IP Abuse Contact Database


Overview

Our IP Abuse Contact Database gives you instant access to the correct abuse desk for any routable IP that connecting you to verified addresses, phone numbers, and emails worldwide. By mapping IPs to the responsible operator (ISPs, cloud providers, hosting networks, and enterprises) and their preferred reporting channels, it streamlines abuse escalation, speeds up takedowns, and helps you quickly pinpoint the source of malicious or unwanted activity to keep your environment safer.

Updated daily and delivered as CSV and MMDB, with JSON, Parquet, or any custom export on request at no extra cost and backed by stable schemas and changelogs. Each record includes organization and netblock context, primary abuse mailbox and phone. Below, you'll find full documentation of the archive contents, schema definitions, file specifications, and integration notes to help you integrate with SIEM/SOAR, ticketing, and security workflows—fast.


Available Database Formats

CSV
CSVCSV
  • File Size: 426.45 MB
  • Entries: 47.5M
  • Fields: 9
  • Last Updated: Yesterday
MMDB
MMDBMMDB
  • File Size: 789.80 MB
  • Entries: 47.5M
  • Fields: 9
  • Last Updated: Yesterday

CSV Database Documentation


1. Overview

The CSV version is a set of Gzip-compressed CSV files containing IP ranges and their Abuse Contact details. Designed for bulk imports and integration into relational databases.


2. Archive Content

After downloading and extracting the IP to Abuse Contact CSV database archive, you'll find the following files (with their types noted):

db-abuse-details.csv.gz
db-abuse-details.csv.gzdb-abuse-details.csv.gz

Gzip-compressed CSV provides abuse contact info: unique ID, network, and contact details.

  • File Size: 114.69 MB
  • Entries: 12.4M
  • Fields: 8
db-ip-abuse.csv.gz
db-ip-abuse.csv.gzdb-ip-abuse.csv.gz

Each start_ip, end_ip link to the abuse details ID that is related to the abuse-details file.

  • File Size: 311.76 MB
  • Entries: 47.5M
  • Fields: 3
README.md
README.mdREADME.md

Documentation for dataset contents, schema, usage, and support.

  • File Size: 5.60 KB
checksum.txt
checksum.txtchecksum.txt

SHA-256 checksums for verifying file integrity.

  • File Size: 251 Bytes

Schema

This section describes the schema of each file included in the IP to Abuse Contact Database archive. For every file, you'll find its purpose, field definitions, and examples to help with integration.


1. db-ip-abuse.csv.gz

This file contains IP address ranges linked to abuse details. It maps each IP block to a unique abuse_details_id , which in turn corresponds to the abuse contact information.

FieldTypeDescriptionCan be empty?Example
start_ipstringThe starting IP address of the range in IPv4 or IPv6 format.No192.168.0.1
end_ipstringThe ending IP address of the range in IPv4 or IPv6 format.No192.168.0.255
idnumberThe unique identifier for the abuse contact.No1

I. Example Records

Example
start_ip,end_ip,abuse_details_id
180.168.175.200,180.168.175.211,7517995
23.240.191.23,23.240.191.23,512530
172.119.65.98,172.119.65.98,0
79.55.102.26,79.55.102.26,3254357
223.148.85.0,223.148.85.255,10706703
81.95.9.18,81.95.9.19,3604329
106.111.151.0,106.111.151.255,5696043
98.198.225.159,98.198.225.159,5288114
120.19.47.69,120.19.47.69,6192432
122.52.122.148,122.52.122.148,6263681

2. db-abuse-details.csv.gz

This file provides detailed abuse contact information. It links a unique ID to a specific network, country, and other contact details, including name, address, emails, and phone numbers.

FieldTypeDescriptionCan be empty?Example
idnumberThe unique identifier for the abuse contact.No1
networkstringThe network associated with the abuse contact.Yes192.168.1.0/24
countrystringThe ISO 3166-1 alpha-2 code of the country associated with the abuse contact.YesUS
kindstringThe kind specifies whether the contact is a person or an organization.Yesgroup
nameobjectThe name (english) of the abuse contact.YesAbuse Team
addressstringThe physical address of the abuse contact.Yes1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
emailsstringComma-separated email addresses associated with the abuse contact.Yesabuse@example.com
phone_numbersstringComma-separated phone numbers associated with the abuse contact.Yes+1-800-555-0199

I. Example Records

Example
id,network,country,kind,name,address,emails,phone
3604329,81.95.9.0/24,DE,group,Core-Backbone Netmaster,"Deutschherrnstr. 15-19, 90429 Nürnberg, Germany",abuse@core-backbone.com,+4991131043200
5288114,98.196.0.0/14,US,group,Network Abuse and Policy Observance,"1800 Bishops Gate Blvd, Mount Laurel, NJ, 08054, United States",abuse@comcast.net,+18885654329
512530,23.240.0.0/14,US,group,Abuse,"P.O. Box 4987, Greenwood Village, CO, 80155, United States",abuse@charter.net,+18777772263
5696043,106.108.0.0/14,CN,group,IRT-CHINANET-CN,"No.31 ,jingrong street,beijing, 100032","anti-spam@chinatelecom.cn, abuse_gdicnoc@163.com",+862087189274
10706703,223.144.0.0/12,CN,group,IRT-CHINANET-CN,"No.31 ,jingrong street,beijing, 100032",anti-spam@chinatelecom.cn,+861058501724
6192432,120.16.0.0/13,AU,group,IRT-VODAFONE-AU,"Level 1, 177 Pacific Highway, North Sydney, NSW",ipadmin@tpgtelecom.com.au,+611800683683
6263681,122.52.122.148/32,PH,group,IRT-PLDT-PH,"Philippine Long Distance Telephone Company, G/F PLDT Smart Integrated Center (IOC), Nicanor Garcia St, Makati City, Philippines",abuse@pldt.com.ph,+6325840201
3254357,79.55.0.0/17,IT,group,Abuse Consumer TIM,"Telecom Italia S.p.A., Abuse Consumer Customer Area",abuse@retail.telecomitalia.it,+390636881
7517995,180.160.0.0/12,CN,group,IRT-CHINANET-CN,"No.31 ,jingrong street,beijing, 100032",anti-spam@chinatelecom.cn,"+862150623458, +862168405784"

