Opt-out
If you operate network address space, you can ask us to stop scanning it and to stop publishing indicators found on it. This page explains how to ask, why we verify the request, and the two situations in which we will say no.
Effective 27 August 2026 · Public Mosaic LLC
Who this is for
Operators of address space: network owners, hosting and transit providers, universities, and anyone with administrative responsibility for a range rather than a single machine. If you want to contest one specific record rather than exclude a whole range, that is abuse & takedown instead — it is a faster route and it does not need the verification described below.
How to ask
support@publicmosaic.com, with Opt-out in the subject line. Include:
- The ranges, in CIDR notation, and the autonomous system number they are announced from.
- How we can verify you control them. The simplest route is to write from the abuse or technical contact published for the range in the relevant regional registry's whois. If that address is not available to you, we will agree another proof — typically a DNS TXT record we nominate, placed under a zone the range's reverse DNS delegates to.
- Whether the request is permanent or time-boxed — for example, for the duration of an incident response engagement.
Why we verify
This is the request an operator of command-and-control infrastructure would most like to make. An opt-out channel that applied on the strength of an email would be a way to remove working infrastructure from a defensive feed by asking politely, and it would make the feed worth less to everyone relying on it. So we confirm that the person asking controls the range before we exclude it. Verification is the reason this page exists separately from abuse & takedown, where no such leverage exists — contesting a single record only ever triggers a re-scan.
What exclusion does
Once applied, we stop probing the range, and indicators already published from it are withdrawn at the next export — about fifteen minutes. The exclusion persists until you tell us otherwise; it is not something you need to renew.
When we will say no
Two cases, and we will tell you which one applies rather than simply declining:
- Active, evidenced malicious use. Where a range is at that moment serving command-and-control infrastructure we have determinatively confirmed, we will not withdraw it on request. We will share what we observed so you can act on it, and we will reconsider once it stops.
- Unverifiable control. Where we cannot establish that the requester controls the range. This is usually a problem we can solve together rather than a refusal — write back and we will find a proof that works.
What it does not mean
Opting out is not a finding that a listing was wrong, and we do not treat it as one; if you believe a record was mistaken, say so and we will correct it on the merits, which is a different and better outcome for you. Nor does it reach other publishers: the feed is TLP:CLEAR and may already have been copied, so exclusion stops us publishing but cannot retract copies other people hold. And it is not a request to be un-scanned by the internet — it binds us, and only us.
Related
To contest a single indicator, see abuse & takedown. To see what is currently published, see /indicators. What this site records about you when you read it — a separate matter from the indicators, and never joined to them — is set out in privacy.