Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Abuse Contact Finder

Who to tell about spam, phishing or attacks — taken from the registries’ own records.

Network Uses live data Free, no sign-up

Find an abuse contact

Paste the address from a log, the link from a phishing message (defanged links such as hxxps://evil[.]example work too) or the sender’s e-mail address. An AS number (AS13335) works as well.

Try:

Next steps

About the Abuse Contact Finder

Paste the IP address from your server log, the link from a phishing message or the domain of a scam site, and see who to report it to: the abuse contact of the network that uses the address, and for a domain also the registrar’s abuse contact and the network that hosts the site. Every contact comes from the official registration records (RDAP), not from a third-party database.

When the most specific network lists no abuse contact — common for addresses a provider has assigned to a business customer — the finder asks the registry for the network above it, which usually belongs to the provider. A report template with the facts already filled in helps you write a report abuse desks can act on. MySmartCoPilot never sends anything: you copy the text or open it in your own e-mail app.

How to use it

  1. Enter an IP address (203.0.113.7), a domain (example.com), a link (defanged links such as hxxps://login.example[.]com work too), an e-mail address (also a sender line such as PayPal <[email protected]>) or an AS number.
  2. Press Find contacts. For a domain you get the registrar and every hosting network behind the exact host name; for an address, its network.
  3. Read the notes on each card: an unvalidated contact, a web form the registry record recommends, or a parent network used because the address range had no contact of its own.
  4. Under Write the report, choose what happened, add the time with your time zone and paste your evidence (log lines or full e-mail headers).
  5. Press Copy report, or Open in e-mail app to start an e-mail to the addresses you ticked — addresses a record names only in its remarks are listed too, marked as such, and ticked only when the record has no abuse e-mail of its own. Use the web form instead when the record points to one.

Examples

An IP address (Google Public DNS)
Input
8.8.8.8
Result
Network: GOGL (Google LLC) · 8.8.8.0 – 8.8.8.255 · ARIN
Abuse e-mail: [email protected] · Phone: +1-650-253-0000
The record says: … To report abuse and illegal activity: https://www.google.com/contact/

ARIN nests the abuse contact inside the organisation’s record; the remark with the web form belongs to the same record.

An address behind Cloudflare
Input
104.16.1.1
Result
Network: CLOUDFLARENET (Cloudflare, Inc.) · 104.16.0.0 – 104.31.255.255 · ARIN
Abuse e-mail: [email protected] · Phone: +1-650-319-8930
The record says: All Cloudflare abuse reporting can be done via https://www.cloudflare.com/abuse
Note: the registry marks this contact as unvalidated (it did not answer ARIN’s validation request).

Many sites sit behind a CDN, so DNS points to the CDN’s network rather than the real server; the CDN’s own record says where it wants reports.

A .com domain and its host
Input
https://www.google.com/
Result
Registrar: MarkMonitor Inc. · IANA ID 292 · from the .com registry’s RDAP record
Abuse e-mail: [email protected] · Phone: +1.2086851750
Hosting network: GOOGLE (Google LLC) · 142.250.0.0 – 142.251.255.255 · ARIN
Abuse e-mail: [email protected]

The .com registry’s answer contains the registrar’s abuse contact, as ICANN’s RDAP profile requires; www.google.com resolved to addresses in Google’s own network.

Common uses

  • Reporting a phishing page to the company hosting it and to the registrar of its domain.
  • Sending log lines of a brute-force or scanning attack to the network that the attacking address belongs to.
  • Reporting the server that sent spam, using the IP address from the message headers.
  • Finding the right desk for a fake shop or investment-scam site before warning others.

Who can act on a report

  • The hosting provider — the network whose addresses the site uses — can take the content or the server offline.
  • The registrar can suspend the domain name, so the site disappears wherever it is hosted. For generic TLDs, ICANN’s Registrar Accreditation Agreement (§3.18) requires registrars to publish an abuse contact, confirm that they received a report, and take prompt action when they have actionable evidence of DNS abuse: malware, botnets, phishing, pharming, and spam used to deliver them.
  • The network of an IP address — an internet provider, hosting company or cloud — handles spam and attacks coming from its addresses.

For phishing, malware and scam sites, report to both the host and the registrar. If the host is a CDN or proxy (such as Cloudflare), report there: DNS shows only the CDN’s network, and the CDN’s own record says where it wants reports.

