Have you looked at Abusix? They have tools to manage abuse mailbox, parse various log types, and include a mechanism for building playbooks to automate handling.
--h On Wed, Jul 29, 2026 at 11:14 AM Max Grobecker < [email protected]> wrote: > Hello, > > I hope this is the right list to discuss. > > I'm seeing more and more providers auto-responding to abuse reports mailed > to their "abuse-mailbox" address, stating that this mailbox will not be > monitored and urging you to use some form on their website. > And often enough, those forms are either only usable for very specific > types of abuse or they are just tedious to use and sometimes I suddenly > don't want to report spam or phishing anymore to that specific provider > when I see a form with 20+ input fields. > Besides that, it renders automatic reports useless, even those that are > meant to be automatically processable (i.e., containing information as > XARF). > (Surely, automated reports are a very special topic, but as a provider we > are grateful to receive prompt reports of abuse on our network.) > > > This raises the questions: Is there – at least for the RIPE region – any > sort of requirement to accept/process abuse reports by mail? > > While I'm sometimes a bit "pissed" about how bad reporting forms can be, I > understand why providers might not want to maintain abuse mailboxes anymore > (the amount of spam sent towards these addresses is hilariously large) and > instead rely on forms with captchas to tackle this problem. > > So I'm wondering: Would there be a benefit for building some standardized > HTTP API with an authentication system, that would allow providers to > automatically send authenticated abuse reports to other providers? > That could work in a similar way like DKIM does: The sending provider > needs to publish a private key somewhere in the RIPE database, signs the > report, and the receiving provider would be able to immediately verify that > signature. > And if you get a ton of false reports or even spam from a specific > provider you can still filter these out based on the sender information in > the signature. > > > I would like to hear your opinion on this, or maybe there already *are* > solutions I just don't know about yet (besides from manually reporting > 20-30 phishing mails a day over 30 different forms). > > > Thanks and greetings > > Max > ----- > To unsubscribe from this mailing list or change your subscription options, > please visit: > https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ > As we have migrated to Mailman 3, you will need to create an account with > the email matching your subscription before you can change your settings. > More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
