Primary Domain
Internet Infrastructure
Within the Primary Domain facet, Internet Infrastructure intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

History
A Policy Sentence Was Not a Network Control: RFC 1087 and the Limits of “Acceptable Use”
In 1989, the Internet Activities Board could identify conduct that threatened a shared research facility. It could say that intentional intrusion, disruption, waste, destruction and privacy compromise were unacceptable. What it could not do with a sentence was observe an act…

History
The Bit Preserved a Return Path. It Did Not Authenticate the Request: RFC 1044's HYPERchannel SRC
In a physical network, an address can do something concrete without saying who is entitled to act. RFC 1044 gave HYPERchannel messages a Source Address Correct bit that could survive only while the declared return address remained usable in reverse. That was valuable path…
CASE FILE
The CMC Message Arrived. It Did Not Arrive With Certificate Authority: RFC 10003
One CMC entity can travel by file, mail, HTTP or TCP. RFC 10003 makes that portability useful without turning any carrier, delivery receipt or listener into proof that a certificate authority made a decision.

History
The Speed Was a Display Hint. It Was Not the Link: RFC 1079’s Telnet Boundary
In 1988, a remote terminal program could know something useful about the terminal at the other end without pretending to know the network between them. RFC 1079 made that distinction unusually crisp. It let one Telnet peer request a pair of terminal speeds and let the other peer…
Europe and Middle East National Telecom Trends
A 2G device inventory is not a safe switch-off plan until each replacement path is confirmed
A facilities list can show that a building owns a pendant, lift alarm or fire alarm. It cannot show that the device is 2G-only, that its supplier has accepted an upgrade, or that the function will still work after the mobile network changes.
CASE FILE
The Key Became Portable. Custody Did Not: RFC 9964, ML-DSA and the AKP Boundary
Post-quantum migration often arrives in a deceptively tidy form: choose a new algorithm, register an identifier, put a key in the familiar container, and continue signing. RFC 9964 does something more useful and more limited. It defines how ML-DSA keys and signatures can travel…
CASE FILE
A Completed SCIM Request Is Not a Completed Cross-Domain Decision: RFC 9967
An asynchronous identity request is easy to over-read. A provider accepts a SCIM change, returns 202, and later emits a Security Event Token that carries the same transaction value. The trail is valuable: it gives two parties something specific to correlate. But it does not…

IETF
Tobias Fiebig and the Four DNS Reachability Receipts
A zone can display two A records, two AAAA records and a reassuring “dual stack” label while still withholding names from an IPv6-only resolver. RFC 10001 replaces that label with four bounded claims: two authoritative services must answer over IPv4 and two must answer over IPv6…

History
Before DHCP, Four Bytes Chose the Grammar: RFC 1048 and BOOTP's 64-Octet Limit
Before a diskless machine could fetch its operating system, it needed enough network knowledge to ask for one. BOOTP carried that knowledge in a field only 64 octets long. RFC 1048 made the field intelligible across vendors with four opening bytes and a compact option…

History
The Name Was the Address. It Was Not a Route: RFC 1088’s IP-over-NetBIOS Mapping
In February 1989, RFC 1088 made an unusually literal bargain between two naming systems. A host carrying IP over NetBIOS would derive a 16-byte NetBIOS name from its IP address: `IP.XX.XX.XX.XX`, with each `XX` written as ASCII hexadecimal. The name was meant to let a NetBIOS…

History
Four Bytes Put a Message in TCP. They Did Not Rebuild the OSI Network: RFC 1006’s TPKT Boundary
TCP can deliver every byte in order and still decline to say where one application-shaped entity ends. In 1987, RFC 1006 addressed that awkward fact for ISO Transport over TCP with a remarkably small intervention: put four octets before a TPDU, then make the receiver count. The…
CASE FILE
The Legacy Code Point Reached the Client. It Did Not Reauthorise the Server: RFC 9963
An IANA code point can look like a broad permission slip when it appears in a migration review. RFC 9963 is deliberately narrower. It gives TLS 1.3 three legacy RSASSA-PKCS1-v1_5 signature values, but only for a client proving possession of a client-certificate key after a server…
CASE FILE
The Reverse Socket Arrived. The Device Had Not Yet Identified Itself: RFC 10011 and RESTCONF Call Home
A controller can receive a connection from the direction it expected, on a listener it deliberately opened, after a device has been configured to call home. That is useful evidence. It is not yet the same thing as knowing which device has arrived, establishing a RESTCONF session…

History
The Token Found the Connection. It Did Not Admit the Subflow: MPTCP's MP_JOIN Boundary
One new TCP SYN can propose to become part of a connection that began somewhere else, on another address pair, minutes earlier. That is the useful oddity in Multipath TCP. It is also where a casual description—“the session moved”—loses the decisions that keep continuity from…
CASE FILE
The Quantum-Safe Key Was Added. The Classical Recipient Still Opened the Mail: RFC 9980
RFC 9980 gives OpenPGP a post-quantum vocabulary, including composite encryption keys that combine ML-KEM with X25519 or X448. That is an important interoperability step. It is also easy to overstate. A message can carry a genuinely PQ/T-capable recipient key and still be…

IETF
Weiqiang Cheng and the SRv6 Locator Lease That Still Needed a Route
The DHCPv6 log can show a valid Reply, a locator, an IAID and two working clocks while the route table still has nothing to say. RFC 10038 makes that gap explicit: assignment is one controlled event; reachability must be created, distributed and observed through separate systems.
Europe and Middle East National Telecom Trends
A final digital-landline notice is not a safe cessation until the critical call path is confirmed
A dated notice can prove that a provider started a final process. It cannot by itself prove that the person, telecare service or critical call path at the address has been safely carried through that process.

History
The Banner Marked the Screen. It Did Not Make the Policy: RFC 933 and Telnet's Display Boundary
A security banner could be sent once and kept visible by the workstation instead of being mixed into every screenful of application output. RFC 933 made that presentation bargain explicit—and left the security level, access decision and truth of the label outside the banner…
CASE FILE
The Fast Packet Kept the Session Up. It Did Not Authorise the Change: RFC 9985
RFC 9985 offers a disciplined answer to an awkward operational fact: a protocol can need frequent authenticated liveness packets at a rate that makes identical expensive authentication hard to sustain. Its answer is a split, not a blank cheque. Stronger-in-cost authentication…

History
The NAK Rejected the Port, Not the Packet: RFC 938 and the Boundary Between Delivery and Dispatch
In an experimental 1985 Internet protocol, a receiver could say two things at once: the next packet number had been received in sequence, and the local port named in that packet was not known. RFC 938 called that reply `PORT NAK`. Its precision is a useful warning against…
