Summary

  • RIPE-705 requires every allocation and ASN record to name a dedicated abuse contact and obliges the RIPE NCC to validate the abuse-mailbox attribute at least annually, following up where the attribute is judged incorrect.
  • The completed first round validated 77,168 distinct abuse-mailbox attributes: 71,711 (93%) passed the automated check and 5,457 (7%) failed, with about 8,000 attributes updated during 2019.
  • The automated test examines syntax, domain and mail-server configuration. It does not test whether a report sent to the address is acted upon.
  • The registry has published a terminal escalation sequence — a three-month deadline, reminders at 30 and 60 days, then possible termination and deregistration with RPKI revocation — but its 2017-02 impact analysis records that more than 1,000 external invalid-contact reports over five years were resolved without ever triggering closure, which it calls a last resort.
  • The remedy is unevenly available: member closure and deregistration can be reached through a member's organisation abuse contact, while invalid contacts on LIR resource objects and End User objects are addressed by a database comment instead.

What the annual check is, and is not

The obligation is specific. Under RIPE-705, the policy settled by proposal 2017-02, every aut-num object must carry an abuse-c reference and allocated address records must have one; the referenced role must hold a single abuse-mailbox, and the RIPE NCC must validate that attribute at least annually and follow up where it is deemed incorrect (RIPE-705). The proposal behind it reached consensus on 1 June 2018 and was recorded as fully implemented on 10 October 2019, with an automated solution checking technical parameters — syntax, domain and mail server configuration (2017-02 implementation archive, how invalid contacts would be followed up).

That boundary matters more than the numbers that follow it. Reachability is not responsiveness, and a later community proposal says so in the registry's own documentation.

The numbers the registry published

Before annual validation existed, the registry received several hundred reports of invalid abuse contact information a year. Its impact analysis for 2017-02 recorded that over the preceding five years it investigated and resolved more than 1,000 external reports on incorrect abuse-mailbox attributes "without ever needing to trigger the closure and deregistration procedure", describing that procedure as a last resort (proposal 2017-02). The same analysis estimated that 10% to 25% of roughly 70,000 distinct attributes might be incorrect or inactive, based on a preliminary test with a random batch.

A trial in late 2018 covered abuse contacts in 900 LIR organisation objects and produced 187 tickets, about 21%; 106 were resolved without staff intervention and 81 needed manual follow-up (RIPE Labs, following up with invalid abuse contacts).

The completed first round came in lower. Of 77,168 distinct abuse-mailbox attributes, 71,711 (93%) passed automated validation and 5,457 (7%) failed; about 8,000 attributes were updated during 2019; the work consumed three temporary full-time equivalents for several months, and 20% to 25% of tickets needed manual follow-up (RIPE 79 implementation summary). An interim progress report had put it differently again: roughly 60% of flagged cases resolved without staff intervention, about 9,500 abuse contacts updated out of about 67,000 checked, and about 50 independent resources changing their sponsorship status (progress and numbers). A mid-2019 breakdown split the work by object class — 18,200 LIR organisation addresses yielding 3,500 tickets, 3,200 LIR resource addresses yielding 200 tickets, and 13,500 End User addresses still underway with 1,200 tickets (RIPE 78 abuse-c update).

By November 2021 the process had settled into a steady state: about 2,000 contacts checked weekly, 6% to 8% failing, against an annual scope of roughly 19,600 LIR organisation objects, 58,100 LIR resource objects and 15,400 independent resources (RIPE 87 Anti-Abuse Working Group update).

The denominator problem

Read as a sequence, the published failure rates fall: 10%-25% estimated before implementation, about 21% in the 2018 trial sample, 7% in the completed round, 6%-8% weekly in 2021. Read as a remedy, the sequence measures one thing only — whether an attribute passed a configuration test. No published figure in that chain states how many abuse reports were received, how many were answered, or how quickly.

The community record makes this explicit. A later policy proposal argued that the existing check does not establish that an abuse mailbox works in practice, and its accompanying impact text states that the policy intent is not to examine how abuse cases are monitored or handled; it also projected that a full recurring validation round could generate more than 32,000 tickets, about 19,200 of them needing manual checking (proposal 2019-04, RIPE 80 presentation on 2019-04). That presentation restated the same headline results — 77,168 attributes, 93% passing, 7% failing — and the roughly 8,000 attributes updated in 2019.

In other words, the regime's published evidence base measures record quality, and it is presented in the vocabulary of abuse handling.

Who the terminal remedy can actually reach

The escalation design is asymmetric, and the asymmetry appears in the registry's own description of the follow-up process. For an invalid contact on a member's organisation object, unresponsiveness or refusal to cooperate may ultimately lead to closure of the member and de-registration of resources, with a further three months after the closure process starts for the LIR to correct its abuse contact before membership is terminated. For LIR resource objects and End User objects, the registry stated it would not terminate membership or sponsorship; instead it would add a RIPE Database comment noting that the abuse contact failed validation (RIPE Labs).

The full ladder, as written for serious and unresolved violations, runs through a written notification with a three-month deadline, reminders at 30 and 60 days, notification to the Managing Director that the service agreement may be terminated at 90 days, and then deregistration of resource records and revocation of RPKI certificates (ripe-858).

So the enforceable endpoint is real, and its collateral effects are real — deregistration touches routing records, and RPKI revocation touches route origin authorisation. It is also aimed at one class of object. For the much larger population of resource objects inside member allocations, and for independent End User resources, failure produces an annotation in a public database rather than a consequence, unless the responsible LIR's own organisation contact is the one at fault.

What a durability claim would have to show

A claim that this regime converts reports into durable remediation would need evidence the published record does not currently supply: the number of closure or de-registration proceedings actually opened over an invalid abuse contact; validation statistics published after November 2021; any measure of how quickly reported abuse is answered, rather than whether a mailbox resolves; and a registry statement describing outcomes rather than attribute states. A policy change extending termination to resource and End User objects — or replacing the comment fallback with something that carries cost — would be a second, equally testable signal.

Until one of those appears, the defensible reading is bounded. The RIPE NCC built a system that reliably finds and fixes malformed abuse contacts, and it has documented, in advance, a hard remedy it has not publicly reached. The registry record behind this briefing is the RIPE ABUSE directory entry.