Summary
- AFRINIC reported that, by the end of 2012, it had signed 49 DS records for 13 domains from two members. Those three numerators establish that the service was used, while the two-member count establishes that observed participation was narrow.
- Service availability is not the same as operator uptake. The report does not state how many members or reverse domains were eligible, how many child zones were signed, how many submissions were attempted, or how many attempts were accepted, rejected, withdrawn or abandoned. No defensible member-adoption percentage can therefore be calculated.
- The internal arithmetic is informative but bounded: 49/13 is about 3.77 records per reported domain, 13/2 is 6.5 domains per participating member, and 49/2 is 24.5 records per participating member. Each is an aggregate average, not the actual allocation between domains or members.
- The two-member concentration ratio, CR2, is mechanically 100% within the reported cohort because every one of the 49 records came from those two members. It is not a measure of concentration among all AFRINIC members, African networks, domains, countries or sectors. The only defensible lower bound on the larger contributor’s record share is 25/49, or at least 51.02%.
- Low measured participation cannot enlarge AFRINIC’s role. As a private membership-based bookkeeper and technical coordinator, its legitimate response was to define the denominator, disclose the submission funnel, reduce technical friction, provide voluntary assistance and make operations safe and reversible—not to compel uptake or punish non-adoption.
The snapshot is a numerator, not a verdict
On 31 December 2012, AFRINIC had a compact result to report. In the annual report’s words, by the end of the year it had signed 49 DS records for 13 domains from two members. The sentence is unusually useful because it preserves three distinct units: records, domains and participating organisations. It proves that the member-facing service reached running use. It also puts a hard boundary around what was observed: the reported record set came from only two members.
That is already enough to prevent two common analytical mistakes. The first is to mistake technical availability for adoption. AFRINIC had made it possible for members operating signed reverse-DNS zones to provide DS material for publication towards the parent side. But the existence of a path says only that a path existed. Operator uptake begins when eligible operators actually implement, validate, deploy and use the capability. A service can be technically ready while participation remains narrow; equally, a small early cohort can do substantial work without representing the broader population.
The second mistake is to turn a precise numerator into a percentage without its denominator. Two participating members divided by what? The report does not state the total active membership at the cutoff in a form tied to service eligibility. More importantly, total membership would not necessarily be the correct denominator. Some members may not have held an applicable reverse delegation; some may not have operated a signed child zone; some may not have had the authority, technical readiness or operational need to submit DS material. The relevant eligible population has to be defined before it can be counted.
The result is a narrow conclusion that is stronger for being disciplined. The service was not merely announced: two reported members used it, across 13 reported domains and 49 reported records. Yet no regional or membership-wide rate follows. Nor does the count establish that the service succeeded or failed as an institution. The snapshot provides evidence of use and concentration inside the observed cohort. It leaves the population, conversion path, persistence and barriers unmeasured.
This distinction matters because institutional stories tend to rush into the space left by missing measurement. A coordinator can present a working service as evidence of broad progress. A critic can present two users as evidence of failure. Neither verdict is available from the numbers given. The correct task is first to describe what the ledger can support, then identify the information required for any wider claim.
Records, domains and members are not interchangeable
The three quantities in the disclosure answer different questions. The 49 figure counts DS records. RFC 4034 defines a DS record as a distinct protocol object containing a key tag, algorithm, digest type and digest fields at a delegation point. That limited technical point is enough to explain why one domain can be associated with more than one record. It also explains why 49 cannot be restated as 49 domains, 49 organisations or 49 independent deployments.
The 13 figure counts reported domains. It therefore supplies a smaller unit of deployed scope than the record count, but the report does not say how those domains were divided between the two members. It also does not say whether every record was simultaneously active at year end. The records could have reflected multiplicity, changes, replacements or other circumstances, but the evidence does not distinguish among those possibilities. None should be selected as the explanation.
The two figure counts the members from whom the records came. It is the strongest evidence of concentration because it locates all observed activity within a two-organisation cohort. Yet the members remain unidentified. Their countries, sectors, network sizes, resource holdings, operating models, motives and individual contributions are unknown. Guessing any of those characteristics would convert an anonymous aggregate into a fictional case study.
