Skip to content
ASN-Aware

ASN reputation that adds context without becoming a blunt weapon

ASN reputation helps operators understand whether an artifact sits inside a provider with recurring abuse, a normally trusted network seeing something new, or a noisy environment that needs tighter local policy.

vspam uses ASN evidence as a supporting layer. It raises or lowers confidence around domains, IPv4, and IPv6 infrastructure, but it is not designed to replace direct artifact evidence.

What ASN reputation means here

Recent abuse density versus long-term history so operators can distinguish chronic noise from novel bad activity.

Provider-aware context for cloud, datacenter, ISP, residential, and mobile environments where the same abuse count can mean very different things.

Support for reputation and watch workflows rather than treating an ASN as a direct, standalone block decision.

Daily aggregates that let domain and IPv6 host scores borrow provider context without losing artifact-level precision.

Recommended operator workflow

Prioritize investigations

Use ASN abuse density to rank where analysts spend time across mail and phishing infrastructure.

Tune local controls

Apply throttling, soft blocks, or escalation inside locally sensitive providers without treating ASN context as a universal deny list.

Corroborate direct artifacts

Combine ASN context with domain and IPv6 exact-host evidence before promoting new infrastructure into direct-block feeds.

Explore the supporting surfaces