If a space is in an email oriented blocklist like say Spamhaus, it just gets used for some other kind of abuse .. DDoS C2, account farming, host illegal content and so on. Or if spam, then spam through some messaging or social media platform rather than through email.
From: Jeroen Massar <[email protected]> Date: Monday, 3 August 2026 at 5:21 PM To: Serge Droz <[email protected]> Cc: Suresh Ramasubramanian <[email protected]>; denis walker <[email protected]>; [email protected] <[email protected]>; Gert Doering <[email protected]> Subject: Re: [Security-wg] Abuse mailboxes are increasingly no longer monitored and are being replaced by (bad) forms > On 3 Aug 2026, at 13:33, Serge Droz <[email protected]> wrote: > [..] > b: Complaints about missing action > RIPE NCC solicitations feedback about failure to take action. This feedback > should only be admissible for specific abuses, I would start small (spam, > maybe residential proxies, but that's already hard). > If there are n (1, 2, ...) complains the RIPE NCC will send a warning to the > violating organisation. TLDR: - Abuse mailbox response is meaningless if the customer gets recycled to another host - Blacklists make the ASN / address space useless as not more abuse can happen - ISPs that care will try to get themselves off blacklists - What is the problem to solve with 'reports'? - IMHO abuse-mailbox should be volunantary for those that want to take action, everybody else should be able to publish a 'do-not-care-won't-handle' as then folks know what the network is about. A response means very very little. Please note that there are a variety of 'enablers' that will happily answer all your abuse reports. Some will acknowledge the report back to the report and directly forward the full email to the one who is using the IP addresses in question. Some will "shutdown" that "customer". The 'customer' will then create a new account, re-setup resources on a different IP and continue doing what it did before. Then the bigger fun: setup a whole bunch of companies, all entered in the trade register, paper work legit, all separate entities, heck, have random people act as CEO. One of these entities are then used for the LIR, one for one or more transit AS, some for datacenters/rack colocation and some others become customers of these other entities. Voila: keep rotating a few of these elements. The reports are handled, customers are shutdown (they can even show the config changes, the billing etc) But all the reporting will not do anything as it will take time, effort (mostly on the side of the reporters and the RIRs) and then possibly some legal challenges in the mix to make it all even nastier. And then the other fun: - Spam sources, can be because of compromised hosts, and given Wordpress that is easy; next to thousands of others of software with issues (and throw LLM analysis in the mix and ... fun) - Residential Proxies tend to be enabled not by the customer, but by a gadget they buy and plug into their networks. And that is just two parts of the equation. Hence the big question is more: - what is the exact type of problem you want to solve, and how much time do you have. Noting: I have a long time given up on abuse reporting a long time ago (unless I know the entity will act). Hence shutting down, and trying KYC style helps a wee bit. But as noted, easy to setup new companies as RIPE NCC is well aware of with the many international/out-of-RIR-area customers they get with often rather shady setups. But due to the rules they accept them anyway. I've seen hundreds of megabit flow for weeks, many millions of requests just coming in and going; reporting them does often not matter, as even if the provider shuts them down, the 'customer' will pop up in a new place. Provider takes money, service for a bit, shutdown, repeat.... For some ISPs it is even 'good' to have that kind of traffic, as then they might rebalance their network to be more equal in inbound/outbound traffic flow which means they can get cheaper/better transit.... Hence why many resort simply to blacklists, or even some cases whitelists. Blacklists act quicker and causes a ASN / Prefix to end up blocked. Does not matter if they rotate their 'customers' the resource becomes useless: and that costs them money. Of course the fun with "cloud" and "hyperscalers" is that they have so many swaths of address space that they become unblockable, especially when the address space gets shared by many other inhabitants. One sees that also with gmail/outlook/SES where much of the spam comes from: many customers, thus 1% spam is suddenly a lot. Regards, Jeroen
----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
