Where to send an abuse report, for every address.
The contact that takes abuse reports for each address range, resolved from the registries' records and operators' RWHOIS servers, with the email, phone and postal address, and the block the contact was taken from.
Schema at a glance.
See documentation →The database's schema and metadata are documented carefully. It is published as CSVGZ and MMDB.
| start_ip | end_ip | network | name | phone | country | address | |
|---|---|---|---|---|---|---|---|
| 1.1.1.0 | 1.1.1.255 | 1.1.1.0-1.1.1.255 | ABUSE APNICRANDNETAU | helpdesk@apnic.net | AU | PO Box 3646, South Brisbane, QLD 4101, Australia | |
| 8.8.8.0 | 8.8.8.255 | 8.8.8.0-8.8.8.255 | Abuse | network-abuse@google.com | +1-650-253-0000 | US | 1600 Amphitheatre Parkway, Mountain View, CA, 94043 |
| 12.4.166.88 | 12.4.166.119 | 12.0.0.0-12.255.255.255 | abuse | abuse@att.net | +1-919-319-8167 | US | 2701 W 15th ST, Plano, TX, 75075 |
| 88.198.0.0 | 88.198.71.199 | 88.198.0.0-88.198.255.255 | Hetzner Online GmbH - Contact Role | abuse@hetzner.com | +49 9831 505-3 | DE | Hetzner Online GmbH, Industriestrasse 25, D-91710 Gunzenhausen, Germany |
| 2a01:4f8:: | 2a01:4f8:171:f7ff:ffff:ffff:ffff:ffff | 2a01:4f8::/29 | Hetzner Online GmbH - Contact Role | abuse@hetzner.com | +49 9831 505-3 | DE | Hetzner Online GmbH, Industriestrasse 25, D-91710 Gunzenhausen, Germany |
Downloading it from code.
Database API reference →One call gets you the current IP Abuse Contact build. Every official client wraps it three ways: straight to disk, a time-limited link you hand to your own runner, or bytes in memory. A file written to disk lands only once the whole transfer has arrived, and checksums() returns the published digests to verify it against.
download()downloadUrl()downloadBytes()metadata()checksums()import osfrom internetdata import InternetDataclient = InternetData(os.environ["INTERNETDATA_API_KEY"])# what is in today's build, without moving the filemeta = client.database.metadata("ip_abuse_contact_v1")client.database.download("ip_abuse_contact_v1", "mmdb", "./ip_abuse_contact_v1.mmdb")sums = client.database.checksums("ip_abuse_contact_v1", "mmdb")print(meta.updated, meta.entries, sums["sha256"])
Getting your hands on it.
The file is the product. Teams join IP Abuse Contact against traffic they already log, inside their own infrastructure, and never send an address anywhere to get an answer.
Abuse reporting
Send each report to the mailbox that handles abuse for that range, not to the registry that allocated it.
Reporting in bulk
Route what your own detection finds to the right contacts by address, without a lookup per report.
An official client for every major language.
All SDKs on GitHub →Twelve official clients for the languages you ship in, each wrapping the database endpoints — list what you are licensed for, poll a build, follow the download redirect, verify what landed. Install commands are in the docs.
No loose ends.
How often does this database rebuild?
Daily, except IP RDNS and IP RWHOIS, which change weekly. The metadata call answers when the current build landed and how many rows it holds, before you fetch it.
Where does the data come from?
The five regional internet registries and the national ones, network operators' own RWHOIS servers, the global routing table, and our own scans of the address space. The documentation names the sources of each database.
Why is a contact field empty?
Because the registry does not publish it. Bulk registry data leaves out what privacy rules withhold, most often a personal contact's email, and a record carries only what its holder filed.
Which formats does a build ship in?
Gzipped CSV for all of them, and MMDB for IP ASN, IP Whois, IP RWHOIS and IP Abuse Contact. The schema section above names this one's.
Test the real build first.
An evaluation license puts a full current build in your hands — every row, every column, no sampling — so you can measure it against your own traffic before anyone talks about terms.