---
title: "IP Abuse Contact Database Documentation – IPGeolocation Docs"
slug: "/documentation/ip-abuse-contact-database.html"
parent: "IP Geolocation Databases"
description: "Discover abuse contact details for any IP address with our deep IP Abuse Contact Database. Enhance your cybersecurity efforts & streamline incident reporting."
---

# IP Abuse Contact Database

* * *

## Overview

Our IP Abuse Contact Database gives you instant access to the correct abuse desk for any routable IP that connecting you to verified addresses, phone numbers, and emails worldwide. By mapping IPs to the responsible operator (ISPs, cloud providers, hosting networks, and enterprises) and their preferred reporting channels, it streamlines abuse escalation, speeds up takedowns, and helps you quickly pinpoint the source of malicious or unwanted activity to keep your environment safer.

Updated daily and delivered as CSV and MMDB, with JSON, Parquet, or any custom export on request at no extra cost and backed by stable schemas and changelogs. Each record includes organization and netblock context, primary abuse mailbox and phone. Below, you'll find full documentation of the archive contents, schema definitions, file specifications, and integration notes to help you integrate with SIEM/SOAR, ticketing, and security workflows—fast.

* * *

## Available Database Formats

**CSV**

*   File Size: 347.14 MB

*   Entries: 33.9M

*   Fields: 9

*   Last Updated: Today

[Documentation](https://ipgeolocation.io/documentation/ip-abuse-contact-database.html#csv-database-documentation)

**MMDB**

*   File Size: 790.32 MB

*   Entries: 33.9M

*   Fields: 9

*   Last Updated: Today

[Documentation](https://ipgeolocation.io/documentation/ip-abuse-contact-database.html#mmdb-database-documentation)

> [!IMPORTANT]
> If you require our IP to Abuse Contact Database in a different format, such as Parquet or any custom structure, please feel free to reach out to us via our [Contact form](https://ipgeolocation.io/db-pricing.html#contact-us-for-quote). We are happy to accommodate specific format requests to meet your needs.

* * *

## CSV Database Documentation

* * *

### 1. Overview

The CSV version is a set of Gzip-compressed CSV files containing IP ranges and their Abuse Contact details. Designed for bulk imports and integration into relational databases.

* * *

### 2. Archive Content

After downloading and extracting the IP to Abuse Contact CSV database archive, you'll find the following files (with their types noted):

**db-abuse-details.csv.gz**

Gzip-compressed CSV provides abuse contact info: unique ID, network, and contact details.

*   File Size: 114.97 MB

*   Entries: 12.4M

*   Fields: 8

**db-ip-abuse.csv.gz**

Each start_ip, end_ip link to the abuse details ID that is related to the abuse-details file.

*   File Size: 232.17 MB

*   Entries: 33.9M

*   Fields: 3

**README.md**

Documentation for dataset contents, schema, usage, and support.

*   File Size: 5.60 KB

**checksum.txt**

SHA-256 checksums for verifying file integrity.

*   File Size: 251 Bytes

* * *

## Schema

This section describes the schema of each file included in the IP to Abuse Contact Database archive. For every file, you'll find its purpose, field definitions, and examples to help with integration.

* * *

### 1. db-ip-abuse.csv.gz

This file contains IP address ranges linked to abuse details. It maps each IP block to a unique `abuse_details_id` , which in turn corresponds to the abuse contact information.

| Field | Type | Description | Can be empty? | Example |
| --- | --- | --- | --- | --- |
| start_ip | string | The starting IP address of the range in IPv4 or IPv6 format. | No  | 192.168.0.1 |
| end_ip | string | The ending IP address of the range in IPv4 or IPv6 format. | No  | 192.168.0.255 |
| id  | number | The unique identifier for the abuse contact. | No  | 1   |

> [!TIP]
> `abuse_details_id` joins to `db-abuse-details.id` to get abuse contact information for IP.

#### I. Example Records

**Example**

```json
start_ip,end_ip,abuse_details_id
72.78.171.5,72.78.171.5,2876618
87.0.171.170,87.0.171.170,4360973
188.36.125.202,188.36.125.202,7992659
14.19.59.73,14.19.59.73,423479
69.70.85.229,69.70.85.229,2612731
77.103.140.7,77.103.140.7,3226832
5.246.176.27,5.246.176.27,127950
2601:2c5:4485:d050:146:f651:45e4:26b4,2601:2c5:4485:d050:146:f651:45e4:26b4,11567669
85.108.232.6,85.108.232.6,4257930
199.187.181.28,199.187.181.28,8887681
```

* * *

### 2. db-abuse-details.csv.gz

This file provides detailed abuse contact information. It links a unique ID to a specific network, country, and other contact details, including name, address, emails, and phone numbers.

