Blog
Longer answers to the questions a report cannot fit in a panel. What a record can settle, what it cannot, and where a signal that looks decisive is worth less than it appears.
No news and no announcements. Each piece is about a decision somebody is in the middle of, and it names the registries, feeds and prefixes involved rather than talking around them.
-
What an LOA is for IP address space, and what your upstream actually checks
No RFC defines the letter, no registry issues or validates one, and its whole authority rests on the reader believing a signature. What providers actually publish, which two unrelated documents share the abbreviation, who can legitimately sign for leased space, and the records that carry the weight the letter only claims.
-
Reading a bounce: is the receiver blaming your IP, your domain, or your message?
Before you change anything, work out which of the three the receiver objected to. What each part of a rejection is allowed to mean, why the registry meaning of a code and a receiver's meaning have drifted apart, and the line in the standards that explains why a bounce never tells you the whole story.
-
How long should an IP block last? Ageing out address based rules
Nobody publishes a recommended duration, and a timer is the wrong instrument anyway. How fast address space really changes hands, why the registration date will not tell you, which lists expire themselves and which do not, and a review that answers the only question that matters: is this still the thing you blocked?
-
How to find the sending IP address in an email header, and which Received line to trust
Received lines read newest first, and only the one your own server wrote is evidence; the bottom line most guides point at is the easiest to fake. What each field proves, where else receivers record the address, why webmail often carries none, and what the address you find actually is.
-
Can an IP address be spoofed? What a source address in your logs does and does not prove
Yes for a bare datagram, practically no for a completed session, and the transport is the tell. Why the addresses flooding you are often other victims, why most "my IP was spoofed" claims are about something else, and what a source address in a log can honestly be said to prove.
-
What SWIP is and when you must register customer assignments
The word is ARIN's, the obligation exists at every registry, and the details differ: ARIN's /29 and seven-day rule, RIPE's register-everything rule, APNIC's non-public option. What a sub-assignment record proves, the innocent reasons one may be missing, and what it does for abuse routing and geolocation.
-
Who held an IP address on a given date? How IP address history lookups work
Every dated question about an address, from a log line to a due-diligence file, is answered from two ledgers: the routing archives that show who was announcing it and the registry records that show who was responsible for it. Where each is kept, how far back each reaches, and why the dates need reading before they are trusted.
-
IRR route objects: what they are, where to create one, and whether a ROA replaces it
Your prefix is being filtered and somebody said "route object". What one is, why transit providers still generate their filters from them, which registry counts, who creates the object for leased space, and the per-upstream answer to whether a ROA has made it unnecessary.
-
Legacy IPv4 space: what the label means, and what it changes for a buyer
Legacy is a registry status, not a class of address. What the label means at each registry, what it changes for ROAs, route objects and fees, whether it survives a sale, and the checks a buyer runs before signing for a block issued before the registries existed.
-
Can you trace an IP address to a person? What a lookup really finds
The most asked question in the subject deserves a straight answer: from public data you can trace an address to a network, in remarkable detail, and you cannot trace it to a person, at all. Where the trail runs, where it stops, and why the first half is worth more than people think.
-
How to report IP abuse and actually get a response
Every block of address space has a published abuse contact whose job is to hear about misbehaviour, and most reports sent there die unread anyway. The right mailbox, the evidence an operator can act on, what to expect back, and where to escalate when the contact is dead.
-
What SPF, DKIM and DMARC do not fix: authentication vs IP reputation
You set up all three records, the checks pass, and mail still lands in spam. Nothing is misconfigured: authentication answers who sent the mail, reputation answers whether anyone wants it, and receivers require both. The two halves, kept honestly apart.