<div dir="auto"><div><div><br></div><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Sun, 27 Sept 2026, 1:24 pm Loganaden Velvindron, <<a href="mailto:loganaden@gmail.com">loganaden@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On Sat, 26 Sept 2026 at 12:23, Ben Roberts - AfriNIC<br>
<<a href="mailto:ben.roberts@afrinic.net" target="_blank" rel="noreferrer">ben.roberts@afrinic.net</a>> wrote:<br>
><br>
> Logan,<br>
> It might be wrong to assume that all quarantined and returned space is contaminated. I’m sure that cyber threat blacklist companies have their own methods of determining address space with threats. I might be wrong to just ask to block all returned space (thus rendering it potentially useless to a future user who has been allocated the space).<br>
><br>
> Is there a particular problem that you are trying to solve ?<br>
<br>
The problem statement is quite simple: There is currently no dedicated<br>
web page on AFRINIC website where<br>
we can see the list of quarantine and/or recovered IPs. I would be<br>
happy for AFRINIC to prove me wrong here.<br>
This information is *very useful* for Cybersecurity threat Intel<br>
providers, ISPs, and other blocklist operators<br>
to remove IPs from blocklists.<br>
<br>
ARIN has this: <a href="https://www.arin.net/resources/guide/ipv4/blocks_cleared/" rel="noreferrer noreferrer" target="_blank">https://www.arin.net/resources/guide/ipv4/blocks_cleared/</a><br>
<br>
I quote from ARIN web page:<br>
"This page lists the addresses used to fulfill waiting list requests.<br>
We encourage blocklist operators to use this data to remove<br>
potentially stale reputation information based on activity by the<br>
previous registrant."<br>
<br>
I work very closely with Cybersecurity Threat Intel Providers. I'm<br>
seeing a lot of automation happening in this space. If AFRINIC<br>
provides a page similar<br>
to the ARIN one, it would be easier for Cybersecurity Threat Intel<br>
Providers to *reduce stale information* from their blocklists.<br>
<br>
Is the problem statement clear Ben ?<br></blockquote></div></div><div dir="auto"><br></div><div dir="auto">This is clear logan and such a VAS shall come in handy once implemented so that other actors beyond cybersec folks make use of the data.</div><div dir="auto"><br></div><div dir="auto">Cheers,</div><div dir="auto">./noah</div><div dir="auto"><br></div><div dir="auto"><br></div><div dir="auto"><div class="gmail_quote gmail_quote_container"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<br>
_______________________________________________<br>
RPD mailing list<br>
<a href="mailto:RPD@afrinic.net" target="_blank" rel="noreferrer">RPD@afrinic.net</a><br>
<a href="https://lists.afrinic.net/mailman/listinfo/rpd" rel="noreferrer noreferrer" target="_blank">https://lists.afrinic.net/mailman/listinfo/rpd</a><br>
</blockquote></div></div></div>