Skip to main contentSkip to footer

Abuse Contact Lookup

Find out who is responsible for an IP address and where to report it. Reads the registry directly over RDAP. Free, no account, nothing sent on your behalf.

Find the network that is responsible for an address and the mailbox it publishes for abuse reports. A domain is resolved to its address first. Nothing is sent on your behalf: you get the address, the facts and a draft to send yourself.

An abuse contact is the mailbox a network operator publishes for reports about traffic coming out of its address space. The reportedIP Abuse Contact Finder reads it straight from the registry that allocated the address, together with the network block, the holder and the community reputation of the address.

How this tool works and its limits

The address is matched against the IANA bootstrap registry, the file that maps every allocated prefix to the registry responsible for it, and the longest matching prefix decides which of the five regional registries is asked. That registry is then queried over RDAP, the JSON successor to WHOIS, and the abuse mailbox is read out of the contact entity that carries the abuse role.

What comes back is what the operator published, no more. A contact can be stale, a shared hosting provider will forward a report to a reseller, and some networks publish no abuse mailbox at all, in which case the registry and the holder of the block are the next places to go. The address itself is never contacted and no mail is sent from here.

A report is only actionable if the recipient can find the same session in their own logs. Timestamps with a time zone and a few raw log lines do more than any amount of description, which is why the draft below asks for exactly that.

Reporting to the wrong place is the same as not reporting

Every address block belongs to someone, and that someone publishes a mailbox for abuse reports. The catch is that the block you see is rarely the block that matters. A single address can sit inside a hosting company allocation, which sits inside a transit provider allocation, which sits inside a regional registry range. A report sent to the widest one gets ignored; a report sent to the narrowest one reaches the people who can actually disconnect the machine.

This lookup asks the registry that is authoritative for that exact address, follows the chain to the most specific allocation, and returns the mailbox published for it.

How the responsible registry is found

There are five regional registries and no central directory of addresses. IANA publishes the map of which address ranges belong to which registry, and that map is what this tool reads first. Ranges are matched by the longest prefix, not the first one that fits, because carve-outs exist: a small range inside an old, large allocation frequently belongs to a different registry than its parent.

The registry is then queried over RDAP, the successor to WHOIS, which returns structured data instead of free text.

What you get

The responsible registry, the network block, its holder, the abuse mailbox, the country, and what our own community data knows about that address. Plus a report draft with the known facts already filled in.

Nothing is sent from this page. The draft is yours to check and send from your own mailbox, which is also where the reply will arrive.