July 20, 2026
Finding the abuse contact when WHOIS wants you to suffer

Someone is throwing traffic at you from 64.64.96.0/24. You want the human who can stop it. WHOIS hands you a registrar privacy proxy, a role account that auto-replies in a language you do not read, and a fax number from 2003. Welcome to the abuse contact hunt.
I do not start with the IP. I start with the prefix and the origin ASN. The person who can withdraw a route is rarely the person listed on a single address.
The order that actually works
- Prefix WHOIS / RDAP — look for
abuse-mailbox,org-abuse,irt. Ignoreadmin-cunless you are desperate; those people left in 2017. - Origin ASN WHOIS — the network’s abuse role is often cleaner than the end-user object.
- Upstream of that ASN. If the origin is a tiny downstream, their transit’s abuse desk has leverage. PeeringDB sometimes has a better email than the RIR.
- The hosting panel or cloud “report abuse” form, if category says cloud. Those forms are ugly and they get read.
Our abuse contact finder is built for that walk, because doing it by hand at 2 a.m. is how you email the wrong LLC and wait three days.
What to put in the first email
NOCs delete novels. I send: the prefix, the exact timestamps (UTC), a sample of source ports, why it is abuse (not “it felt mean”), and a one-line ask (“please filter or withdraw”). I attach a looking-glass screenshot of their origin so they cannot tell me the prefix is not theirs.
I do not threaten. I do not CC fifty people on the first shot. I do put the ticket ID in the subject so their thread does not die in a shared inbox. If I have to escalate to the upstream, I forward the whole thread so I am not asking them to reinvent the incident.
When WHOIS is empty on purpose
Some bulletproof hosts publish a mailbox and never read it. Some networks in certain RIRs still have objects that look complete and route to /dev/null. If two follow-ups get nothing, I stop pretending email is the plan. I filter locally, I tell the customer what I filtered, and I document the attempt. Routing security is not a helpdesk SLA.
If the space is hijacked, you are writing to the wrong villain. Check origin and RPKI first. I have sent a very polite abuse report to the legitimate holder of a prefix that was being announced by someone else. They were confused. I was embarrassed. Now I run BGP lookup before I write.
A note on privacy and rage
Do not dox a reassigned residential customer because their cable modem got recruited into a botnet. Write to the access network. Do not paste full packet dumps into a public list. Do not confuse “this IP is loud” with “I know who is at the keyboard.” Category helps here: residential vs cloud vs VPN changes both the tone and the destination of the mail.
The job is to stop the traffic and leave a paper trail. It is not to win WHOIS. WHOIS does not care if you win.