Blog
Longer answers to the questions a report cannot fit in a panel. What a record can settle, what it cannot, and where a signal that looks decisive is worth less than it appears.
No news and no announcements. Each piece is about a decision somebody is in the middle of, and it names the registries, feeds and prefixes involved rather than talking around them.
-
What is bulletproof hosting? Recognizing abuse tolerant networks in registry and routing records
The servers are ordinary; what is sold is tolerance. How the documented operations worked and ended, from the transit cutoff that visibly dented global spam to the German bunker convictions, and the pattern of traces an analyst can read in any public record.
-
Does your ASN affect IP reputation? Choosing where your clean space gets announced
Two published lists judge whole autonomous systems rather than addresses, so identical clean space reads differently depending on who announces it. What your prefix inherits from its origin, how to vet one before you commit, and why moving a burned range somewhere cleaner launders nothing.
-
Whois status decoded: what ASSIGNED PA, SUB-ALLOCATED PA, LEGACY and the rest actually mean
The status field is registry vocabulary, not a quality score. The strings all five registries print, what each says about who holds the space and who can hand it onward, and the misreadings that cost buyers and investigators real money.
-
Proving a range changed hands: the four dates a delisting request can call day one
A list operator asks you to show the space is under new management. That is four dated events, not one, and nothing obliges them to line up. Which to claim, how to build something the recipient can verify, and why a complete exhibit obliges nobody.
-
After an IPv4 transfer completes: the record updates to make before you announce
The registry moving the block is step zero. The seller's ROAs die with the transfer, stale route objects do not, and a covering ROA that outlives the move can make your first announcement invalid. The cleanup runbook, ordered by what breaks hardest when skipped.
-
How to read a prefix's routing history: gaps, origin changes and deaggregation
The announcement timeline is a record the registry does not keep, and it survives every transfer. What a long dark gap, a parade of origins and a block dissolving into /24s each mean, benign and ugly readings both, and what the collectors cannot see.
-
Why clean hosting addresses still get CAPTCHAs, and what an operator can actually change
The range is spotless and the challenges keep coming, because hosting origin is treated as a category rather than as a verdict on your record. What the web side actually publishes about it, what you can publish back, and the honest ceiling on what publishing achieves.
-
Block the address, the /24, or the whole ASN? Sizing a block to the evidence you have
Each step up in width changes who else is inside the rule, and none of them appears in the evidence that started the incident. What a /24 actually contains, why an AS number is not a company, and how to pick a width you can defend at review.
-
iCloud Private Relay, browser relays and corporate egress: when a proxy address belongs to a legitimate user
A whole class of relays carries ordinary people by default, switched on by a phone setting or a corporate deployment nobody mentioned. What the operators publish about their egress space, what those files cannot settle, and how to treat a proxy signal as context rather than a verdict.
-
PA vs PI address space: which addresses you keep when you leave your provider
One status string on the registry record decides whether a block travels with you or goes back to the provider. What the labels mean, what each registry's own text says about returning space, why new PI is not for sale in the RIPE region, and the two things portability does not buy.
-
Running an abuse desk: the abuse-c record, the validation cycle, and what happens when nobody answers
The receiving end of a complaint. Where the contact for your space actually comes from, why a customer sub-block with no record of its own resolves to you, what your registry checks and how often, and why the people keeping score are not the registry at all.
-
An IP address alone proves nothing: the timestamp, time zone and source port that make it evidence
Behind shared addresses the address names a gateway, not a subscriber, and what narrows it to one session is the port and the moment. What the standards ask you to log, why a conforming timestamp still may not be UTC, and what the other side may not have kept.