Topic
DNS Delegation Power
Within the Topic facet, DNS Delegation Power topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.

ICANN
ICANN Mapped AFRALO’s Requests Without Adopting Them
The most important phrase in the AFRALO-AfrICANN submission is not in the Board Chair’s reply. It is in the cover note: the statement was sent to the ICANN Board “for information purposes.” Six pages of recommendations then met a two-page response that acknowledged the problem…

Story
RIPE NCC Kept the Lameness Checks and Stopped the Emails
In 2009, RIPE NCC separated two activities that are often mistaken for one: it continued periodic checks of broken DNS delegations and ended the bulk email alerts generated from them. The decision is a useful historical operating case in what an infrastructure measurement can…

ICANN
The autistici.org Hold Has a Timestamp but No Public Decision Receipt
PIR’s RDAP service records exactly when `autistici.org` changed and which registry controls remain applied. It cannot tell the public who connected a US sanctions designation to that domain-wide action, which rule governed the choice, why it happened before a wind-down licence…

ICANN
The Enforcement Chain Behind ICANN’s Rules
ICANN's authority becomes consequential only when a policy, contract, compliance process and review route connect to an operational act. The public record identifies that chain, but it does not yet prove a single regulator-like mandate, a current universal contract baseline or an…
Global Cloud Services
Genesis Cloud’s Network Control Plane: When AS209045, DNS and Peering Still Do Not Prove Reachability
Public records can describe a cloud provider’s network identity without proving that customers have an independently observable path to its applications. Genesis Cloud’s case is therefore less a question of whether one registry entry is authoritative than of whether several…
ICANN
ICANN’s Authority Is Layered—and So Are Its Remedies
ICANN does not exercise one undifferentiated kind of power. Its authority is assembled from corporate instruments, Bylaws, policy procedures and private contracts; the route for challenging an action depends on which layer produced it.

Story
APNIC’s Two-Nameserver Run Had Fewer Repeats. The Difference Still Needs a Reproduction Receipt
APNIC measured fewer authoritative DNS queries in a later run using two nameservers than in an earlier run using one. The observation is real in the published aggregates; the cause is not settled. A reproducible decision needs the two treatments to share a clock, cohort and…

History
RFC 2065: The DNS Reply Crossed an Ordinary Server. Its Signature Carried the Trust
In January 1997, RFC 2065 proposed a security upgrade that did not require every machine carrying a DNS answer to become its judge. A security-aware resolver could retrieve signed records through a server that knew little about the new machinery and verify the evidence itself.…

Story
AFRINIC’s Uganda Anycast Node Is Two Services, Not One
AFRINIC’s Uganda Anycast Node Is Two Services, Not One intelligence summary explains the development, the public evidence available to readers, the organisations involved, the regional context, market exposure, and the infrastructure consequences that may follow. The Story…

ICANN
ICANN’s Alternative-Name Integration Needs a Verifiable Turn-Down
ICANN’s draft model would let a gTLD registry coordinate the same name across the global DNS and another naming system. The report recommends a mandatory plan for switching that integration off. The harder governance test is whether the operator can later prove that every…

Story
AFRINIC’s ccTLD Test Cannot Set a Country’s IPv6 Ceiling
The deployment monitor makes a useful check of registry nameservers, then draws a conclusion about every site below them. A recursive resolver can cross a transport boundary that the wording leaves out.

IETF
DNS ANY Should Be Retired by Purpose, Not by Query Code
A server can stop answering an ambiguous DNS query in one release. It cannot, by that act alone, replace the diagnostics, discovery habits and legacy dependencies that grew around the query. The defensible unit of retirement is the purpose, with an owner and a substitute—not…

IETF
A ULD Server Handoff Needs Proof That Local Services Survived
The network can stay up while the printer, display and local controller quietly disappear. That is the awkward possibility inside a seemingly clean Unicast Local Discovery transition. A client may correctly choose a better server, close its old path and report success. Yet the…
IETF
The Zone Was Still Answering. The Signing Key Was Already Gone
A correctly signed zone can outlive the private key that produced it. That interval is not recovery; it is a perishable option whose value depends on preserving old cryptographic state while proving, clock by clock, that a replacement chain has taken over.

IETF
DANCE 14 Turns Four TLSA Outcomes Into a Two-Way Server Decision
Four DNS observations can now enter the same TLS policy gate. The latest DANCE client-authentication draft tells a server what to do when it receives anything other than a DNSSEC-validated TLSA record set: abort, or continue while treating the client as unauthenticated. Revision…

IETF
EDE 33 Can Show an NTA Without Showing It Changed the Answer
A new DNS diagnostic can make a hidden exception visible without explaining its effect. EDE 33 tells a client that a covering Negative Trust Anchor was active when a resolver generated a response. The current draft also allows the signal when the exception made no material…

Story
RIPE NCC’s Four Stale IPv6 Glue Records Are Now Three. Root Repair Was Never a Batch.
One of four old IPv6 glue mappings identified after RIPE NCC’s AuthDNS renumbering has aligned with the nameserver’s current address. The other three have not. That split result reveals the real unit of root-zone maintenance: one delegation, one authorised decision and one…

History
Gihan Dias and the Two Names Sri Lanka Added to the Root
The smallest-looking part of a national network can expose its largest unfinished business. For Sri Lanka, two names in the DNS root showed that connecting a country and letting it recognise itself online were separate engineering tasks.

Story
LACNIC Signs 150 Reverse-DNS Files. The Batch Has No Manifest.
LACNIC’s public directory gives every reverse-DNS data file its own signature and checksum. What it does not give a whole-directory consumer is one signed statement saying which 150 filenames belong to the same completed publication.

History
Demi Getschko and the Country Code That Arrived Before Brazil Spoke TCP/IP
On 18 April 1989, `.br` entered the DNS root while Brazilian academic networks were still speaking BITNET, HEPnet and other protocols. Demi Getschko's part in that sequence reveals a neglected infrastructure skill: securing a durable name, accepting responsibility for it and…