How the contacts are found

IANA’s bootstrap files (RFC 9224) say which regional internet registry (ARIN, RIPE NCC, APNIC, LACNIC, AFRINIC) holds an address and which registry runs a domain ending. The finder asks that registry over RDAP (RFC 9082, RFC 9083) and reads the contact with the abuse role — the entity that “handles network abuse issues on behalf of the registrant” (RFC 9083 §10.2.4).

For domains in generic TLDs the registrar’s abuse e-mail and phone are mandatory: ICANN’s RDAP Response Profile (version 2.2, §2.4.5) requires an entity with the abuse role inside the registrar entity. The host name is resolved with Cloudflare’s DNS-over-HTTPS service, and up to two IPv4 and two IPv6 addresses are looked up. A network without an abuse contact is walked up to the network that contains it (an RFC 9082 prefix query), at most twice.

What makes a report actionable

  • One incident per report, with the exact date, time and time zone — providers reuse addresses, so “yesterday” is not enough.
  • The full link, the IP address, and for e-mail the complete headers (the “Received:” lines show where it came from).
  • For attacks, a few log lines with source and destination addresses and ports.
  • Facts, not threats: say what happened and ask them to investigate under their acceptable use policy.
  • Do not attach malware samples unless the desk asks for them; give the link and a hash instead.
  • When the record names a web form, use it — some providers do not read their abuse mailbox.

If nobody answers

For generic TLDs (.com, .net, .org, .shop …) you can complain to ICANN Contractual Compliance with the “Abuse/DNS Abuse (Registrar)” form when a registrar does not handle a report; ICANN cannot help with country-code domains. The regional internet registries do not act on abuse themselves: the RIPE NCC, for example, says that handling a report is the network operator’s responsibility, but asks to be told when an abuse contact appears to be invalid or missing. In its region every resource needs an abuse contact whose mailbox the RIPE NCC validates at least once a year (RIPE-705).

Limitations

  • Contacts are only as good as the registries’ records. Some registries hide or omit the abuse e-mail address (the card then says so and lists the other contacts).
  • For a site behind a CDN or proxy, DNS shows only the CDN’s network; the server behind it stays hidden by design.
  • Country-code registries without RDAP (for example .co, .eu and .jp) cannot be asked from a web page, so their registrar is not shown — the hosting contact still is.
  • Only the first two IPv4 and two IPv6 addresses of a host are looked up; other addresses in the same networks are listed with them.
  • MySmartCoPilot cannot tell whether a provider will act. It never sends reports and does not check whether an e-mail address accepts mail.
  • Lookups relayed through MySmartCoPilot’s server (when a registry blocks browser requests) are limited per hour.

Privacy

Lookups go from your browser to IANA (data.iana.org), to the registry and registrar RDAP servers and to Cloudflare’s DNS-over-HTTPS resolver, without cookies; those services see your IP address and what you look up. When a server does not accept browser requests, that one lookup is relayed through MySmartCoPilot’s server instead, which stores nothing and logs only the server name and status code. The report you write stays in your browser: it is never uploaded, and “Open in e-mail app” only hands the text to your own mail program.

Frequently asked questions

Should I report a phishing site to the host or the registrar?

Both. The host can remove the page or switch off the server; the registrar can suspend the domain so it stops working everywhere. Phishing often moves between hosts within hours, so the registrar’s action matters too.

Why does it show a provider and not the person who attacked me?

Registries record the organisation that holds an address block — an internet provider, hosting company or cloud — not its customers. Only the provider knows which customer used the address at a given time, which is why your report needs the exact time and time zone.

Why is a “parent network” shown?

Providers often register blocks they hand to business customers without an abuse contact of their own. The finder then asks the registry for the next larger network, which usually belongs to the provider that assigned the block, and says so on the card.

What does “unvalidated” mean on a contact?

Registries ask contacts to confirm their details regularly. ARIN, for example, adds an “Unvalidated POC” remark when a contact did not respond. The address may still work, but use any web form the record mentions as well.

Does MySmartCoPilot send the report for me?

No. MySmartCoPilot never sends anything. You copy the report into an e-mail or a web form, or press Open in e-mail app, which starts a new message in your own mail program — nothing is sent until you press Send there.

How do I report spam correctly?

The sender address is easy to forge, so look at the full message headers: the “Received:” lines show the server that really delivered it. Look up that server’s IP address here and include the complete headers in your report. The Email Header Analyzer helps you read them.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.