Summary
- ARIN-prop-353, dated 2 August 2026 and still listed as a new proposal, would define out-of-region use as use or advertisement solely outside ARIN's region and exclude deployments that also operate or advertise inside it.
- The word “solely” makes the classification depend on scope and time, yet the proposal does not say whether it applies per prefix, resource set, request or organization, or how long an outside-only state must persist.
- A protected four-state receipt—inside only, outside only, mixed, or indeterminate—should record the observation window, evidence classes, transient events, text version, reasons, correction path and expiry without exposing private topology.
The same design can cross the line twice
The opening case is hypothetical, but its mechanics are ordinary. An operator anycasts one service address from several locations. An in-region node is taken out of service for maintenance. For that interval, all remaining service locations are outside the region. When the node returns, the deployment is mixed again.
The 2 August proposal mirror tries to resolve a real ambiguity. Section 9 contains conditions for out-of-region use but has no definition of the term. The proposal says recurring concern has centred on simultaneous inside-and-outside deployment, including anycast. Its answer is to reserve the category for resources used or advertised solely outside the ARIN region; if use or advertisement also occurs inside, the definition would not apply.
That is an intelligible boundary. It stops the mere presence of an external anycast node from converting a mixed service into an outside-only one. But solely is not a photograph. It is a claim about the complete state of a system across some period. Without a period, maintenance, failure, route convergence and planned migration can turn the label on and off faster than any administrative decision can sensibly follow.
Classification and consequence are separate records
Proposal 353 asks one bounded question: which deployment state belongs in the out-of-region category? A decision record should answer that question before attaching any later policy consequence.
First classify the evidence as inside only, outside only, mixed or unresolved. Then record the text version and state the consequence applied under it. Combining those steps would make it impossible to tell whether an outcome turned on the geographical predicate or on a later rule.
Proposal 353 is also only a new proposal. The reviewed record does not establish Advisory Council acceptance, final drafting, consensus, adoption, an effective date or implementation. Its author even leaves open whether the definition belongs in the general definitions section or beside the Section 9 rule. That placement matters less than making its inputs and duration reproducible.
Anycast makes the time problem visible
RFC 4786 defines anycast operationally: one service address is available at two or more discrete, autonomous locations, and routing delivers packets to one available location. Each node presents a path to the common address. A catchment is topological—the part of the network directed to a node—not a political constituency drawn on a registry map.
The document also explains why a snapshot is weak evidence. Availability seen by a client varies with that client's position, and the client population reaching a node is neither static nor reliably deterministic. A route collector may see an origin while a particular user cannot reach the site. A withdrawn route may reflect maintenance rather than abandonment. The same prefix may be globally visible while local policy chooses different nodes for different observers.
None of that defeats the proposal. It tells the drafters what must be named. Is the relevant unit the entire prefix or a more-specific route? Does one functioning in-region node make the deployment mixed? Does a scheduled withdrawal preserve the prior state for an allowed interval? When does an outage become outside-only use rather than a fault inside a mixed design? What happens when the evidence cannot distinguish them?
“Use” and “advertisement” need separate columns
The proposed sentence joins two ideas: use in a location and advertisement from a location. They are not interchangeable. A route can be announced from a facility that forwards traffic elsewhere. A service can operate behind a routing arrangement not visible as a unique public origin. An operator may have equipment, customers, contracts and traffic in different places. A BGP observation proves that an observation point received routing information; it does not by itself prove physical equipment, customer residence or the legal centre of a service.
Location material has its own limits. RFC 8805 records a format through which an operator may publish coarse prefix geolocation. Location fields are optional. Consumers are told to verify authority and, where practical, accuracy; discrepancies may require review, and data can change without notice. A geofeed can be useful operator-supplied evidence. It is not a compulsory, complete or timeless inventory of every anycast node.
A protected case record should therefore keep at least three evidence classes apart: the operator's bounded deployment declaration; route observations with named vantage points and timestamps; and optional location assertions with their authority and freshness. Agreement strengthens confidence. Conflict should produce an indeterminate result, not a guess dressed as a rule.
A real operator account shows why the category matters
Mixed-region architecture is not merely a diagram. In an August 2025 NANOG archive, an operator described a historical allocation experience involving a CDN with infrastructure across several registry regions and ARIN addresses used globally. The thread also disputes the assumed binding between an IP address and a geographic address and discusses the uneven quality of correction mechanisms.
That account is context, not adjudicated evidence. It does not prove current ARIN staff practice, proposal 353's motive or a present dispute. It does show why an administrative category can meet a global service in more than one shape. Any policy record that reduces the result to inside or outside without a time window will be least reliable exactly where network design is most distributed.
Four states are safer than an automatic binary
The smallest useful result has four states: inside-only evidence, outside-only evidence, mixed evidence, and insufficient or conflicting evidence. Proposal 353 would attach its new definition only to the second. The fourth is essential. Without it, the actor who controls the most convenient observation also controls the conclusion.
The protected receipt need not become a public topology file. It should identify the scoped prefix or resource set, the request or decision type, the policy text version, and the start and end of the observation window. It should separately record in-region use evidence, in-region advertisement evidence, outside-region use evidence and outside-region advertisement evidence, each with source, time and confidence. It should flag anycast, maintenance, failure and planned migration; record optional location assertions and conflicts; then name the resulting state, decision role and reasons.
The final fields are procedural: notice, response, correction, review and expiry. Expiry matters because a true mixed state in August does not establish the same state forever. Correction matters because route and location evidence can be stale. Notice matters because a classification may affect access to a later request even when no public accusation exists.
The public layer can stay narrow: scoped outcome, applicable text version, decision date, reason code and review status. Customer lists, traffic volumes, facility details and security-sensitive topology can remain protected. Reproducibility does not require surveillance.
Geography should describe, not confer title
Heng Lu's Running-Code Primacy provides the governing limit. The number-resource layer is justified by uniqueness, proof of control, interoperability, security assertions and operational continuity. A service region is not a people, and a registry record may describe operational reality without creating it.
That distinction keeps the constructive recommendation proportionate. If ARIN retains a geographical test in its policy process, the result should be deterministic enough to audit and narrow enough to correct. It should not become a claim that the registry owns the geography of a route, can dictate the operator's site plan, or can treat an outage as an invitation to expand authority.
The reviewed evidence does not show that proposal 353 has harmed anyone. It shows a short proposed definition with an important protective intention and an unfinished temporal interface. Before the word solely carries an administrative consequence, ARIN should say: sole across what, observed by whom, for how long, on which evidence, under which text, and with what route back from an error.
Sources
- TeamARIN mirror, ARIN-prop-353: Define Out Of Region Use
- RFC Editor, RFC 4786: Operation of Anycast Services
- RFC Editor, RFC 8805: A Format for Self-Published IP Geolocation Feeds
- SecLists NANOG archive, public discussion of global deployment and IP geolocation
- Heng Lu, Running-Code Primacy: The Patch Needed to Preserve the Internet's Original Design
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
