Have you looked at Abusix?  They have tools to manage abuse mailbox, parse
various log types, and include a mechanism for building playbooks to
automate handling.

 --h

On Wed, Jul 29, 2026 at 11:14 AM Max Grobecker <
[email protected]> wrote:

> Hello,
>
> I hope this is the right list to discuss.
>
> I'm seeing more and more providers auto-responding to abuse reports mailed
> to their "abuse-mailbox" address, stating that this mailbox will not be
> monitored and urging you to use some form on their website.
> And often enough, those forms are either only usable for very specific
> types of abuse or they are just tedious to use and sometimes I suddenly
> don't want to report spam or phishing anymore to that specific provider
> when I see a form with 20+ input fields.
> Besides that, it renders automatic reports useless, even those that are
> meant to be automatically processable (i.e., containing information as
> XARF).
> (Surely, automated reports are a very special topic, but as a provider we
> are grateful to receive prompt reports of abuse on our network.)
>
>
> This raises the questions: Is there – at least for the RIPE region – any
> sort of requirement to accept/process abuse reports by mail?
>
> While I'm sometimes a bit "pissed" about how bad reporting forms can be, I
> understand why providers might not want to maintain abuse mailboxes anymore
> (the amount of spam sent towards these addresses is hilariously large) and
> instead rely on forms with captchas to tackle this problem.
>
> So I'm wondering: Would there be a benefit for building some standardized
> HTTP API with an authentication system, that would allow providers to
> automatically send authenticated abuse reports to other providers?
> That could work in a similar way like DKIM does: The sending provider
> needs to publish a private key somewhere in the RIPE database, signs the
> report, and the receiving provider would be able to immediately verify that
> signature.
> And if you get a ton of false reports or even spam from a specific
> provider you can still filter these out based on the sender information in
> the signature.
>
>
> I would like to hear your opinion on this, or maybe there already *are*
> solutions I just don't know about yet (besides from manually reporting
> 20-30 phishing mails a day over 30 different forms).
>
>
> Thanks and greetings
>
>   Max
> -----
> To unsubscribe from this mailing list or change your subscription options,
> please visit:
> https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
> As we have migrated to Mailman 3, you will need to create an account with
> the email matching your subscription before you can change your settings.
> More details at: https://www.ripe.net/membership/mail/mailman-3-migration/
-----
To unsubscribe from this mailing list or change your subscription options, 
please visit: https://mailman.ripe.net/mailman3/lists/security-wg.ripe.net/
As we have migrated to Mailman 3, you will need to create an account with the 
email matching your subscription before you can change your settings. 
More details at: https://www.ripe.net/membership/mail/mailman-3-migration/

Reply via email to