On the flip side of things - and speaking in absolutely general terms rather than specific facts or figures from any particular provider
1. An abuse mailbox of long standing will receive enough direct spam that 99.99% of its traffic is spam rather than complaints 2. Provider feedback loops from report spam clicks account for the lions share of actual spam complaints; in a machine parseable format and at scale. 3. A lot of the complaints that do come in are either misdirected, incomplete or both (and that is not counting the cranks aggrieved about alien mind control rays and/or secret government experiments that somehow involve an internet connection) Given all these, the usual best practice that seems to be evolving is to prefer a web form but also accept and process emailed abuse reports on a best effort basis. Though more than one provider probably stops short at just the web form --srs ________________________________ From: Jeroen Massar via Security-wg <[email protected]> Sent: Monday, 03 August 2026 19:26:55 To: Marko Karppinen <[email protected]> Cc: [email protected] <[email protected]> Subject: [Security-wg] Re: Abuse mailboxes are increasingly no longer monitored and are being replaced by (bad) forms > On 3 Aug 2026, at 15:42, Marko Karppinen via Security-wg > <[email protected]> wrote: > > As someone new to the list I can naturally take the village idiot role, > without the burden of considering the outcomes of past discussions :-) IMHO the ship of abuse reporting simply has completely sailed. Some years ago one could still report and action would be taken, now that will happen if you know the people directly and otherwise even with an intro it often just gets ignored (many people are also to busy with too many fires though). And as the subject of this thread is: - Abuse mailboxes are increasingly no longer monitored - are being replaced by (bad) forms I think we just need to accept that One way would be a 'good netizen' marking by giving LIRs with a 'functional abuse/report handling and. Noting that it is not only about abuse, sometimes there is a MTU issue, or packet lo, that one would love to see fixed and that will help both parties. Or simply peering. Contacts are hard, especially if they go against business interests. [..] > Of course, the counterargument is the one Jeroen just made, that just > responding to emails is not worth much. Sure. But a setup like this would at > least help folks keep their abuse-c working, and I’m sure there are tons of > cases where they’re inoperable not because of malice, but because nobody > thought to make sure they worked. Lots of abuse mailboxes work fine, there might even be people checking that mail is arriving from something 'important' (eg a RIR) and respond to that. But most of it is /dev/null, especially if ones "business" is facilitating the things that are complained about. There are many examples that can be found simply on: https://krebsonsecurity.com <https://krebsonsecurity.com/> the latter not being really monitored either.... Fortunately as Brian's articles shows, some operations are annoying enough for large companies to go after them with their vast legal respresentation, many are not though, and many get recycled under different names. Regards, Jeroen ----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
----- To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
