Skip to content
Notis

Submit Abuse Reports to Abuselpdb by Changing a Notion Status

You shouldn't have to manually paste incident data into Abuselpdb to file a report. Change a status in Notion and the report submits itself, saving you the context switch and copy-paste work.

Trigger

Page Properties Updated

Triggers when properties of a Notion page are updated. Customer optionally scopes with at most one of: - data_source_id: any row in this data source - page_id: this specific page - parent_page_id: any page whose immediate parent is this page With none set, fires for any property change in the workspace the integration has access to. Adding a column to a data source fires this trigger once per existing row. Customers can branch on `data.updated_properties` (array of property IDs) to filter downstream.

Action

Bulk Report

Tool to submit multiple ip abuse reports in bulk. use when you need to report a large set of ips at once by uploading a csv file with required headers. csv must include columns: ip, categories, reportdate, comment.

Why this helps

After investigating in Notion, you have to switch to Abuselpdb, manually re-enter the IP and details, and submit the report yourself--duplicating work and wasting mental energy on a mechanical task.

  • Mark 'Reported' once and the submission happens automatically
  • No manual re-entry of data to Abuselpdb
  • Clear audit trail linking Notion incidents to Abuselpdb reports

Setup

Build it in a few focused steps.

  • 1Connect your Notion incidents database to Notis.
  • 2Connect your Abuselpdb account with report submission permissions.
  • 3Create an automation: name it 'Report to Abuselpdb on Status Change' with this prompt: 'When the Status property of an incident row is updated to Reported, submit all IPs and details as a bulk abuse report to Abuselpdb.'
  • 4Select 'Page Properties Updated' as the trigger and configure your notification channel.
  • 5Test by marking a sample incident row as 'Reported' and confirm the report appears in Abuselpdb.

Questions about this workflow

What information gets included in the report?

IP address, timestamp, category (e.g., spam, malware), and any comment field from your Notion row.

What if I change status back from Reported?

Only status-to-Reported transitions trigger submission. Changing back won't re-submit.

Can I edit the report after it's submitted?

Abuselpdb submissions are permanent, but you can update your Notion incident record for your own tracking.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Notion to Abuselpdb. A trigger fires from one place; an action lands in another.

Notion triggers

Abuselpdb actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Retrieve IP Blacklist

Tool to retrieve a list of the most reported ip addresses. use when building dynamic blocklists or threat intelligence feeds.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Bulk Report

Tool to submit multiple ip abuse reports in bulk. use when you need to report a large set of ips at once by uploading a csv file with required headers. csv must include columns: ip, categories, reportdate, comment.

ActionInstant

All Page Events

Triggers when any Notion page is created or updated across the workspace.

TriggerPolling

Check Block

Tool to check the reputation of all ip addresses in a cidr range. use when you need aggregated abuse data for a network block.

ActionInstant

Comment Created

Triggers when a new comment is created in Notion. Optional `page_id` filter scopes to comments on a specific page. When omitted, fires for any new comment in the workspace the integration has access to. Requires the 'Read comments' capability on the Notion integration. If a connection was authorized before that capability was enabled, the user must re-authorize the connection for comment events to flow.

TriggerInstant

Check IP Reputation

Tool to check the reputation of an ip address. use when you need to determine if an ip address has been reported for abusive activity within a specified look-back period. example: checkip(ipaddress='8.8.8.8', maxageindays=90).

ActionInstant

New Comment

Triggers when a new comment is added to a specified Notion block or page.

TriggerPolling

Clear Address Reports

Tool to remove all reports associated with a specific ip address. use when you need to purge your own abuse records after verifying control of the ip.

ActionInstant

Database Created

Triggers when a new Notion database (the container) is created. A database is the post-2025-09-03 container that holds one or more data sources. This trigger fires for the container's creation event (`database.created`), distinct from `NOTION_DATASOURCE_CREATED` which fires when a new data source is added to an existing database. Most customers calling Notion's `POST /v1/databases` (the legacy API) or creating a database via the Notion UI will see this event. Adding a new data source to an existing database fires `data_source.created` instead — use `NOTION_DATASOURCE_CREATED` for that. Notion's payload puts `entity.type: "block"` (the container is a `child_database` block in the content tree) and `entity.id` is the database id.

TriggerInstant

Get Abuse Reports

Tool to retrieve a list of abuse reports for a specific ip address. use when you need to fetch historic reports with optional filtering by status, date range, reporter, and pagination.

ActionInstant

Data Source Created

Triggers when a new Notion data source is created. Fires workspace-wide. The payload's `data.parent` carries the data source's tree parent (typically the teamspace) for downstream filtering. A single template-based database creation can fire multiple `data_source.created` events at once — one per data source the template instantiates.

TriggerInstant

Data Source Schema Updated

Triggers when a Notion data source's schema is updated. Fires on column add / remove / rename. Payload includes `data.updated_properties: [{id, name, action}]` so consumers can discriminate the kind of change downstream. Optional `data_source_id` filter scopes to schema changes on a single data source. When omitted, fires for any schema change in the workspace the integration has access to. Note: adding a column also fires `page.properties_updated` once per existing row in the data source. Customers wanting a single structural-change signal should use this trigger.

TriggerInstant

Connect any two apps with Notis in the middle.

Notion and Abuselpdb, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Abuselpdb.