- Abuse address, defined
- An abuse address is the
abuse@mailbox a domain is expected to operate under RFC 2142, where other operators report spam, attacks and compromised accounts originating from it.
The specification names several role mailboxes a domain should answer, and this is the one with operational consequences. Spamhaus and others check it exists and use it to contact you.
Reports arriving here are usually structured. The Abuse Reporting Format wraps the offending message with metadata, so a parser can route it without a person reading every one.
Monitoring it protects you in both directions. A compromised account sending spam through your infrastructure shows up here days before the blocklist listing does.
It must never require authentication or a captcha, and it must accept mail from anyone. An abuse address behind a contact form defeats the entire purpose.
How ZapBounce reports it
Role addresses including abuse@ are flagged as role alongside their deliverability verdict. That flag is a hint about suitability for a marketing send, not a judgment about whether the mailbox works.
A compromised mailbox, seen from the abuse inbox
Say a 40-person firm has one employee who reused a password on a breached site. At 1:50 a.m. an attacker logs in to the mail account and starts sending. By 2:10 the first complaint lands at abuse@ from a large mailbox provider's feedback system, followed by a steady stream.
Each report follows the Abuse Reporting Format from RFC 5965 and has three parts. It opens with a short human-readable note. Next is a machine-readable block with fields such as Feedback-Type: abuse, the reporting source and the arrival date. Last comes a copy of the offending message with its full headers, which names the account that sent it.
If someone reads that inbox, or software does, the account is locked by breakfast and the damage is a few thousand messages. When nobody does, the firm finds out two days later, when the office IP is on a blocklist and client mail starts bouncing.
Four checks on your own abuse mailbox
First, send it a message from an outside account, such as a personal Gmail, and see where it goes. You're confirming three things. It exists, it accepts mail from strangers, and a named person receives it.
Second, exempt it from spam filtering, which is the step you're most likely to miss. Abuse reports contain copies of spam and phishing by design, so a content filter will happily quarantine them, and the mailbox that exists to receive bad news never gets any.
Third, check who's listed as the abuse contact for your IP addresses, if you hold your own ranges. Regional internet registries keep an abuse contact on each allocation, and that's where reports about your network traffic are sent. An address belonging to someone who left years ago is common.
Fourth, decide what happens next. A report should open a ticket or page someone, with a plain first action: find the sending account, lock it, reset its credentials.
Abuse address: common questions
Is an abuse address required?
RFC 2142 expects it, and blocklist operators treat its absence as a negative signal. It is a convention with real consequences.
Who sends mail to abuse addresses?
Other network operators, blocklist maintainers and automated reporting systems. Listing notices arrive here first.
Should I include abuse@ in a marketing list?
Never. Mailing a role address of this kind is a fast route to being reported by the person whose job that is.