3. File Relationship Diagram

The diagram below illustrates the relationships between the various files included in the CSV database package. It shows how the main CSV file connects to reference table for abuse contact details, ensuring accurate data linkage and integrity.

Image

File Format & Encoding

All IP to Abuse Contact CSV datasets are provided in UTF-8 encoding, comma-separated, and compressed with Gzip (.csv.gz). Each file includes a header row listing the field names for clarity and consistency.

Field values are unquoted by default, with quotes applied only in the following cases:

  • Line breaks within text fields.
  • Commas inside a value (e.g., addresses).
  • Lists of values (e.g., languages).
  • Spaces that may be auto-quoted by export tools.

MMDB Database Documentation


1. Overview

MMDB version of the database consists of three files: one MMDB file containing all the abuse contact data, a README file, and a checksum file, all compressed together in a ZIP file for easy delivery.


2. Archive Content

After downloading and extracting the IP to Abuse Contact MMDB database archive, you'll find the following files (with their types noted):

db-ip-abuse.mmdb
db-ip-abuse.mmdbdb-ip-abuse.mmdb

Provides full abuse contact details for IP addresses: network, country, kind, and contact info.

  • File Size: 789.79 MB
  • Entries: 47.5M
README.md
README.mdREADME.md

Documentation for dataset contents, schema, usage, and support.

  • File Size: 3.92 KB
checksum.txt
checksum.txtchecksum.txt

SHA-256 checksums for verifying file integrity.

  • File Size: 159 Bytes

Response Schema

This section describes the structure of the data returned from the IP to Abuse Contact MMDB file. Each field is detailed with its type, meaning, and example values to help you interpret responses and integrate them into your applications.


1. db-ip-abuse.mmdb

This file contains abuse contact details for both IPv4 and IPv6 address ranges. Below is an example of the structure you will encounter in the response.


2. Field Reference

The following reference lists all fields available in the MMDB response. Each entry includes the field path, its description, data type, and example value to help you understand how to parse and integrate the data.

Showing 0 of 7
Select a field to view details

I. Example Records

Example
{
  "abuse": {
    "address": "No.31 ,jingrong street,beijing, 100032",
    "country_code": "CN",
    "emails": "anti-spam@chinatelecom.cn",
    "kind": "group",
    "name": {
      "en": "IRT-CHINANET-CN"
    },
    "phone_numbers": "+862150623458, +862168405784",
    "route": "180.160.0.0/12"
  }
}

Database Integrity & Authenticity Verification

There are two methods of verifying the integrity and authenticity of our Database:


1. Using the Signature File (Recommended)

IPGeolocation.io signs every database release to ensure its authenticity and integrity. This allows customers to verify that a downloaded IP to Abuse Contact database file originates directly from IPGeolocation.io and has not been altered, corrupted, or tampered with during transfer or storage.

Each database update includes a corresponding signature file, generated using our private signing key. Customers can validate the database using the provided public verification key. To verify a database file, you need:

  1. Database file (the downloaded archive)
  2. Signature file (the matching signature for that archive)
  3. Public key (public-key.pem)

These files are available via official IPGeolocation.io download endpoints and are also shared in database update notifications.


2. Using the Checksum File (Legacy)

Each database archive includes a checksum.txt file containing the SHA-256 checksums for the files packaged in the archive. You can use this file to validate that the extracted contents are complete and unchanged.


Data Format & Constraints

  • All fields defined in the schema are always present in the IP to Abuse Contact MMDB response.
  • Fields may contain empty strings (""), but never null, so null checks are not required.
  • Place names such as countries, states, districts, and cities are available in multiple translations.
  • All text values are encoded in UTF-8.
  • Field names and response structure remain stable across updates for backward compatibility.

Database Updates & Delivery

When you subscribe to our IP to Abuse Contact database, we'll send you static download links. These links never change, so you can use them both for your initial download and for all future updates. You will receive:

  1. Database Archive URL : downloads the latest release of your subscribed database (CSV, MMDB or requested formats).
  2. Signature File URL : downloads the matching signature file for the latest release (used for authenticity verification).
  3. Public Key URL : downloads the public verification key (used with the signature file).
  4. Status Endpoint URL : returns the database's most recent update timestamp.

Our databases are updated continuously and shipped on a daily or weekly cycle depending on your plan, ensuring you always have access to the most current data. Each time your subscribed dataset is updated, you'll also receive an email notification so you don't miss a release.

For automated workflows, you can check our status endpoint to see the last update timestamp. When the date changes, simply re-fetch the archive using your static download URL to pull the latest version into your system.

Subscribe to Our Newsletter

Get the latest in geolocation tech, straight to your inbox.