Keeping the units separate avoids false scale. Forty-nine sounds larger than 13, and 13 sounds larger than two, but they do not describe competing versions of the same thing. They describe layers of the same disclosed set. A record-to-domain ratio can illuminate multiplicity in the aggregate. A domain-to-member ratio can illuminate the average scope inside the participating cohort. A member count can illuminate the breadth of observed organisational participation. None supplies the missing population against which adoption should be assessed.
The difference also protects readers from an easy rhetorical slide. If a report moves from “49 records” to “adoption” without showing domains, organisations and eligibility, a technical object count can acquire social meaning it has not earned. Conversely, if a critic treats “two members” as if each had made one trivial change, the record count and domain count disappear. The proper reading retains all three quantities at once: a multi-record deployment over 13 domains, concentrated within two anonymous members.
What the arithmetic can—and cannot—show
The internal calculations are reproducible from the published snapshot. Their value lies in displaying the shape of the observed set without borrowing a denominator from elsewhere.
| Measure | Calculation | Result | Proper interpretation |
|---|---|---|---|
| Aggregate DS records per reported domain | 49 / 13 | 49/13, about 3.77 | An average across the reported domains, not a domain-by-domain allocation or proof of simultaneous records |
| Aggregate domains per participating member | 13 / 2 | 13/2, or 6.5 | An average across two members, not evidence that either member operated 6.5 domains |
| Aggregate DS records per participating member | 49 / 2 | 49/2, or 24.5 | An average across two contributors, not evidence that either member supplied 24.5 records |
| CR2 within the reported cohort | 49 / 49 | 1, or 100% | All reported records came from the two reported members; this says nothing about the unobserved eligible population |
| Largest-contributor record-share lower bound | ceil(49 / 2) / 49 | 25/49, at least 51.02% | A mathematical floor for the larger contributor, not its known share |
| Records above a one-record-per-domain baseline | 49 - 13 | 36 | Aggregate multiplicity only; it does not identify the technical reason or timing |
The first ratio, 49/13, is approximately 3.769 records per reported domain. That tells us the record count exceeded a one-record-per-domain baseline by 36. It does not tell us whether a particular domain had a particular number of records. Nor does it reveal an algorithm mix, rollover history, record validity or the time for which any state persisted. The average is a property of the aggregate statement, not a reconstruction of the underlying configuration.
The second ratio, 13/2, is 6.5 domains per participating member. Fractions are normal in averages even when the counted objects are indivisible. No member operated half a domain merely because the quotient contains a decimal. The only defensible statement is that the 13 reported domains were attributed in aggregate to two members, with the actual division unknown.
The third ratio, 49/2, is 24.5 records per participating member. Again, that is not an allocation. With 49 indivisible records split between two contributors, they could not both have supplied exactly 24.5. The quotient is useful only as a cohort average.
The concentration calculation requires even greater care. Because the annual report attributes all 49 observed records to two members, the two-member concentration ratio within that disclosed record set is 49/49, or 100%. Calling this CR2 is acceptable only if the scope travels with the number. It is the share of the reported cohort accounted for by its only two reported contributors. It is not the share of AFRINIC membership, all reverse-DNS operators, African domains, Internet-number resources, countries, sectors or any market.
The lower bound on the larger contributor follows from the odd total. If 49 records are divided between two members, one must account for at least 25. Therefore the larger contributor’s share is at least 25/49, approximately 51.02%. This is a pigeonhole bound, not an observation that one member supplied 25. If both members supplied at least one record, the possible larger share ranges from 25/49 through 48/49. The report gives no basis for choosing a point within that range.
These calculations expose a particular kind of concentration: the observed implementation was organisationally narrow, while its internal record footprint was larger than a one-record-per-domain picture. They do not turn that shape into a representative sample. Indeed, the more carefully the arithmetic is presented, the clearer the missing comparison becomes.
The denominator has to describe eligibility
An adoption rate is a relationship between a clearly defined adopted population and a clearly defined eligible population at a specified time. The snapshot supplies the adopted side only in three reported units. It does not supply the eligible side in any of them.
For a member-level rate, the denominator might begin with members that held reverse delegations applicable to the service. But even that might be too broad if some did not operate the corresponding signed child zones. A more operational definition could count members that both controlled an eligible reverse domain and had a signed child zone ready for a parent-side DS relationship. Another could count members authorised and technically ready to submit. Each definition asks a different policy and service question. The annual disclosure gives none of them.
