Primary Domain
Infrastructure
Within the Primary Domain facet, Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.
CASE FILE
The Zone Went Dark. The Resolver Made the Outage Louder
When authoritative DNS stops answering, the first failure belongs to the zone. The next thousand queries may belong to the resolver. RFC 9520 draws a narrow but consequential line between the two: silence is not proof that a name does not exist, yet a resolver that has exhausted…
CASE FILE
The Block Was Explained. The Policy Was Still a Claim.
The night shift sees an authenticated DNS response that says a name was blocked, identifies a policy category and offers a support route. The explanation is orderly, machine-readable and intact. It still does not reveal whether the upstream classification was right, who had…
CASE FILE
The Proof Verified. The Fork Was Still Private.
Every response on Alice’s device verifies. Every later tree head extends the one before it. Across town, Bob sees the same tidy sequence—except his latest head commits to a different key for Alice. The log has not broken either local proof chain. It has separated the witnesses.
CASE FILE
The Handshake Succeeded. The DNS Question Was Already Exposed
RFC 9539 lets a recursive resolver encrypt its next hop to an authoritative server without waiting for the server to advertise a new policy or present a verifiable identity. That modest bargain can hide many DNS questions from passive observers. It also creates an unusually…

Europe and Middle East Regional ISP Trends
BSH's single-operator model makes dependency evidence part of the SLA
BSH offers distributed organisations a commercially simple proposition: aggregate communications services into one contract and give the customer one point of responsibility. That can reduce the cost of coordinating a fault. It does not, by itself, show whether the underlying…
CASE FILE
The Certificate Was Fresh. The Number Authority Had Its Own Clock.
A verifier receives a PASSporT with an intact signature, a valid certificate path and a certificate that will expire in hours. Between issuance and the call, however, control of the calling number has changed. The credential can be fresh in the precise X.509 sense while the fact…
CASE FILE
The TLS Session Resumed. The DNS Subscription Did Not
DNS Push can make a changing RRset look continuously current by stopping the client’s TTL clock and replacing polling with a server’s promise to send changes. That promise belongs to one accepted subscription on one live DSO session. A resumed TLS channel is cheaper to rebuild…

Story
ARIN’s RDAP Parent Handle Describes Registration Hierarchy, Not Network Transit
Two handles in one ARIN RDAP response can reconstruct how an address block sits inside the registry, but they cannot reveal who carries its traffic. The distinction is small in syntax and consequential in analysis.
CASE FILE
The Tokens Stayed Server-Side. The Browser Still Spent the Session.
The incident review found no exported access token, no stolen refresh token and no readable session cookie. Yet a state-changing request had crossed the Backend for Frontend and reached the protected service. The missing fact was not secret custody. Compromised code had run…

Story
AFRINIC Invited Members to Test MyAFRINIC v2. The Beta Needs a Defect-to-Release Ledger
AFRINIC used its AfPIF 2026 page to invite members into the next stage of MyAFRINIC v2: workflow interviews, user acceptance testing and a live beta. That is a sensible way to test a member portal against real registry work. It also creates an evidence duty. Every finding should…
CASE FILE
The Record Expired. The Resolver Kept It Alive
DNS Serve Stale can preserve service when authorities cannot answer. It can also keep a retired address or denial alive after the publisher's ordinary freshness claim has ended. The difference lies in who owns the exception and whether its evidence survives.

Story
AFRINIC’s RDAP CIDR Array Describes a Registered Range, Not a BGP Route
AFRINIC’s RDAP service can render a registered address interval in the same CIDR notation used by routing systems. The shared notation is useful for comparison, but the registry field does not establish that a route exists, identify its origin or prove that traffic can reach the…
CASE FILE
The SID Chose a Member Link. It Did Not Own the Bundle.
One peering interface was really three physical links. The ordinary Peer Adjacency SID sent traffic to the logical bundle and let its own balancing choose a member. The new member SID could instead place one flow on the lane that looked emptiest. That sharper instruction did not…

History
The Address Seen from Outside: What STUN Could Discover but Not Guarantee
When a client behind a Network Address Translator (NAT) seeks to understand its reachable address from the perspective of an external server, it performs a specific exchange: sending a STUN Binding request. This request, originating from a known local address and port, traverses…
CASE FILE
The Certificate Named an Interface. It Did Not Prove the Device.
The commissioning test produced two honest identifiers. The certificate named the factory address of one Wi-Fi interface. The frame arriving at the access point used a private address chosen for that network. Rejecting the connection would punish a real device for using a privacy…
IETF
DNS Serve-Stale Lets the Recursive Resolver Decide When Expired Data Is Better Than Failure
A DNS record reaches the end of its TTL just as every authoritative server becomes unreachable. The old address may still preserve a working service—or it may lead users back to infrastructure the zone owner meant to retire. Serve-stale keeps resolution alive by giving the…
CASE FILE
Two Answers Said NOERROR. Only One Carried the New Zone
RFC 9660 can bind a DNS answer to the zone version that produced it. That makes a mismatch visible without pretending that one version token proves the zone is correct, the fleet has converged or users saw the same path.
Europe and Middle East Regional ISP Trends
A mapped pole is not a broadband route until access is cleared
A fibre planner can draw a convincing line through a village in minutes. The line follows existing poles, avoids an expensive trench and turns a difficult build into a short spreadsheet. Then a field team reaches the first pole and asks the question the map did not answer: can…
CASE FILE
The Timestamp Got Sharper. The Clock Did Not Gain Authority.
Send one NTP request through ordinary UDP port 123 and its arrival may be timestamped after software and queueing have already left fingerprints on the measurement. Wrap the same logical request in a PTP event message, and a compatible network card can timestamp it at the wire.…
CASE FILE
The Service Vanished. Its DNS Lease Did Not
A DNS Update Lease can make stale records expire without a cleanup command. It can also keep an authoritative answer valid long after the advertised service has stopped, because the server—not the requester—sets the operative publication horizon.
