivered. It does not show who reads the mailbox, whether a rota covers weekends, whether a report is assigned to the right security team, or whether a network operator changes anything. Those processes may exist and work well. The public contact field does not measure them.

What the annual check can establish

The published RIPE-705 policy requires RIPE NCC to validate the abuse-mailbox attribute at least once a year. Where it is deemed incorrect, RIPE NCC follows up under applicable policies and procedures. The policy does not turn the registry into the operator’s incident desk, nor does it specify a complaint-response time.

The 2017-02 proposal’s implementation material describes automated checks of technical parameters such as address syntax, domain and mail-server configuration. Its accompanying analysis acknowledged possible false positives and false negatives: a contact might be flagged even though it works, or pass a technical check and later prove unusable. A validation result is therefore a bounded signal about configuration, not a certified outcome for every message.

The evidence also needs a date attached. RIPE NCC’s assessment of a later proposal described the then-current tool as checking formatting, DNS, suspicious or honeypot addresses, and whether a mailbox appeared to exist and accept mail. It said the automated tool did not send an email. The assessment reported that 92.5% of addresses passed the automated check in that period. That figure describes one historical validation method; it is not a current performance rate and says nothing about the quality of complaint handling.

The two-week rule that did not become the rule

An earlier version of the 2017-02 proposal included a clause that would have marked an abuse-mailbox invalid if no valid reply arrived within two weeks, including after a bounce. The official revision history shows that wording removed. The final published RIPE-705 text instead says annual validation and follow-up where the attribute is considered incorrect.

That distinction matters because a deadline can sound like an operational service level even when it belongs only to a draft. The policy that took effect did not set a two-week response obligation for resource holders, and a mailbox’s validation status is not a public rating of how quickly its operator handles complaints.

A later proposal tested the line, then was withdrawn

Proposal 2019-04 explored a more direct check of whether each mailbox could receive a message, as well as a shorter validation interval. RIPE NCC’s impact analysis made the limit unusually clear: confirming that a mailbox can receive mail would still not establish whether reports were followed up in the way a reporter wanted. It said the proposal did not give RIPE NCC a mandate to intervene in resource holders’ internal abuse-handling procedures.

The proposal did not become policy. The RIPE 81 Anti-Abuse Working Group minutes record that there was no consensus and that 2019-04 was withdrawn. It is useful as evidence that the boundary was debated, not as evidence that RIPE NCC adopted the proposed checks.

Throughput is not an outcome measure

The RIPE NCC 2019 annual report gives concrete implementation volumes: 77,979 email addresses validated, 73,023 through automation, 4,956 requiring manual intervention, and 38,307 role objects created or updated. These figures show the scale and labour of improving registry data. They do not count complaints received, acknowledgment times, triage decisions, corrective actions or unresolved cases.

That is not a flaw in the annual report. It answered an implementation question. It simply cannot be repurposed as an abuse-response scorecard. A registry can report the share of addresses technically checked; a service-quality assessment needs a different denominator and different events.

Keep the three proofs separate

Operators and complainants can ask three distinct questions. Does the public record point to an address? Does the address’s technical mail path work? Does a responsible team acknowledge and handle a well-formed report? Each answer requires different evidence. Combining them into one green “valid” status makes a narrow data-quality result carry more meaning than it contains.

A proportionate operating model would keep the registry’s remit legible. The registry can publish the contact, run configuration checks, allow holders to correct errors and explain the consequences of an invalid record under existing rules. Operators can separately publish what they monitor, how they acknowledge reports and where escalations go. A voluntary or policy-backed service measure could record delivery, acknowledgment and triage milestones without asking a registry to decide the merits of every complaint.

The test is not whether an abuse contact is important. It plainly is. The test is whether a particular signal proves the thing being claimed from it. RIPE’s annual check protects the address-book layer. Evidence about the remedy belongs to the handling process behind that address.

Sources