For a domain-level rate, the institution would need to define eligible reverse domains and show how many had a published DS relationship at the cutoff. It would also have to distinguish domains from records. A domain with several records should not silently count as several adopted domains, just as a replacement should not necessarily be counted as an additional deployment.
For an attempt-conversion rate, the denominator would be members or domains that tried to use the service. That requires an event trail: unique submitters, unique domains, accepted attempts, rejected attempts, withdrawals, abandoned attempts and timeouts. Without it, readers cannot distinguish lack of interest from lack of eligibility, lack of readiness, undetected friction or an incomplete attempt.
For a persistence measure, a year-end table would need to show which records and domains were active at the cutoff, as well as adds, replacements, rollovers and removals during the period. The report’s use of “signed” should not be expanded into an undocumented processing model. Nor should the year-end sentence be read as proof that every one of the 49 records was valid, concurrent and persistent.
The denominator problem is therefore not a complaint that a single total is missing. It is a demand for definition. “All members” may be easy to count but analytically weak if many could not use the service. “Eligible members” is stronger only if eligibility is explicit, consistently applied and auditable. “Ready members” may illuminate immediate conversion potential, but readiness itself needs criteria. The point is not to choose the most flattering or most critical denominator; it is to choose one that corresponds to the question being asked.
This also explains why no percentage of African networks, domains or countries can be derived. The disclosure does not map the two members or 13 domains geographically, and their identities must not be inferred. Dividing 13 by a country count would combine unlike units and invent representativeness that the report did not claim. A technical record set is not a proxy census of a region.
Why 136 and 141 cannot repair the gap
The 2012 annual report contains two inconsistent figures for new members. Its three-year overview says 141; its membership narrative and table say 136. That inconsistency is worth noting as a bookkeeping issue, but neither figure is an eligible-service denominator.
Both numbers describe reported new members during the year, not the total active membership on 31 December. They do not identify which members held reverse delegations, which operated signed child zones, which were authorised and ready to submit DS material, or which had a reason to use the service. Dividing the two participating members by 136 or 141 would produce a decimal, but not an adoption rate. Arithmetic cannot rescue a mismatch in definitions.
The inconsistency also makes a broader point about institutional reporting. Precision is not achieved merely by placing integers in a table. A number needs a stable category, a stated period and a relationship to the decision it is meant to inform. Even if the new-member figures had agreed, they would still answer a different question. The appropriate response is not to select the more convenient number. It is to leave the rate uncalculated and request the population that actually corresponds to eligibility.
Two other figures in the report are similarly tempting and similarly unsuitable. AFRINIC said its training programme covered evolving technologies including DNSSEC and RPKI and reported more than 500 participants across 15 workshops in 13 countries during 2012. Those totals establish activity, but not a DNSSEC adoption funnel. The report does not say how many participants received DNSSEC instruction, belonged to eligible members, left with an operationally ready zone, attempted submission or became users of the service.
The report also said that 55% of surveyed members were satisfied and 16% were very satisfied, while listing DNSSEC among highlighted service areas. Yet the cited material does not provide the survey sample, response rate, DNSSEC-specific answers or overlap with the two participating members. Satisfaction across a survey cannot explain why a narrowly used technical service did or did not convert eligible operators.
These adjacent metrics may belong in a fuller institutional account, but they cannot be made to serve as substitutes for direct measurement. Membership growth, training reach, general satisfaction and DS publication are four different categories. A useful adoption report would connect them through defined stages rather than asking readers to infer a conversion path from unrelated totals.
The missing funnel is more important than a missing headline rate
A denominator would permit a rate, but a rate alone would still be a thin diagnosis. If participation were low, decision-makers would need to know where eligible operators left the path. If participation were high, they would still need to know whether successful records remained accurate and active. The missing conversion funnel therefore matters more than any single percentage.
The first stage should identify the population of eligible members and eligible reverse domains. The second should identify signed child zones discovered or declared. The third should count submission attempts by unique member and domain. The fourth should separate accepted, rejected, withdrawn and abandoned attempts using clear reason categories. The fifth should measure processing time, including both the median and the slower tail. The sixth should show active DS records and domains at period end, along with adds, replacements, rollovers and removals.
Such a sequence would answer practical questions that the 49/13/2 snapshot cannot. Were there many eligible members but few signed zones? Were signed zones common but submissions rare? Did operators attempt the service and encounter correctable errors? Did accepted records remain present? Were support contacts associated with completed submissions? None of these possibilities is established for 2012. They are examples of questions a properly instrumented service could answer.