| Field | Type | Description | Can be empty? | Example |
| --- | --- | --- | --- | --- |
| id  | number | The unique identifier for the abuse contact. | No  | 1   |
| network | string | The network associated with the abuse contact. | Yes | 192.168.1.0/24 |
| country | string | The ISO 3166-1 alpha-2 code of the country associated with the abuse contact. | Yes | US  |
| kind | string | The kind specifies whether the contact is a person or an organization. | Yes | group |
| name | object | The name (english) of the abuse contact. | Yes | Abuse Team |
| address | string | The physical address of the abuse contact. | Yes | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA |
| emails | string | Comma-separated email addresses associated with the abuse contact. | Yes | abuse@example.com |
| phone_numbers | string | Comma-separated phone numbers associated with the abuse contact. | Yes | +1-800-555-0199 |

> [!TIP]
> `id` in the db-abuse-details.csv.gz file joins to the `abuse_details_id` field in db-ip-abuse.csv.gz

#### I. Example Records

**Example**

```json
id,network,country,kind,name,address,emails,phone
11567669,2601:2c0::/26,US,group,Network Abuse and Policy Observance,"1800 Bishops Gate Blvd, Mount Laurel, NJ, 08054, United States",abuse@comcast.net,+18885654329
8887681,199.187.180.0/22,US,individual,Brandon Kester,"5350 Hwy 66, Ashland, OR, 97520, United States",brandon@projecta.com,"+15412615637, +15414889207"
3226832,77.103.140.0/22,US,group,Abuse-C Role,"Virgin Media, 500 Brook Drive Green Park, Reading, Berkshire, RG2 6UU",abuse@virginmediao2.co.uk,+443703904848
127950,5.246.0.0/15,EG,group,Mobily Admin Abuse Reporting,"P.O 69179, Riyadh 11423",abuse@mobily.com.sa,"+966560316152, +966560313263"
4360973,87.0.0.0/12,IT,group,Abuse Consumer TIM,"Telecom Italia S.p.A., Abuse Consumer Customer Area",abuse@retail.telecomitalia.it,+390636881
4257930,85.108.0.0/16,TR,group,Abuse Role,"Turk Telekomunikasyon A.S Turgut Ozal Blv. Aydinlikevler, 06103 ANKARA TURKEY",abuse@turktelekom.com.tr,"+903125550000, +903123131924"
2612731,69.70.64.0/19,CA,group,Network Operations Center,"150, Beaubien Ouest, Montreal, QC, H2V 1C4, Canada",abuse@videotron.ca,+15142818498
423479,14.16.0.0/12,CN,group,IRT-CHINANET-CN,"No.31 ,jingrong street,beijing, 100032","anti-spam@chinatelecom.cn, abuse_gdicnoc@163.com",+862087189274
7992659,188.36.120.0/21,HU,group,Abuse-C Role,"Konyves Kalman korut 36., 1097, Budapest, HUNGARY",abuse@telekom.hu,
2876618,72.73.128.0/17,US,group,Abuse,"22001 Loudoun County Parkway, Asburn, VA, 20147, United States","abuse@verizon.com, abuse-mail@verizonbusiness.com",+18009000241
```

* * *

### 3. File Relationship Diagram

The diagram below illustrates the relationships between the various files included in the CSV database package. It shows how the main CSV file connects to reference table for abuse contact details, ensuring accurate data linkage and integrity.

![Image](https://static.ipgeolocation.io/web-assets/images/database/er-diagrams/ip-abuse.svg)

* * *

## File Format & Encoding

All IP to Abuse Contact CSV datasets are provided in UTF-8 encoding, comma-separated, and compressed with Gzip (.csv.gz). Each file includes a header row listing the field names for clarity and consistency.

Field values are unquoted by default, with quotes applied only in the following cases:

*   Line breaks within text fields.
*   Commas inside a value (e.g., addresses).
*   Lists of values (e.g., languages).
*   Spaces that may be auto-quoted by export tools.

* * *

## MMDB Database Documentation

* * *

### 1. Overview

MMDB version of the database consists of three files: one MMDB file containing all the abuse contact data, a README file, and a checksum file, all compressed together in a ZIP file for easy delivery.

* * *

### 2. Archive Content

After downloading and extracting the IP to Abuse Contact MMDB database archive, you'll find the following files (with their types noted):

**db-ip-abuse.mmdb**

Provides full abuse contact details for IP addresses: network, country, kind, and contact info.

*   File Size: 790.31 MB

*   Entries: 33.9M

**README.md**

Documentation for dataset contents, schema, usage, and support.

*   File Size: 3.92 KB

**checksum.txt**

SHA-256 checksums for verifying file integrity.

*   File Size: 159 Bytes

* * *

## Response Schema

This section describes the structure of the data returned from the IP to Abuse Contact MMDB file. Each field is detailed with its type, meaning, and example values to help you interpret responses and integrate them into your applications.

