A LOA, route object and ROA are not interchangeable. A LOA records permission for a process, an IRR object describes a prefix and origin ASN for routing filters, and a ROA cryptographically authorises an AS to originate the network.

Request data for the actual prefix before payment or make successful verification an acceptance condition. “Clean network” without addresses and criteria proves nothing.

01

Start with RDAP or the authoritative RIR database

Check how the range is registered, which RIR is authoritative and which contacts are published. The resource holder and invoicing company may differ, so the right-to-use chain should be clear.

Do not focus on the country field alone. Resource status, encompassing allocation, organisation, abuse contact and available history are more useful.

  • exact prefix and authoritative RIR;
  • resource holder and its relationship to the supplier;
  • allocation or assignment status;
  • current abuse contact;
  • ability to issue documents for the routing model.
NextConfirm PTR control
02

Confirm PTR control

PTR records live in the reverse DNS zone. The supplier may process changes by ticket, provide zone control or delegate it to customer name servers. Delegation is convenient for a /24, but must be supported for the actual block.

Agree the change time, record limits and any forward-confirmed reverse DNS requirements for mail use. PTR alone does not repair reputation or guarantee mail delivery.

NextCheck the LOA and the signer
03

Check the LOA and the signer

A Letter of Authorization is used when a facility or upstream needs written permission to announce or use a resource. The prefix, permitted ASN, parties, purpose and validity period should match the request.

Confirm who issues the LOA and whether the target upstream will accept it. A PDF without a verifiable signer or connection to the resource holder may fail review.

  • complete IPv4 prefix;
  • ASN authorised to originate it;
  • resource holder and authorised party;
  • date, validity and verification contact;
  • wording accepted by the receiving operator.
NextDo not confuse IRR with RPKI
04

Do not confuse IRR with RPKI

An IRR route object links an IPv4 prefix to an origin ASN and may feed operator filters. A RPKI ROA is a signed authorisation from the address holder for an AS to originate a prefix up to a stated maximum length.

Check both layers when required. An announcement with the wrong origin or a length not permitted by the ROA can be Invalid and rejected by networks applying route origin validation.

  • an exact route object with the correct origin;
  • the IRR databases used for upstream filtering;
  • ROA state: Valid, Invalid or NotFound;
  • matching ASN, prefix length and maxLength;
  • owner and lead time for corrections.
NextTest reputation for the actual workload
05

Test reputation for the actual workload

One public blacklist does not describe complete reputation. Mail, advertising systems, APIs, VPNs and ordinary web traffic need different checks. Request test addresses and inspect the services that matter to your application.

Define what happens when part of the delivered range is already restricted by an external service. Replacement, timing and acceptable evidence should be clear before launch.

NextRead abuse terms before the first complaint
06

Read abuse terms before the first complaint

Learn which events produce a notice, time-limited address restriction or immediate suspension. The contact channel, time zone, response window, evidence format and ability to isolate one IP instead of the whole prefix all matter.

Assign an attended abuse contact and a backup channel. A response window is useless when the notice goes to an abandoned mailbox.

  • where notices arrive and how receipt is acknowledged;
  • time allowed for initial response and remediation;
  • when one IP, one server or the whole prefix is blocked;
  • how to explain or dispute an incorrect complaint;
  • activities prohibited by the agreement.
NextGo to the topic questions