As someone new to the list I can naturally take the village idiot role, without the burden of considering the outcomes of past discussions :-)
On 3. Aug 2026, at 14.33, Serge Droz via Security-wg <
security-wg@ripe.net> wrote:
So here is what I propose. I'm not a lawyer, so maybe this needs to be phrased differently. But the idea is
a: Make sure poeple read their abuse e-mails
b: Possibly, take further acction if they read it bud don't act.
a: Abuse mailbox tests:
The RIPE NCC cunducts bi-annual communications checks to the abuse handles. It is expected that these are replied to within [X hours/days/...]
If no replies is received this will be escalated through other contacts.
If no reply is received on may as well assume the org no longer exists and take appropriate action. LACNIC blocks access.
b: Complaints about missing action
It very much sounds like the b) part of this proposal is where the objections come from, so would it be helpful to just focus on the a) part?
One parallel I’d like to draw is RPKI, where the RIRs have put in place infrastructure to detect unauthorized route advertisements, but don’t really mandate specific action operators should take with them. Rather it’s just information the operators’ own policies can consider.
To me this reads like a) can be implemented essentially the same way. Checks are added to enforce the already existing requirement of a valid abuse contact; results of those checks are published in the database.
This creates compliance pressure without any specific threats of further action. Not processing abuse emails results in a signal that third parties are free to interpret in a way that might be harmful towards the reputation and thus value of the number resources that refer to that specific abuse-c.
And I think crucially, this does not require a RIPE policy to argue what the signal means (like some sort of LIR score would), it’s just there for anyone to interpret as they wish.
Of course, the counterargument is the one Jeroen just made, that just responding to emails is not worth much. Sure. But a setup like this would at least help folks keep their abuse-c working, and I’m sure there are tons of cases where they’re inoperable not because of malice, but because nobody thought to make sure they worked.
Marko