* * *

### 1. db-ip-abuse.mmdb

This file contains abuse contact details for both IPv4 and IPv6 address ranges. Below is an example of the structure you will encounter in the response.

* * *

### 2. Field Reference

The following reference lists all fields available in the MMDB response. Each entry includes the field path, its description, data type, and example value to help you understand how to parse and integrate the data.

#### I. Example Records

**Example**

```json
{
  "abuse": {
    "address": "22001 Loudoun County Parkway, Asburn, VA, 20147, United States",
    "country_code": "US",
    "emails": "abuse@verizon.com, abuse-mail@verizonbusiness.com",
    "kind": "group",
    "name": {
      "en": "Abuse"
    },
    "phone_numbers": "+18009000241",
    "route": "72.73.128.0/17"
  }
}
```

* * *

## Database Integrity & Authenticity Verification

There are two methods of verifying the integrity and authenticity of our Database:

* * *

### 1. Using the Signature File (Recommended)

IPGeolocation.io signs every database release to ensure its authenticity and integrity. This allows customers to verify that a downloaded IP to Abuse Contact database file originates directly from IPGeolocation.io and has not been altered, corrupted, or tampered with during transfer or storage.

Each database update includes a corresponding signature file, generated using our private signing key. Customers can validate the database using the provided public verification key. To verify a database file, you need:

1.  Database file (the downloaded archive)
2.  Signature file (the matching signature for that archive)
3.  Public key (public-key.pem)

These files are available via official IPGeolocation.io download endpoints and are also shared in database update notifications.

> [!NOTE]
> The public key may be provided as PEM-encoded text. Save it to a file named public-key.pem
>
> Ensure OpenSSL is installed on your system. If not, install it using the following commands
>
> On Linux, if openssl is not installed
>
> ```shell
> sudo apt install openssl
> ```
>
> Verify OpenSSL installation:
>
> ```shell
> openssl version
> ```
>
> To verify the database file, run the following command, replacing the placeholders with your actual file paths:
>
> ```shell
> openssl dgst -sha256 -verify <path-to-public-key.pem> -signature <path-to-signature-file.sig> <path-to-database-file.zip>
> ```
>
> Example output:
>
> ```shell
> Verified OK
> ```
>
> if verification `FAILED` do not use the file, re-download the database and signature from official IPGeolocation endpoints. If the issue persists, please [contact our support team](https://ipgeolocation.io/contact.html).

* * *

### 2. Using the Checksum File (Legacy)

Each database archive includes a checksum.txt file containing the SHA-256 checksums for the files packaged in the archive. You can use this file to validate that the extracted contents are complete and unchanged.

> [!TIP]
> Always verify downloaded files with the provided checksum before importing.
>
> On Linux, if sha256sum is not installed, first run:
>
> ```shell
> sudo apt-get install coreutils
> ```
>
> Then check the archive files against the checksum file with:
>
> ```shell
> sha256sum -c checksum.txt
> ```
>
> Example output:
>
> ```shell
> db-abuse-details.csv.gz: OK
> db-ip-abuse.csv.gz: OK
> README.md: OK
> ```
>
> *your output may differ depending on the specific database archive you downloaded.
>
> If a file's checksum does not match, `FAILED` will be shown instead of `OK` . If verification fails, first confirm that the download completed correctly; if the issue persists, please [contact our support team](https://ipgeolocation.io/contact.html).

> [!IMPORTANT]
> Signature verification confirms both authenticity and integrity. Checksum verification confirms integrity only (it detects corruption/modification, but does not independently prove who produced the file).

* * *

## Data Format & Constraints

*   All fields defined in the schema are always present in the IP to Abuse Contact MMDB response.
*   Fields may contain empty strings (""), but never null, so null checks are not required.
*   Place names such as countries, states, districts, and cities are available in multiple translations.
*   All text values are encoded in UTF-8.
*   Field names and response structure remain stable across updates for backward compatibility.

* * *

## Database Updates & Delivery

When you subscribe to our IP to Abuse Contact database, we'll send you static download links. These links never change, so you can use them both for your initial download and for all future updates. You will receive:

1.  **Database Archive URL :** downloads the latest release of your subscribed database (_CSV, MMDB or requested formats_).
2.  **Signature File URL :** downloads the matching signature file for the latest release (_used for authenticity verification_).
3.  **Public Key URL :** downloads the public verification key (_used with the signature file_).
4.  **Status Endpoint URL :** returns the database's most recent update timestamp.

Our databases are updated continuously and shipped on a daily or weekly cycle depending on your plan, ensuring you always have access to the most current data. Each time your subscribed dataset is updated, you'll also receive an email notification so you don't miss a release.

For automated workflows, you can check our status endpoint to see the last update timestamp. When the date changes, simply re-fetch the archive using your static download URL to pull the latest version into your system.
