Summary

  • RIPE NCC's annual validation proves that an abuse mailbox exists, resolves and can receive mail — 93% of 77,168 distinct attributes passed the 2019 full round — but it never measures whether a delivered report is handled. https://www.ripe.net/participate/member-support/lir-basics/abuse-c
  • The consequence chain is fully documented: under ripe-858, an invalid abuse-mailbox treated as a registration violation runs an initial notice with a three-month termination threat, reminders at 30 and 60 days, and after 90 days official SSA termination by the Managing Director, followed by service stoppage, deregistration of number-resource records and RPKI certificate revocation. https://www.ripe.net/publications/docs/ripe-858/
  • The institution's own policy proposal states that more than 1,000 external reports about incorrect abuse-mailbox attributes were investigated and resolved over five years "without ever needing to trigger the closure and deregistration procedure" — a self-reported aggregate with no per-case record. https://www.ripe.net/community/policies/proposals/2017-02/
  • The final rung is structurally unreachable for part of the resource population: the Legacy Agreement bars deregistering Legacy Internet Resources unless the holder requests it. https://www.ripe.net/publications/docs/ripe-746
  • Annual-report closure statistics (29 member closures for unresponsiveness in 2024, 3 in 2025) record general unresponsiveness conduct, not abuse-c-specific enforcement, and cannot be counted as the sanction firing. https://www.ripe.net/participate/member-support/lir-basics/abuse-c

A mailbox that passes while reports go unanswered

Every validation regime has a boundary, and RIPE NCC's is unusually easy to state. The automated checks inspect the abuse-mailbox attribute for syntactic validity, confirm that the domain resolves, and test that the mail server is configured to accept messages. What the checks cannot see is the other side of the mailbox: whether anyone reads what arrives. A resource holder can operate a correctly configured mailbox that silently files every abuse report into an unattended folder, and the registry's own metric would record that holder as fully compliant. https://www.ripe.net/participate/member-support/lir-basics/abuse-c

The published numbers make the reachability side concrete. The first complete validation round, finished in 2019, tested 77,168 distinct abuse-mailbox attributes; 71,711 passed, a 93% pass rate, and 5,457 failed. Around 8,000 attributes were updated in the database that year. Since then the registry has moved to annual and weekly checks. None of those figures measure response. https://www.ripe.net/participate/member-support/lir-basics/abuse-c

The ladder on paper

What happens when a mailbox fails, or when the registration data it anchors is wrong, is written down in unusual detail. Ripe-858, the current procedural document on closure of members and deregistration of internet resources, treats an invalid abuse-mailbox address and unresponsiveness to registration-correction requests as policy violations, and sets out a timed sequence: an initial email setting out the violation and a three-month termination threat; a reminder after 30 days; a second reminder after 60 days; and after 90 days an official notification of termination of the Standard Service Agreement from the Managing Director. On termination, services stop, the relevant number-resource records are deregistered, RPKI certificates are revoked, and the member loses member status and voting rights. https://www.ripe.net/publications/docs/ripe-858/

The document is a revision. Its predecessor, ripe-833 of 18 October 2024, described the same 30/60/90-day sequence, with differences in wording and in the postal-mail reminder step. Version matters when citing escalation steps, and the current version is dated 7 May 2026. https://www.ripe.net/publications/docs/ripe-833/

The policy that created the obligation, ripe-705, is notably thinner on consequences. It mandates the abuse-c and abuse-mailbox attributes, requires public availability through whois and APIs, requires at-least-annual validation, and then defers enforcement to "relevant RIPE Policies and RIPE NCC procedures" — the procedural detail lives elsewhere, in documents like ripe-858. https://www.ripe.net/publications/docs/ripe-705/

The institution's own non-use record

The clearest statement about whether the ladder's final rung has ever been reached for abuse-mailbox conduct comes from the registry itself, in the 2017-02 policy proposal that introduced regular validation. It records that over the prior five years RIPE NCC had investigated and resolved more than 1,000 external reports on incorrect abuse-mailbox attributes "without ever needing to trigger the closure and deregistration procedure." It describes closure as a last resort and notes that a holder who reaches that point still has three months to resolve the problem. https://www.ripe.net/community/policies/proposals/2017-02/

That sentence is the hinge of this report, and it deserves careful handling. It is an institution's self-description, not an audited enforcement log. No per-case record is published; the denominator — how many abuse-c-specific violations reached any tier of escalation — is not published either. What the statement establishes is the registry's own account that the documented sanction has not fired for the conduct it polices. That is a finding about the record, not an accusation of bad faith: resolution without escalation is, on its face, the intended behavior of a compliance process whose early tiers work.

The accountable question is different — whether the system can show, case by case, that it worked.

The Legacy carve-out

Even the paper sanction has a documented limit. The Legacy Agreement, ripe-746, provides that RIPE NCC is not entitled to deregister Legacy Internet Resources unless the Legacy Holder requests it. For that part of the resource population, the ladder's final rung is not merely unused; it is contractually unavailable. The carve-out does not remove the validation obligation or the earlier escalation tiers, but it means the population over which the ultimate sanction could theoretically apply is smaller than the population over which the obligation applies. https://www.ripe.net/publications/docs/ripe-746

What the closure statistics do and do not show

RIPE NCC's annual reports do record member closures. The figures visible in this research — 29 closures for unresponsiveness in 2024 and 3 in 2025 — are sometimes read as evidence that the escalation machinery works. They show something narrower. "Unresponsiveness" in the procedural documents means failing to react to a specific RIPE NCC request about incorrect or ambiguous registration data, regardless of responsiveness to other requests or continued fee payment. Those closures are general unresponsiveness outcomes, not abuse-c-specific enforcement, and the registry does not publish a separate count of abuse-mailbox-driven terminations. Counting them as the sanction firing would be exactly the conflation this report exists to avoid. https://www.ripe.net/participate/member-support/lir-basics/abuse-c

Bounded consequence and uncertainty

Three conclusions hold on the documented record. First, the validation regime measures reachability, not responsiveness, and its published statistics say nothing about whether reports are handled. Second, the consequence chain from an invalid mailbox to membership closure and deregistration is fully documented and version-controlled. Third, by the institution's own account the final step has never been triggered for abuse-mailbox conduct, while the only published closure counts concern a different category of conduct.

What remains uncertain is as important as what is established. Whether "never triggered" covers SSA termination only or also deregistration and RPKI revocation as separable steps is not established by the available documents. The 1,000-plus figure is an aggregate without dates or case detail. And the absence of a published abuse-c-specific enforcement record is itself an absence — it constrains what outsiders can verify, which is a governance fact about transparency, not proof that no member was ever closed for a mailbox problem.

For the person sending an abuse report, the practical consequence is bounded: the registry guarantees a reachable door, documents a sanction it says it has never used, and publishes no way to check whether any given report was answered. https://www.ripe.net/community/policies/proposals/2017-02/