The distinction between unique actors and event counts is essential. One member can make several attempts. One domain can have several record changes. One support engagement can address more than one domain. A table that mixes events with unique participants can appear busy while hiding how narrow the user base remains. The annual sentence avoids some of that confusion by naming two members, 13 domains and 49 records separately. A future disclosure should preserve that discipline across every stage.
Time also matters. A year-end stock differs from an annual flow. “Active at period end” is not the same as “ever accepted during the year.” Adds and removals can create gross activity without increasing the final deployed population. A median processing time can look healthy while a small set of cases stalls for much longer, hence the need for a tail measure. These definitions do not prejudge the result; they prevent the result from changing meaning as it passes through an annual report.
Privacy does not require institutional blindness. The two members need not be named to show unique participating-member counts, eligibility categories, attempt outcomes or reason codes. Small-cell handling may be needed in a more detailed report, but the core principle is straightforward: preserve enough evidence to distinguish non-eligibility, non-interest, failed attempts and successful use without exposing private identities.
Prerequisites are known; barriers are not
The evidence establishes a short chain of prerequisites. A member had to operate a signed reverse-DNS zone. It had to supply DS material through the member-facing domain-object path described by AFRINIC. AFRINIC then had to process and publish the material towards the parent side. Those steps describe what successful use depended on. They do not reveal why others did not appear in the reported cohort.
Several barriers would be reasonable subjects for investigation. Operators might have needed greater key-management or rollover capability. They might have needed clearer understanding of DS generation and child-parent sequencing. Access to the relevant domain object, or current contact and maintainer authority, might have mattered. Concern about validation failure or service interruption could have affected willingness. Staff time, tooling, support availability and the perceived balance between benefit and operational risk could also have mattered. Processing friction, rejection or unclear error feedback would be another testable category.
Every item in that list is a hypothesis, not a finding about 2012. The disclosure does not say that any member lacked skill, feared failure, encountered an access problem, received a rejection, ran out of staff time or judged the benefit too small. It reports no rejected, failed, abandoned or withdrawn attempts. It reports no outage, invalid DS relationship, bogus validation, failed rollover or emergency reversion. Analysis must not turn plausible friction into invented history.
This is not excessive caution. Misstating a barrier leads directly to the wrong remedy. If the principal gap were eligibility, more generic promotion would miss the issue. If eligible operators were interested but unable to pass a preflight check, clearer diagnostics would matter. If attempts were accepted but processing was slow, operational capacity would matter. If capable operators simply did not see sufficient value, assistance should remain available without pretending that reluctance is a defect.
Barrier measurement should therefore be built into the service at the point where evidence arises. A preflight check can return structured failure categories. An attempted submission can record whether it was completed, withdrawn or left unfinished. Support contacts can be classified without publishing private content. Training can be linked, in aggregate, to later readiness and submission. These are measurement designs, not claims about what happened in the reported year.
The boundary between prerequisites and barriers is particularly important in governance. A prerequisite can be described neutrally: an operator needs control of an applicable signed child zone. A barrier claim attributes a reason for absence: operators did not participate because they lacked capability, access or confidence. Only the first is supported here. The second requires evidence that the annual disclosure does not provide.
The stakes justify better service, not inflated authority
The DS publication surface is narrow but consequential. For a member, adoption can require scarce engineering attention, reliable key operations, accurate authority records and confidence that an erroneous transition can be corrected quickly. For downstream relying networks, a correct DS relationship contributes to verifiable DNS data; a wrong or stale relationship can produce failures for validating resolvers. These operational stakes raise the standard of care around the shared record.
They do not change AFRINIC’s institutional character. AFRINIC is a private membership-based recordkeeper and technical coordinator. Its proximity to consequential technical records does not give it sovereign, regulatory, police, punitive, confiscatory or adjudicative power. It records and coordinates a relationship required by running systems; it does not rule the operators whose data it handles.
That limit has a direct consequence for adoption policy. Low uptake does not authorise mandatory use. Non-adoption is not a violation, misconduct or evidence of bad standing. It cannot justify punishment or leverage over unrelated membership and registry services. A coordinator may explain benefits, improve service quality, publish evidence and offer help. It may not manufacture public authority from a technical count.
