prop-172: Defining Internet Abuse through IP Addresses

Proposal text prop-172-v002.txt
Objective

This proposal introduces a clear and explicit definition of “Internet Abuse through IP Addresses” (or “IP address abuse”) into APNIC policy documents.
If adopted, APNIC policy would, for the first time, contain an agreed definition of this term. That definition would:
• identify the categories of conduct that constitute IP address abuse;
• state how such conduct is adjudicated in the first instance, and clarify APNIC’s own role in that process; and
• be precise enough to serve as a stable foundation for any future policy proposal on resource holder obligations.
This proposal does not aim to create any new obligation, reporting requirement, or compliance mechanism. Section 4 does describe a resource holder’s responsibility to respond to abuse, and APNIC’s role in holding them accountable for doing so — but that responsibility already exists under APNIC’s current policy requiring resource holders to monitor and respond to abuse reports. Whether any further obligations should attach to this definition is left for future policy discussion.

Current status For Discussion at APNIC62 OPM
Authors

Alban Kwan

Relevant forum Policy SIG
Previous versions

prop-172-v001.txt

Secretariat impact assessment

This impact assessment is for v001

1. APNIC’s Understanding of the Proposed Policy

APNIC understands this proposal as introducing a formal definition of ‘Internet Abuse through IP Addresses’ into APNIC policy.

The proposal states that it does not create new enforcement powers, reporting requirements, or compliance mechanisms. However, the text also says APNIC retains responsibility for holding resource holders accountable for responding to and addressing abuse.

APNIC Secretariat have noted that this overlaps with the current IRT policy, which already requires IRT contacts to be maintained and validated.

2. Impact of Proposed Policy on Registry and Addressing System

No direct registry impact expected

3. Impact of Proposed Policy on APNIC Operation/Services

APNIC Secretariat notes that the main issue is ambiguity about APNIC’s role.
The proposal says APNIC does not have the power to adjudicate abuse, but also says APNIC retains responsibility for holding resource holders accountable for responding to and addressing abuse. It is unclear how both can be true without creatingn some form of operational enforcement role.
APNIC is not currently resourced to perform this work, and the associated cost may not be something the membership would expect or support.

As of 17 Aug, 2026, 2,359 out of a total of 10,815 active APNIC accounts (21.8%) had no validated IRT emails associated with their resources. APNIC marks IRT emails as invalid 15 days after sending the validation request and restricts MyAPNIC access if the validation is not completed in 30 days.
This figure does not take into account those that will validate within the 30 day window, it is a point-in-time reference.

4. Legal Impact of Policy

The proposal would define “Internet Abuse through IP Addresses” as the use of IP addresses in a way that causes technical harm to the security, stability, or trust of the Internet. It would also include facilitating unlawful conduct that the resource holder has the practical ability to address.

 Although presented as a definition, the proposal also discusses responsibilities, how abuse is determined, and circumstances where a resource holder may be protected from further action. These elements appear to go beyond a simple definition and could be interpreted as introducing broader operational expectations. A number of legal and implementation issues may arise if the proposal is adopted.

 The reference to “unlawful conduct” creates uncertainty because APNIC serves account holders operating across many different jurisdictions. Conduct that is unlawful in one jurisdiction may be lawful in another. In some cases, conduct that is unlawful in one jurisdiction may even be required by law in another. Resource holders may also be based in, and operate across multiple jurisdictions, so the legality of behaviour may differ between those different locations.

 The proposal states that APNIC does not have the power to adjudicate abuse. However, it also states that APNIC has an existing responsibility to hold resource holders accountable for responding to and addressing abuse. We do not consider this to be an accurate reflection of current policy. Section 5.3.3 of the APNIC Internet Number Resource Policies requires resource holders to maintain responsive IRT contacts and requires APNIC to validate those contacts. It does not require APNIC to investigate alleged abuse, determine whether abuse has occurred, or assess whether a resource holder’s response was adequate.

 There also appears to be some conflict between these two statements. Determining whether abuse has been “addressed” would generally require first determining whether abuse occurred. This would place APNIC in an adjudication role, which the proposal expressly states APNIC does not have.  In any case, only a competent authority (e.g. – a court) is capable of determining whether conduct is unlawful.

 It is also unclear what is meant by “fraudulently … sub-allocating IP address resources” and how such conduct would occur in practice.

 The policy objective states that the definition is intended to serve as a foundation for future policy proposals. While we would not normally comment on possible future proposals, it is worth noting that any future policy requiring APNIC to assess or enforce whether abuse has been addressed would represent a significant expansion of APNIC’s current role. Historically, APNIC’s responsibilities have focused on Internet number resource management and related technical matters rather than assessing conduct or content. Such a change would likely require additional resources, expertise, and risk management measures and should be considered expressly in advance of any such change.

 If “unlawful conduct” remains part of the definition, several practical questions would remain unresolved. For example, when would a finding of unlawfulness be considered sufficiently final? Would all appeals need to be exhausted? How would conflicting decisions from different jurisdictions be handled? These issues could create substantial administrative complexity and may affect APNIC’s neutrality.

 The Secretariat notes that implementation may benefit from greater clarity about the intended scope of the definition. In particular, it may be helpful to confine matters to a technical definition of abuse without any operational or enforcement expectations that may arise from it. A definition based on established technical standards (such as those from IETF) may provide a more objective foundation than concepts based on lawfulness, although this would not resolve all implementation issues. Terms such as “facilitating”, “hosting”, “phishing”, “fraud”, “scam”, and “impersonation” should also be carefully considered to ensure the definition does not unintentionally expand APNIC’s role into determining questions of unlawful conduct or content.

5. Implementation

Until such point as the above clarifications are made, we are unable to make a determination on implementation process and time frames.

Proposal history
10 August 2026 Version 1 posted to the Policy SIG mailing list for community discussion.
26 August 2026 Secretariat impact assessment posted to the Policy SIG mailing list for community discussion.
2 September 2026 Version 2 posted to the Policy SIG mailing list for community discussion.