Manage & analyze reports

Abuse emails cost hosters hours. The Abuse Manager centrally collects your abuse mailboxes, automatically matches reports to your IP ranges and analyzes every report automatically - including risk assessment and concrete recommendations.

With free accountDSGVO-konformHosted in Germany

What you get

Email forwarding

Your own abuse address - incoming reports are processed automatically.

IP range matching

Reports are automatically matched to your CIDR ranges.

Automated analysis

Risk assessment, technical details and recommended actions per report.

Statistics

Categories, severities, top IPs - the complete evaluation.

Workflow status

New -> Investigating -> Resolved or False Positive - fully traceable.

Features in detail

Email forwarding

Your own abuse address - incoming reports are processed automatically.

IP range matching

Reports are automatically matched to your CIDR ranges.

Automated analysis

Risk assessment, technical details and recommended actions per report.

Statistics

Categories, severities, top IPs - the complete evaluation.

Workflow status

New -> Investigating -> Resolved or False Positive - fully traceable.

For teams

Abuse management in a team with clear responsibilities.

How it works

01

1. Set up abuse address

Forward your abuse emails to your personal manager address.

02

2. Add IP ranges

Define CIDR ranges - reports are matched automatically.

03

3. Get automated analyses

Every report is analyzed and equipped with recommendations.

Frequently asked questions

What is the Abuse Manager?

The Abuse Manager bundles all attack reports against your servers: manage reported IPs, analyze patterns (AI-assisted), respond to abuse mails and track the status of every report.

How do I report an attacker?

Via Attack Defense: attacks are reported automatically (fail2ban integration) or manually with a log excerpt. The attacker IP gets a score and the worldwide block list is updated.

What happens to my reports?

Every report raises the IP evidence score. With critical evidence (malware, botnet, spamtrap) or many independent signals, the IP is hard-listed and blocked by all participating servers. Operator abuse desks are notified.

How do I use report tokens?

Report tokens (ar_…) authenticate your fail2ban or script reports: your token permanently links reports to your account — all your reports are bundled in the dashboard.

Who is the Abuse Manager for?

For hosters, IT service providers and companies with their own IP ranges that regularly receive abuse reports.

Which report types are supported?

Spam, port scans, malware/botnet, DDoS, phishing, brute-force, copyright/DMCA, open resolver and more - automatically detected and categorized.

Where does the automated analysis run?

The processing runs entirely on secure servers in the EU. GDPR compliant.

Related guides

Ready? Start in seconds.

Create a free account and start instantly.

Start now