The constructive model is “thin coordination”: maintain accurate records, protect security and continuity, make technical operations predictable, and help voluntary participants succeed. The more consequential the bookkeeping, the more disciplined that service should be. Deterministic preflight checks should catch detectable errors before publication. Error messages should identify what needs correction. Changes should be sequenced safely. Notices should reach the responsible operator. Reversal should be available where a transition creates difficulty. Guidance and assistance should be proportionate to operator needs.
None of those measures requires an institution to claim ownership over members’ resources or keys. None requires a view that “the community” has delegated governmental power. Words such as community, stewardship or mandate in institutional self-description cannot enlarge a private coordinator’s authority. The source of legitimacy here is competent, bounded service: accurate records, clear consent, reliable operation and honest measurement.
The same limit disciplines criticism. A narrow cohort does not prove institutional misconduct. It does not prove that AFRINIC blocked users, caused failures or coerced anyone. The evidence supports a measurement gap and a service-design agenda, not an allegation. Institutional restraint works in both directions: the coordinator should not claim more authority than the role carries, and the analyst should not claim more failure than the record shows.
The strongest countercase: a rational early pilot
The year-end snapshot came in the first year of AFRINIC’s member-facing DNSSEC service. Cautious early uptake can be entirely rational when a technical mistake may impair validation. Forty-nine records across 13 domains may represent meaningful operational work by the two participating members and by the coordinator. It would be unfair to label the service a failure solely because the participant count was small.
This countercase deserves full weight. Early adopters often carry a different risk profile from later users: they are willing and able to test a new operational surface before routines, support and institutional confidence mature. A two-member cohort can reveal whether a service is usable at all and can provide experience from which a better service is built. The reported multiplicity—49 records across 13 domains—also warns against describing the cohort as two token actions.
But the countercase does not turn a pilot into regional adoption. The same numbers that may be consistent with substantial early work remain unable to show the size of the eligible population, the number of attempts, the reasons for non-participation or the persistence of the deployed state. “First year” is a reason to interpret a low count cautiously; it is not a denominator.
Indeed, a pilot interpretation strengthens the case for measurement. If 2012 was an early learning period, AFRINIC needed to know what the two participants encountered, where other eligible operators stopped, how long successful cases took, whether records remained active and what support converted interest into use. A baseline established in the first year would make later comparisons meaningful. Without definitions and a funnel, future totals could rise while leaving the institution unsure whether adoption broadened or the same narrow cohort simply generated more record events.
The fair conclusion is therefore symmetrical. The disclosure supports neither a victory claim nor a failure claim. It supports “used, but narrowly observed.” A working service used by two members is more than a paper capability. It is less than evidence of broad uptake. Treating that middle position honestly is not indecision; it is the only conclusion that respects the disclosed units.
What the annual sentence does well
The measurement critique should not obscure a virtue in AFRINIC’s sentence. By reporting records, domains and members together, it gives readers more structure than a single headline count would have provided. If the report had disclosed only 49 records, organisational concentration would have been invisible. If it had disclosed only two members, the operational footprint across domains and records would have been invisible. If it had disclosed only 13 domains, neither record multiplicity nor participant breadth would have been clear.
The sentence therefore offers the seed of a good adoption table. It recognises that technical objects, deployed domains and participating organisations are different layers. The next step was to place those numerators beside explicit denominators and movement through the service. A sound reporting system should preserve this layered structure rather than replace it with a single composite score.
That is also why an abstract concentration index would add little. With only two anonymous contributors and no record split, an observed HHI or Gini cannot be calculated. Bounds could be explored mathematically, but they would not reveal the actual distribution. The useful concentration facts are simpler: all observed records came from two members; the larger contributor supplied at least 25 of 49; the actual split is unknown. Precision beyond that would be decorative rather than informative.
The sentence’s compactness also makes its omissions easy to audit. It does not identify the members. It does not assert geographic representativeness. It does not describe failed attempts or barriers. It does not claim that every reported record was concurrently active. Those silences should not be filled with inference. They should be turned into the next reporting questions.
In this sense, the annual report performs one half of competent bookkeeping: it records an exact observed state. The missing half is decision-useful context. A bookkeeper serving operators should make clear how the state was defined, how it changed and what fraction of the relevant population it represents. The ledger’s value grows when its limits are as explicit as its totals.
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
